6.9

CVSS4.0

CVE-2025-54864 - Hydra missing authentication when triggering evaluations through GitHub and Gitea plugins

Hydra is a continuous integration service for Nix based projects. Prior to commit f7bda02, /api/push-github and /api/push-gitea are called by the corresponding forge without HTTP Basic authentication. Both forges do however feature HMAC signing with a secret key. Triggering an evaluation can be verโ€ฆ

๐Ÿ“… Published: Aug. 12, 2025, 3:48 p.m. ๐Ÿ”„ Last Modified: Sept. 22, 2025, 2:58 p.m.

7.1

CVSS4.0

CVE-2025-54800 - Hydra persistent XSS in build metrics

Hydra is a continuous integration service for Nix based projects. Prior to commit dea1e16, a malicious package can introduce arbitrary JavaScript code into the Hydra database that is automatically evaluated in a client's browser when anyone visits the build page. This could be done by a third-partyโ€ฆ

๐Ÿ“… Published: Aug. 12, 2025, 3:47 p.m. ๐Ÿ”„ Last Modified: Sept. 22, 2025, 2:57 p.m.

4.3

CVSS3.1

CVE-2025-8452 - Unauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltโ€ฆ

By using the "uscan" protocol provided by the eSCL specification, an attacker can discover the serial number of multi-function printers that implement the Brother-provided firmware. This serial number can, in turn, can be leveraged by the flaw described by CVE-2024-51978 to calculate the default adโ€ฆ

๐Ÿ“… Published: Aug. 12, 2025, 3:23 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-5468 -

Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a local authenticated attacker to reโ€ฆ

๐Ÿ“… Published: Aug. 12, 2025, 3:05 p.m. ๐Ÿ”„ Last Modified: Sept. 23, 2025, 6:17 p.m.

4.9

CVSS3.1

CVE-2025-5466 -

XEE in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with admin privileges to trigger a denial ofโ€ฆ

๐Ÿ“… Published: Aug. 12, 2025, 3 p.m. ๐Ÿ”„ Last Modified: Sept. 23, 2025, 6:18 p.m.

7.5

CVSS3.1

CVE-2025-5462 -

A heap-based buffer overflow in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated attacker to trigger a deniโ€ฆ

๐Ÿ“… Published: Aug. 12, 2025, 2:56 p.m. ๐Ÿ”„ Last Modified: Sept. 23, 2025, 6:21 p.m.

7.5

CVSS3.1

CVE-2025-5456 -

A buffer over-read vulnerability in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated attacker to trigger a dโ€ฆ

๐Ÿ“… Published: Aug. 12, 2025, 2:50 p.m. ๐Ÿ”„ Last Modified: Sept. 23, 2025, 6:24 p.m.

8.1

CVSS3.1

CVE-2025-3831 - Exposed SFTP server

Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.

๐Ÿ“… Published: Aug. 12, 2025, 2:48 p.m. ๐Ÿ”„ Last Modified: Sept. 3, 2025, 4:15 p.m.

6.5

CVSS3.1

CVE-2025-8310 -

Missing authorization in the admin console of Ivanti Virtual Application Delivery Controller before version 22.9 allows a remote authenticated attacker to take over admin accounts by resetting the password

๐Ÿ“… Published: Aug. 12, 2025, 2:42 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:49 p.m.

7.2

CVSS3.1

CVE-2025-8297 -

Incomplete restriction of configurationย in Ivanti Avalanche before version 6.4.8.8008ย allows a remote authenticated attacker with admin privileges to achieve remote code execution

๐Ÿ“… Published: Aug. 12, 2025, 2:37 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:49 p.m.
Total resulsts: 348616
Page 4282 of 34,862
ยซ previous page ยป next page
Filters