4.8

CVSS4.0

CVE-2025-5922 - Retrievable password hash protecting TSplus admin console

Access to TSplus Remote Access Admin Tool is restricted to administrators (unless "Disable UAC" option is enabled) and requires a PIN code. In versions below v18.40.6.17 the PIN's hash is stored in a system registry accessible to regular users, making it possible to perform a brute-force attack usi…

📅 Published: July 29, 2025, 4:54 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS3.1

CVE-2025-31965 - HCL BigFix Remote Control is affected by an authorization bypass vulnerability

Improper access restrictions in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0248 and lower) allow non-admin users to view unauthorized information on certain web pages.

📅 Published: July 29, 2025, 4:53 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-54797 -

This CVE is a duplicate of CVE-2025-52464.

📅 Published: July 29, 2025, 4:50 p.m. 🔄 Last Modified: Aug. 5, 2025, 12:15 a.m.

0.0

CVE-2025-53706 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2025. Notes: none.

📅 Published: July 29, 2025, 4:03 p.m. 🔄 Last Modified: March 10, 2026, 4:05 p.m.

0.0

CVE-2025-53517 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2025. Notes: none.

📅 Published: July 29, 2025, 4:01 p.m. 🔄 Last Modified: March 16, 2026, 5:16 p.m.

0.0

CVE-2025-54758 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2025. Notes: none.

📅 Published: July 29, 2025, 3:59 p.m. 🔄 Last Modified: March 16, 2026, 5:16 p.m.

8.1

CVSS3.1

CVE-2025-6505 -

Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on Linux. This vulnerability allows attackers to combine credentials from different sources, potentially leading to client impersonation and unauthorized access.  When…

📅 Published: July 29, 2025, 12:56 p.m. 🔄 Last Modified: Oct. 2, 2025, 5:40 p.m.

8.4

CVSS3.1

CVE-2025-6504 - Possibilities of IP Spoofing via X-Forwarded-For (XFF) Header

In HDP Server versions below 4.6.2.2978 on Linux, unauthorized access could occur via IP spoofing using the X-Forwarded-For header.  Since XFF is a client-controlled header, it could be spoofed, allowing unauthorized access if the spoofed IP matched a whitelisted range. This vulnerability could …

📅 Published: July 29, 2025, 12:56 p.m. 🔄 Last Modified: Oct. 2, 2025, 5:40 p.m.

6.9

CVSS4.0

CVE-2025-54422 - Sandboxie exposes encrypted sandbox key during password change

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.1 and below, a critical security vulnerability exists in password handling mechanisms. During encrypted sandbox creation, user passwords are transmitted via shared memory, expo…

📅 Published: July 29, 2025, 12:47 p.m. 🔄 Last Modified: Aug. 4, 2025, 5:30 p.m.

6.9

CVSS4.0

CVE-2025-7458 - SQLite integer overflow in key info allocation may lead to information disclosure.

An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a la…

📅 Published: July 29, 2025, 12:43 p.m. 🔄 Last Modified: Aug. 11, 2025, 7:11 p.m.
Total resulsts: 347526
Page 4312 of 34,753
« previous page » next page
Filters