6.8

CVSS3.0

CVE-2023-39338 -

Enables an authenticated user (enrolled device) to access a service protected by Sentry even if they are not authorized according to the sentry policy to access that service. It does not enable the user to authenticate to or use the service, it just provides the tunnel access.

πŸ“… Published: July 12, 2025, 3:30 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.7

CVSS3.1

CVE-2024-38648 -

A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user credentials.

πŸ“… Published: July 12, 2025, 3:30 a.m. πŸ”„ Last Modified: July 17, 2025, 1:36 p.m.

9.8

CVSS3.1

CVE-2023-38036 -

A security vulnerability within Ivanti Avalanche Manager before version 6.4.1 may allow an unauthenticated attacker to create a buffer overflow that could result in service disruption or arbitrary code execution.

πŸ“… Published: July 12, 2025, 3:30 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

7.5

CVSS3.1

CVE-2025-24294 - resolv: Denial of Service in resolv gem

The attack vector is a potential Denial of Service (DoS). The vulnerability is caused by an insufficient check on the length of a decompressed domain name within a DNS packet. An attacker can craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses …

πŸ“… Published: July 12, 2025, 3:30 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2025-5199 - LPE on Multipass for macOS

In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker to escalate privileges by modifying files executed with administrative privileges by a Launch Daemon during system startup.

πŸ“… Published: July 11, 2025, 11:21 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 6:37 p.m.

8.7

CVSS4.0

CVE-2025-7460 - TOTOLINK T6 HTTP POST Request cstecgi.cgi setWiFiAclRules buffer overflow

A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnerability is the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument mac leads to buffer overflow. …

πŸ“… Published: July 11, 2025, 9:32 p.m. πŸ”„ Last Modified: July 16, 2025, 2:58 p.m.

5.4

CVSS3.1

CVE-2025-53636 - Open OnDemand Shell App closed websocket DoS

Open OnDemand is an open-source HPC portal. Users can flood logs by interacting with the shell app and generating many errors. Users who flood logs can create very large log files causing a Denial of Service (DoS) to the ondemand system. This vulnerability is fixed in 3.1.14 and 4.0.6.

πŸ“… Published: July 11, 2025, 9:20 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-7459 - code-projects Mobile Shop EditMobile.php sql injection

A vulnerability classified as critical was found in code-projects Mobile Shop 1.0. This vulnerability affects unknown code of the file /EditMobile.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and …

πŸ“… Published: July 11, 2025, 9:02 p.m. πŸ”„ Last Modified: July 16, 2025, 2:58 p.m.

6.9

CVSS4.0

CVE-2025-7457 - Campcodes Online Movie Theater Seat Reservation System manage_movie.php sql injection

A vulnerability, which was classified as critical, was found in Campcodes Online Movie Theater Seat Reservation System 1.0. This affects an unknown part of the file /admin/manage_movie.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. T…

πŸ“… Published: July 11, 2025, 8:32 p.m. πŸ”„ Last Modified: July 16, 2025, 2:58 p.m.

6.9

CVSS4.0

CVE-2025-7456 - Campcodes Online Movie Theater Seat Reservation System reserve.php sql injection

A vulnerability, which was classified as critical, has been found in Campcodes Online Movie Theater Seat Reservation System 1.0. Affected by this issue is some unknown functionality of the file /reserve.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remo…

πŸ“… Published: July 11, 2025, 8:02 p.m. πŸ”„ Last Modified: July 16, 2025, 2:59 p.m.
Total resulsts: 349182
Page 4669 of 34,919
Β« previous page Β» next page
Filters