7.5

CVSS3.1

CVE-2025-30145 - GeoServer has an Infinite Loop Vulnerability in Jiffle process

GeoServer is an open source server that allows users to share and edit geospatial data. Malicious Jiffle scripts can be executed by GeoServer, either as a rendering transformation in WMS dynamic styles or as a WPS process, that can enter an infinite loop to trigger denial of service. This vulnerabi…

πŸ“… Published: June 10, 2025, 2:58 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 4:11 p.m.

5.3

CVSS3.1

CVE-2025-27505 - GeoServer Missing Authorization on REST API Index

GeoServer is an open source server that allows users to share and edit geospatial data. It is possible to bypass the default REST API security and access the index page. The REST API security handles rest and its subpaths but not rest with an extension (e.g., rest.html). The REST API index can disc…

πŸ“… Published: June 10, 2025, 2:52 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 4:11 p.m.

7.8

CVSS3.1

CVE-2025-5335 - Privilege Ecalation due to Untrusted Search Path Vulnerability

A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in the Autodesk Installer application. Exploitation of this vulnerability may lead to code execution.

πŸ“… Published: June 10, 2025, 2:50 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:51 p.m.

5.5

CVSS3.1

CVE-2024-40625 - GeoServer Coverage REST API Allows Server Side Request Forgery

GeoServer is an open source server that allows users to share and edit geospatial data. The Coverage rest api /workspaces/{workspaceName}/coveragestores/{storeName}/{method}.{format} allows attackers to upload files with a specified url (with {method} equals 'url') with no restrict. This vulnerabil…

πŸ“… Published: June 10, 2025, 2:49 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 4:22 p.m.

5.3

CVSS3.1

CVE-2024-38524 - GWC Home Page communicate version and revision information

GeoServer is an open source server that allows users to share and edit geospatial data. org.geowebcache.GeoWebCacheDispatcher.handleFrontPage(HttpServletRequest, HttpServletResponse) has no check to hide potentially sensitive information from users except for a hidden system property to hide the st…

πŸ“… Published: June 10, 2025, 2:43 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 4:22 p.m.

7.1

CVSS3.1

CVE-2025-26395 - SolarWinds SWOSH DOM-based reflective XSS Vulnerability

SolarWinds Observability Self-Hosted was susceptible to a cross-site scripting (XSS) vulnerability due to an unsanitized field in the URL. The attack requires authentication using an administrator-level account and user interaction is required.

πŸ“… Published: June 10, 2025, 2:41 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 7:17 p.m.

4.8

CVSS3.1

CVE-2025-26394 - SolarWinds SWOSH Open Redirection Vulnerability

SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirect a user to a malicious site. The attack complexity is high, and authentication is required.

πŸ“… Published: June 10, 2025, 2:39 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 7:17 p.m.

8.8

CVSS3.1

CVE-2025-5353 -

A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt stored SQL credentials.

πŸ“… Published: June 10, 2025, 2:39 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:51 p.m.

7.3

CVSS3.1

CVE-2025-22463 -

A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt the stored environment password.

πŸ“… Published: June 10, 2025, 2:39 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:51 p.m.

8.8

CVSS3.1

CVE-2025-22455 -

A hardcoded key in Ivanti Workspace Control before version 10.19.0.0 allows a local authenticated attacker to decrypt stored SQL credentials.

πŸ“… Published: June 10, 2025, 2:38 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:51 p.m.
Total resulsts: 349182
Page 5094 of 34,919
Β« previous page Β» next page
Filters