4.4

CVSS3.1

CVE-2025-24909 - Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Pag…

Overview   The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. (CWE-79)   Description   Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.…

📅 Published: April 16, 2025, 10:30 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2025-24908 - Hitachi Vantara Pentaho Data Integration & Analytics – Path Traversal

Overview   The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory. (CWE-35)   Descriptio…

📅 Published: April 16, 2025, 10:27 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-0756 - Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('R…

Overview   The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control. (CWE-99)   Description   Hitachi Vantara Pentaho D…

📅 Published: April 16, 2025, 10:23 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.4

CVSS3.1

CVE-2025-0757 - Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Pag…

Overview   The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. (CWE-79)   Description   Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.2…

📅 Published: April 16, 2025, 10:18 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-0758 - Hitachi Vantara Pentaho Business Analytics Server - Incorrect Permission Assignment for Critical Re…

Overview  The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. (CWE-732)  Description  Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.2.0.2, including 9.3.x and 8.3.x, is i…

📅 Published: April 16, 2025, 10:12 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-32791 - Permission policy information leakage in Backstage permission system

The Backstage Scaffolder plugin houses types and utilities for building scaffolder-related modules. A vulnerability in the Backstage permission plugin backend allows callers to extract some information about the conditional decisions returned by the permission policy installed in the permission bac…

📅 Published: April 16, 2025, 9:46 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

3.1

CVSS3.1

CVE-2025-32789 - EspoCRM Allows Potential Disclosure of Sensitive Information in the User Sorting Function

EspoCRM is an Open Source Customer Relationship Management software. Prior to version 9.0.7, users can be sorted by their password hash. This flaw allows an attacker to make assumptions about the hash values of other users stored in the password column of the user table, based on the results of the…

📅 Published: April 16, 2025, 9:45 p.m. 🔄 Last Modified: June 18, 2025, 1:08 p.m.

3.1

CVSS3.1

CVE-2025-32787 - SoftEtherVPN Affected by NULL dereference in DeleteIPv6DefaultRouterInRA

SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. Versions 5.02.5184 to 5.02.5187 are vulnerable to NULL dereference in `DeleteIPv6DefaultRouterInRA` called by `StorePacket`. Before dereferencing, `DeleteIPv6DefaultRouterInRA` does not account for `ParsePacket` returning N…

📅 Published: April 16, 2025, 9:41 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.7

CVSS3.1

CVE-2025-32783 - XWiki allows unregistered users to see "public" messages from a closed wiki via notifications from …

XWiki Platform is a generic wiki platform. A vulnerability in versions from 5.0 to 16.7.1 affects users with Message Stream enabled and a wiki configured as closed from selecting "Prevent unregistered users to view pages" in the Administrations Rights. The vulnerability is that any message sent in …

📅 Published: April 16, 2025, 9:38 p.m. 🔄 Last Modified: April 30, 2025, 3:56 p.m.

10

CVSS3.1

CVE-2025-32433 - Erlang/OTP SSH Vulnerable to Pre-Authentication RCE

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor c…

📅 Published: April 16, 2025, 9:34 p.m. 🔄 Last Modified: Feb. 26, 2026, 6:28 p.m.
Total resulsts: 346546
Page 5496 of 34,655
« previous page » next page
Filters