6.5

CVSS3.0

CVE-2025-2838 - Silicon Labs Gecko OS DNS Response Processing Infinite Loop Denial-of-Service Vulnerability

Silicon Labs Gecko OS DNS Response Processing Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability.…

📅 Published: March 26, 2025, 9:16 p.m. 🔄 Last Modified: Aug. 8, 2025, 1 a.m.

8.8

CVSS3.0

CVE-2025-2837 - Silicon Labs Gecko OS HTTP Request Handling Stack-based Buffer Overflow Remote Code Execution Vulne…

Silicon Labs Gecko OS HTTP Request Handling Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerabilit…

📅 Published: March 26, 2025, 9:16 p.m. 🔄 Last Modified: Aug. 8, 2025, 1:03 a.m.

8.7

CVSS4.0

CVE-2025-2787 - Ingress-nginx vulnerability in KNIME Business Hub

KNIME Business Hub is affected by the Ingress-nginx CVE-2025-1974 ( a.k.a IngressNightmare ) vulnerability which affects the ingress-nginx component. In the worst case a complete takeover of the Kubernetes cluster is possible. Since the affected component is only reachable from within the cluster, …

📅 Published: March 26, 2025, 9:08 p.m. 🔄 Last Modified: Oct. 8, 2025, 5:19 p.m.

6.8

CVSS3.1

CVE-2025-2600 -

Improper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use the ELEVATED_PASSWORD variable even though not allowed by the "Allow password in variable policy". This issue affects Remote Desktop Manager versions from 2025…

📅 Published: March 26, 2025, 5:37 p.m. 🔄 Last Modified: Aug. 26, 2025, 6:15 p.m.

8.6

CVSS3.1

CVE-2025-30353 - Directus's webhook trigger flows can leak sensitive data

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.5.0, when a Flow with the "Webhook" trigger and the "Data of Last Operation" response body encounters a ValidationError thrown by a failed condition operation, the API…

📅 Published: March 26, 2025, 5:26 p.m. 🔄 Last Modified: Aug. 26, 2025, 1:47 a.m.

5.4

CVSS3.1

CVE-2025-2562 -

Insufficient logging in the autotyping feature in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a stored password without generating a corresponding log event, via the use of the autotyping functionality. This issue affects Remote Desktop Manager versions …

📅 Published: March 26, 2025, 5:24 p.m. 🔄 Last Modified: July 2, 2025, 5:32 p.m.

3.6

CVSS3.1

CVE-2025-2528 -

Improper authorization in application password policy in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a configuration different from the one mandated by the system administrators. This issue affects Remote Desktop Manager versions from 2025.1.24 through 20…

📅 Published: March 26, 2025, 5:20 p.m. 🔄 Last Modified: July 2, 2025, 5:32 p.m.

5.3

CVSS3.1

CVE-2025-30352 - Directus `search` query parameter allows enumeration of non permitted fields

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0-alpha.4 and prior to version 11.5.0, the `search` query parameter allows users with access to a collection to filter items based on fields they do not have permission to view. This allows the …

📅 Published: March 26, 2025, 5:18 p.m. 🔄 Last Modified: Aug. 26, 2025, 1:41 a.m.

5.4

CVSS3.1

CVE-2025-2499 -

Client side access control bypass in the permission component in Devolutions Remote Desktop Manager on Windows. An authenticated user can exploit this flaw to bypass certain permission restrictions—specifically View Password, Edit Asset, and Edit Permissions by performing specific actions. This …

📅 Published: March 26, 2025, 5:14 p.m. 🔄 Last Modified: July 2, 2025, 5:32 p.m.

3.5

CVSS3.1

CVE-2025-30351 - Suspended Directus user can continue to use session token to access API

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.10.0 and prior to version 11.5.0, a suspended user can use the token generated in session auth mode to access the API despite their status. This happens because there is a check missing in `verif…

📅 Published: March 26, 2025, 5:13 p.m. 🔄 Last Modified: Aug. 26, 2025, 1:36 a.m.
Total resulsts: 346656
Page 5947 of 34,666
« previous page » next page
Filters