5.4

CVSS3.1

CVE-2025-2562 -

Insufficient logging in the autotyping feature in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a stored password without generating a corresponding log event, via the use of the autotyping functionality. This issue affects Remote Desktop Manager versions โ€ฆ

๐Ÿ“… Published: March 26, 2025, 5:24 p.m. ๐Ÿ”„ Last Modified: July 2, 2025, 5:32 p.m.

3.6

CVSS3.1

CVE-2025-2528 -

Improper authorization in application password policy in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a configuration different from the one mandated by the system administrators. This issue affects Remote Desktop Manager versions from 2025.1.24 through 20โ€ฆ

๐Ÿ“… Published: March 26, 2025, 5:20 p.m. ๐Ÿ”„ Last Modified: July 2, 2025, 5:32 p.m.

5.3

CVSS3.1

CVE-2025-30352 - Directus `search` query parameter allows enumeration of non permitted fields

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0-alpha.4 and prior to version 11.5.0, the `search` query parameter allows users with access to a collection to filter items based on fields they do not have permission to view. This allows the โ€ฆ

๐Ÿ“… Published: March 26, 2025, 5:18 p.m. ๐Ÿ”„ Last Modified: Aug. 26, 2025, 1:41 a.m.

5.4

CVSS3.1

CVE-2025-2499 -

Client side access control bypass in the permission component in Devolutions Remote Desktop Manager on Windows. An authenticated user can exploit this flaw to bypass certain permission restrictionsโ€”specifically View Password, Edit Asset, and Edit Permissions by performing specific actions. This โ€ฆ

๐Ÿ“… Published: March 26, 2025, 5:14 p.m. ๐Ÿ”„ Last Modified: July 2, 2025, 5:32 p.m.

3.5

CVSS3.1

CVE-2025-30351 - Suspended Directus user can continue to use session token to access API

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.10.0 and prior to version 11.5.0, a suspended user can use the token generated in session auth mode to access the API despite their status. This happens because there is a check missing in `verifโ€ฆ

๐Ÿ“… Published: March 26, 2025, 5:13 p.m. ๐Ÿ”„ Last Modified: Aug. 26, 2025, 1:36 a.m.

5.3

CVSS3.1

CVE-2025-30350 - Directus's S3 assets become unavailable after a burst of HEAD requests

Directus is a real-time API and App dashboard for managing SQL database content. The `@directus/storage-driver-s3` package starting in version 9.22.0 and prior to version 12.0.1, corresponding to Directus starting in version 9.22.0 and prior to 11.5.0, is vulnerable to asset unavailability after a โ€ฆ

๐Ÿ“… Published: March 26, 2025, 4:49 p.m. ๐Ÿ”„ Last Modified: Nov. 18, 2025, 5:44 p.m.

5.3

CVSS3.1

CVE-2025-30225 - Directus's S3 assets become unavailable after a burst of malformed transformations

Directus is a real-time API and App dashboard for managing SQL database content. The `@directus/storage-driver-s3` package starting in version 9.22.0 and prior to version 12.0.1, corresponding to Directus starting in version 9.22.0 and prior to 11.5.0, is vulnerable to asset unavailability after a โ€ฆ

๐Ÿ“… Published: March 26, 2025, 4:27 p.m. ๐Ÿ”„ Last Modified: Nov. 18, 2025, 5:44 p.m.

6.6

CVSS4.0

CVE-2025-30217 - Frappe has possibility of SQL injection due to improper validations

Frappe is a full-stack web application framework. Prior to versions 14.93.2 and 15.55.0, a SQL Injection vulnerability has been identified in Frappe Framework which could allow a malicious actor to access sensitive information. Versions 14.93.2 and 15.55.0 contain a patch for the issue. No known woโ€ฆ

๐Ÿ“… Published: March 26, 2025, 4:18 p.m. ๐Ÿ”„ Last Modified: Aug. 1, 2025, 6:04 p.m.

4.1

CVSS3.1

CVE-2025-30164 - Icinga Web 2 has open redirect on login page

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 vulnerability allows an attacker to craft a URL that, once visited by an authenticated user (or one that is able to authenticate), allows to manipulโ€ฆ

๐Ÿ“… Published: March 26, 2025, 4:13 p.m. ๐Ÿ”„ Last Modified: Aug. 1, 2025, 3:02 p.m.

1.1

CVSS4.0

CVE-2025-27609 - Icinga Web 2 Vulnerable to Reflected XSS

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a request that, once transmitted to a victim's Icinga Web, allows to embed arbitrary Javascript into it and to act on beโ€ฆ

๐Ÿ“… Published: March 26, 2025, 4:10 p.m. ๐Ÿ”„ Last Modified: Aug. 1, 2025, 3:11 p.m.
Total resulsts: 346671
Page 5949 of 34,668
ยซ previous page ยป next page
Filters