4.8

CVSS3.1

CVE-2025-24513 - ingress-nginx controller - auth secret file path traversal vulnerability

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where attacker-provided data are included in a filename by the ingress-nginx Admission Controller feature, resulting in directory traversal within the container. This could result in denial of service, or…

πŸ“… Published: March 24, 2025, 11:29 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-1098 - ingress-nginx controller - configuration injection via unsanitized mirror annotations

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mirror-host` Ingress annotations can be used to inject arbitrary configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx cont…

πŸ“… Published: March 24, 2025, 11:29 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-1097 - ingress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of…

πŸ“… Published: March 24, 2025, 11:29 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-1974 - ingress-nginx admission controller RCE escalation

A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note th…

πŸ“… Published: March 24, 2025, 11:28 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-2716 - China Mobile P22g-CIac Samba Path path traversal

A vulnerability classified as problematic was found in China Mobile P22g-CIac 1.0.00.488. This vulnerability affects unknown code of the component Samba Path Handler. The manipulation leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may…

πŸ“… Published: March 24, 2025, 11 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-2715 - timschofield webERP Confirm Dispatch and Invoice Page ConfirmDispatch_Invoice.php cross site script…

A vulnerability classified as problematic has been found in timschofield webERP up to 5.0.0.rc+13. This affects an unknown part of the file ConfirmDispatch_Invoice.php of the component Confirm Dispatch and Invoice Page. The manipulation of the argument Narrative leads to cross site scripting. It is…

πŸ“… Published: March 24, 2025, 10:31 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.9

CVSS3.1

CVE-2025-26512 - CVE-2025-26512 Privilege Escalation Vulnerability in SnapCenter

SnapCenter versions prior to 6.0.1P1 and 6.1P1 are susceptible to a vulnerability which may allow an authenticated SnapCenter Server user to become an admin user on a remote system where a SnapCenter plug-in has been installed.

πŸ“… Published: March 24, 2025, 10:06 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

5.3

CVSS4.0

CVE-2025-2714 - JoomlaUX JUX Real Estate addagent cross site scripting

A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /extensions/realestate/index.php/agents/agent-register/addagent. The manipulation of the argument plan_id leads to cross site scripting. Th…

πŸ“… Published: March 24, 2025, 10 p.m. πŸ”„ Last Modified: July 2, 2025, 7:11 p.m.

0.0

CVE-2025-2778 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: March 24, 2025, 9:52 p.m. πŸ”„ Last Modified: May 7, 2025, 3:15 p.m.

5.3

CVSS4.0

CVE-2025-2712 - Yonyou UFIDA ERP-NC top.jsp cross site scripting

A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /help/top.jsp. The manipulation of the argument langcode leads to cross site scripting. The attack can be launched remotely. The exploit …

πŸ“… Published: March 24, 2025, 9:31 p.m. πŸ”„ Last Modified: July 8, 2025, 6:58 p.m.
Total resulsts: 349182
Page 6231 of 34,919
Β« previous page Β» next page
Filters