5.3

CVSS4.0

CVE-2025-0873 - itsourcecode Tailoring Management System customeredit.php sql injection

A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /customeredit.php. The manipulation of the argument id/address/fullname/phonenumber/email/city/comment leads to sql injection. The…

📅 Published: Jan. 30, 2025, 5 p.m. 🔄 Last Modified: Feb. 12, 2025, 7:51 p.m.

5.1

CVSS3.1

CVE-2025-24099 -

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A local attacker may be able to elevate their privileges.

📅 Published: Jan. 30, 2025, 4:32 p.m. 🔄 Last Modified: April 2, 2026, 7:18 p.m.

5.3

CVSS4.0

CVE-2025-0872 - itsourcecode Tailoring Management System addpayment.php sql injection

A vulnerability classified as critical has been found in itsourcecode Tailoring Management System 1.0. Affected is an unknown function of the file /addpayment.php. The manipulation of the argument id/amount/desc/inccat leads to sql injection. It is possible to launch the attack remotely. The exploi…

📅 Published: Jan. 30, 2025, 4 p.m. 🔄 Last Modified: Feb. 7, 2025, 2:07 p.m.

8.7

CVSS4.0

CVE-2025-24883 - go-ethereum has a DoS via malicious p2p message

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdown/crash using a specially crafted message. This vulnerability is fixed in 1.14.13.

📅 Published: Jan. 30, 2025, 3:58 p.m. 🔄 Last Modified: July 13, 2025, 11:07 a.m.

6.5

CVSS3.1

CVE-2025-24376 - The kubewarden-controller AdmissionPolicy and AdmissionPolicyGroup policies can be used to alter Po…

kubewarden-controller is a Kubernetes controller that allows you to dynamically register Kubewarden admission policies. By design, AdmissionPolicy and AdmissionPolicyGroup can evaluate only namespaced resources. The resources to be evaluated are determined by the rules provided by the user when def…

📅 Published: Jan. 30, 2025, 3:51 p.m. 🔄 Last Modified: Feb. 12, 2025, 7:51 p.m.

4.3

CVSS3.1

CVE-2025-24784 - kubewarden-controller has an Information leak via AdmissionPolicyGroup Resource

kubewarden-controller is a Kubernetes controller that allows you to dynamically register Kubewarden admission policies. The policy group feature, added to by the 1.17.0 release. By being namespaced, the AdmissionPolicyGroup has a well constrained impact on cluster resources. Hence, it’s considered …

📅 Published: Jan. 30, 2025, 3:39 p.m. 🔄 Last Modified: Feb. 12, 2025, 7:51 p.m.

7.7

CVSS3.1

CVE-2025-22222 - VMware Aria Operations information disclosure vulnerability (CVE-2025-22222)

VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known.

📅 Published: Jan. 30, 2025, 3:32 p.m. 🔄 Last Modified: May 14, 2025, 4:47 p.m.

5.2

CVSS3.1

CVE-2025-22221 - VMware Aria Operations for Logs stored cross-site scripting vulnerability (CVE-2025-22221)

VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when performing a delete action in the Agent Configur…

📅 Published: Jan. 30, 2025, 3:30 p.m. 🔄 Last Modified: May 14, 2025, 4:47 p.m.

6.8

CVSS3.1

CVE-2025-23216 - Argo CD does not scrub secret values from patch errors

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that exposed secret values in error messages and the diff view when an invalid Kubernetes Secret resource was synced from a repository. The vulnerability assumes the user has write ac…

📅 Published: Jan. 30, 2025, 3:30 p.m. 🔄 Last Modified: June 6, 2025, 3:44 p.m.

4.3

CVSS3.1

CVE-2025-22220 - VMware Aria Operations for Logs broken access control vulnerability (CVE-2025-22220)

VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operations in the context of an admin user.

📅 Published: Jan. 30, 2025, 3:28 p.m. 🔄 Last Modified: Feb. 26, 2026, 7:08 p.m.
Total resulsts: 343040
Page 6292 of 34,304
« previous page » next page
Filters