0.0

CVE-2025-1803 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: March 1, 2025, 12:06 a.m. πŸ”„ Last Modified: March 1, 2025, 1:15 a.m.

9.9

CVSS3.1

CVE-2025-27554 -

ToDesktop before 2024-10-03, as used by Cursor before 2024-10-03 and other applications, allows remote attackers to execute arbitrary commands on the build server (e.g., read secrets from the desktopify config.prod.json file), and consequently deploy updates to any app, via a postinstall script in …

πŸ“… Published: March 1, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-1801 - Aap-gateway: aap-gateway privilege escalation

A flaw was found in the Ansible aap-gateway. Concurrent requests handled by the gateway grpc service can result in concurrency issues due to race condition requests against the proxy. This issue potentially allows a less privileged user to obtain the JWT of a greater privileged user, enabling the s…

πŸ“… Published: March 1, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.6

CVSS4.0

CVE-2024-1509 - Brocade ASCG 3.2.0 web interface does not enforce HSTS, as defined by RFC 6797 for ports 8030 and 8…

Brocade ASCG before 3.2.0 Web Interface is not enforcing HSTS, as defined by RFC 6797. HSTS is an optional response header that can be configured on the server to instruct the browser to only communicate via HTTPS. The lack of HSTS allows downgrade attacks, SSL-stripping man-in-the-middle atta…

πŸ“… Published: Feb. 28, 2025, 9:52 p.m. πŸ”„ Last Modified: April 6, 2026, 2:16 p.m.

4.6

CVSS4.0

CVE-2025-27414 - MinIO SFTP authentication bypass due to improperly trusted SSH key

MinIO is a high performance object storage. Starting in RELEASE.2024-06-06T09-36-42Z and prior to RELEASE.2025-02-28T09-55-16Z, a bug in evaluating the trust of the SSH key used in an SFTP connection to MinIO allows authentication bypass and unauthorized data access. On a MinIO server with SFTP ac…

πŸ“… Published: Feb. 28, 2025, 9:06 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-27413 - PwnDoc Arbitrary File Write to RCE using Path Traversal in template update from backup templates.js…

PwnDoc is a penetration test reporting application. Prior to version 1.2.0, the backup restore functionality allows an administrator to import raw data into the database, including Path Traversal (`../`) sequences. This is problematic for the template update functionality as it uses the path from t…

πŸ“… Published: Feb. 28, 2025, 9:02 p.m. πŸ”„ Last Modified: April 15, 2025, 8:27 p.m.

6.5

CVSS3.1

CVE-2025-27410 - PwnDoc Arbitrary File Write to RCE using Path Traversal in backup restore as admin

PwnDoc is a penetration test reporting application. Prior to version 1.2.0, the backup restore functionality is vulnerable to path traversal in the TAR entry's name, allowing an attacker to overwrite any file on the system with their content. By overwriting an included `.js` file and restarting the…

πŸ“… Published: Feb. 28, 2025, 9 p.m. πŸ”„ Last Modified: April 16, 2025, 1:04 p.m.

6.3

CVSS4.0

CVE-2025-0769 - PixelYourSite 10.1.1.1 - Insecure deserialization

PixelYourSite - Your smart PIXEL (TAG) and API Manager 10.1.1.1 was found to be vulnerable. Unvalidated user input is used directly in an unserialize function in myapp/modules/facebook/facebook-server-a sync-task.php.

πŸ“… Published: Feb. 28, 2025, 8:01 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-0160 - IBM FlashSystem code execution

IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 through 8.6.0.5, 8.6.1.0, 8.6.2.0 through 8.6.2.1, 8.6.3.0, 8.7.0.0 through 8.7.0.2, 8.7.1.0, 8.7.2.0 through 8.7.2.1) could allow a remote attacker with a…

πŸ“… Published: Feb. 28, 2025, 7:02 p.m. πŸ”„ Last Modified: Aug. 18, 2025, 6:21 p.m.

9.1

CVSS3.1

CVE-2025-0159 - IBM FlashSystem authentication bypass

IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 through 8.6.0.5, 8.6.1.0, 8.6.2.0 through 8.6.2.1, 8.6.3.0, 8.7.0.0 through 8.7.0.2, 8.7.1.0, 8.7.2.0 through 8.7.2.1) could allow a remote attacker to bypa…

πŸ“… Published: Feb. 28, 2025, 7:01 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:29 p.m.
Total resulsts: 349182
Page 6511 of 34,919
Β« previous page Β» next page
Filters