6.3

CVSS3.1

CVE-2025-0444 -

Use after free in Skia in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Feb. 4, 2025, 6:53 p.m. πŸ”„ Last Modified: April 8, 2025, 12:26 p.m.

6.3

CVSS4.0

CVE-2025-24373 - Unrestricted Access to PDF Documents via URL Manipulation in woocommerce-pdf-invoices-packing-slips

woocommerce-pdf-invoices-packing-slips is an extension which allows users to create, print & automatically email PDF invoices & packing slips for WooCommerce orders. This vulnerability allows unauthorized users to access any PDF document from a store if they: 1. Have access to a guest document link…

πŸ“… Published: Feb. 4, 2025, 6:45 p.m. πŸ”„ Last Modified: Feb. 19, 2025, 3:45 p.m.

5.4

CVSS3.1

CVE-2024-48019 - Apache Doris: allows admin users to read arbitrary files through the REST API

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in Apache Doris. Application administrators can read arbitrary files from the server filesystem through path traversal. Users are recommended to upgr…

πŸ“… Published: Feb. 4, 2025, 6:19 p.m. πŸ”„ Last Modified: June 9, 2025, 7:49 p.m.

4.7

CVSS3.1

CVE-2025-25039 - Authenticated Remote Command Injection in HPE Aruba Networking ClearPass Policy Manager Web-Based M…

A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager (CPPM) allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as a lower privileged user on …

πŸ“… Published: Feb. 4, 2025, 6:13 p.m. πŸ”„ Last Modified: March 28, 2025, 5:37 p.m.

6.6

CVSS3.1

CVE-2025-23060 - Sensitive Data Exposure Vulnerability in HPE Aruba Networking ClearPass Policy Manager (CPPM)

A vulnerability in HPE Aruba Networking ClearPass Policy Manager may, under certain circumstances, expose sensitive unencrypted information. Exploiting this vulnerability could allow an attacker to perform a man-in-the-middle attack, potentially granting unauthorized access to network resources as …

πŸ“… Published: Feb. 4, 2025, 6:11 p.m. πŸ”„ Last Modified: March 28, 2025, 5:39 p.m.

6.8

CVSS3.1

CVE-2025-23059 - Sensitive Information Disclosure in HPE Aruba Networking ClearPass Policy Manager

A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager exposes directories containing sensitive information. If exploited successfully, this vulnerability allows an authenticated remote attacker with high privileges to access and retrieve sensitive da…

πŸ“… Published: Feb. 4, 2025, 6:10 p.m. πŸ”„ Last Modified: March 28, 2025, 5:53 p.m.

8.8

CVSS3.1

CVE-2025-23058 - Authenticated Broken Access Control Vulnerability in ClearPass Policy Manager Web-Based Management …

A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authenticated remote attacker to gain unauthorized access to data and the ability to execute functions that should be restricted to administrators only with read/write privileges. Succ…

πŸ“… Published: Feb. 4, 2025, 6:07 p.m. πŸ”„ Last Modified: March 28, 2025, 5:55 p.m.

9.8

CVSS3.1

CVE-2025-0364 - BigAntSoft BigAnt Server Account Registration Bypass to File Upload RCE

BigAntSoft BigAnt Server, up to and including version 5.6.06, is vulnerable to unauthenticated remote code execution via account registration. An unauthenticated remote attacker can create an administrative user through the default exposed SaaS registration mechanism. Once an administrator, the att…

πŸ“… Published: Feb. 4, 2025, 5:51 p.m. πŸ”„ Last Modified: Nov. 19, 2025, 8:30 p.m.

5.3

CVSS3.1

CVE-2024-45659 - IBM Security Verify Access information disclosure

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

πŸ“… Published: Feb. 4, 2025, 5:34 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 8:03 p.m.

9.8

CVSS3.1

CVE-2024-9644 - Four-Faith F3x36 bapply.cgi Auth Bypass

The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to an authentication bypass vulnerability in the administrative web server. Authentication is not enforced on some administrative functionality when using the "bapply.cgi" endpoint instead of the normal "apply.cgi" endpoint. A remote …

πŸ“… Published: Feb. 4, 2025, 2:58 p.m. πŸ”„ Last Modified: Nov. 19, 2025, 8:35 p.m.
Total resulsts: 347814
Page 6714 of 34,782
Β« previous page Β» next page
Filters