4.5

CVSS4.0

CVE-2025-24807 - Fast DDS does not verify Permissions CA

eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.6.10, 2.10.7, 2.14.5, 3.0.2, 3.1.2, and 3.2.0, per design, PermissionsCA is not full chain validated, nor is the expiration date validated. Access cont…

πŸ“… Published: Feb. 11, 2025, 3:31 p.m. πŸ”„ Last Modified: Feb. 21, 2025, 3:26 p.m.

0.0

CVE-2025-1234 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: Feb. 11, 2025, 3:30 p.m. πŸ”„ Last Modified: July 5, 2025, 11:15 p.m.

7.1

CVSS3.1

CVE-2024-13813 -

Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to delete arbitrary files.

πŸ“… Published: Feb. 11, 2025, 3:26 p.m. πŸ”„ Last Modified: Feb. 20, 2025, 3:56 p.m.

6

CVSS3.1

CVE-2024-13843 -

Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.

πŸ“… Published: Feb. 11, 2025, 3:26 p.m. πŸ”„ Last Modified: Feb. 20, 2025, 3:55 p.m.

6

CVSS3.1

CVE-2024-13842 -

A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.

πŸ“… Published: Feb. 11, 2025, 3:25 p.m. πŸ”„ Last Modified: Feb. 20, 2025, 3:55 p.m.

6.1

CVSS3.1

CVE-2024-13830 -

Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.

πŸ“… Published: Feb. 11, 2025, 3:22 p.m. πŸ”„ Last Modified: Feb. 13, 2025, 5:09 p.m.

6.8

CVSS3.1

CVE-2024-12058 -

External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to read arbitrary files.

πŸ“… Published: Feb. 11, 2025, 3:21 p.m. πŸ”„ Last Modified: July 16, 2025, 4 p.m.

9.1

CVSS3.1

CVE-2024-10644 -

Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

πŸ“… Published: Feb. 11, 2025, 3:20 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

8.2

CVSS3.1

CVE-2025-24897 - Misskey CSRF vulnerability due to insecure configuration of authentication cookie attributes

Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, due to a lack of CSRF protection and the lack of proper security attributes in the authentication cookies of Bull's dashboard, some of the APIs of bull-board may be subjec…

πŸ“… Published: Feb. 11, 2025, 3:20 p.m. πŸ”„ Last Modified: Nov. 26, 2025, 4:32 p.m.

9.9

CVSS3.1

CVE-2025-22467 -

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution.

πŸ“… Published: Feb. 11, 2025, 3:20 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.
Total resulsts: 349182
Page 6793 of 34,919
Β« previous page Β» next page
Filters