6.5

CVSS3.1

CVE-2025-0367 - Regular Expression Denial of Service (ReDoS) in Splunk Supporting Add-on for Active Directory (SA-lโ€ฆ

In versions 3.1.0 and lower of the Splunk Supporting Add-on for Active Directory, also known as SA-ldapsearch, a vulnerable regular expression pattern could lead to a Regular Expression Denial of Service (ReDoS) attack.

๐Ÿ“… Published: Jan. 30, 2025, 5:04 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-0873 - itsourcecode Tailoring Management System customeredit.php sql injection

A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /customeredit.php. The manipulation of the argument id/address/fullname/phonenumber/email/city/comment leads to sql injection. Theโ€ฆ

๐Ÿ“… Published: Jan. 30, 2025, 5 p.m. ๐Ÿ”„ Last Modified: Feb. 12, 2025, 7:51 p.m.

5.1

CVSS3.1

CVE-2025-24099 - Local Privilege Escalation in macOS via Improper Permissions Checks

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A local attacker may be able to elevate their privileges.

๐Ÿ“… Published: Jan. 30, 2025, 4:32 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 3:45 a.m.

5.3

CVSS4.0

CVE-2025-0872 - itsourcecode Tailoring Management System addpayment.php sql injection

A vulnerability classified as critical has been found in itsourcecode Tailoring Management System 1.0. Affected is an unknown function of the file /addpayment.php. The manipulation of the argument id/amount/desc/inccat leads to sql injection. It is possible to launch the attack remotely. The exploiโ€ฆ

๐Ÿ“… Published: Jan. 30, 2025, 4 p.m. ๐Ÿ”„ Last Modified: Feb. 7, 2025, 2:07 p.m.

8.7

CVSS4.0

CVE-2025-24883 - go-ethereum has a DoS via malicious p2p message

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdown/crash using a specially crafted message. This vulnerability is fixed in 1.14.13.

๐Ÿ“… Published: Jan. 30, 2025, 3:58 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-24376 - The kubewarden-controller AdmissionPolicy and AdmissionPolicyGroup policies can be used to alter Poโ€ฆ

kubewarden-controller is a Kubernetes controller that allows you to dynamically register Kubewarden admission policies. By design, AdmissionPolicy and AdmissionPolicyGroup can evaluate only namespaced resources. The resources to be evaluated are determined by the rules provided by the user when defโ€ฆ

๐Ÿ“… Published: Jan. 30, 2025, 3:51 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-24784 - kubewarden-controller has an Information leak via AdmissionPolicyGroup Resource

kubewarden-controller is a Kubernetes controller that allows you to dynamically register Kubewarden admission policies. The policy group feature, added to by the 1.17.0 release. By being namespaced, the AdmissionPolicyGroup has a well constrained impact on cluster resources. Hence, itโ€™s considered โ€ฆ

๐Ÿ“… Published: Jan. 30, 2025, 3:39 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.7

CVSS3.1

CVE-2025-22222 - VMware Aria Operations information disclosure vulnerability (CVE-2025-22222)

VMware Aria Operations contains an information disclosure vulnerability.ย A malicious user with non-administrative privilegesย may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known.

๐Ÿ“… Published: Jan. 30, 2025, 3:32 p.m. ๐Ÿ”„ Last Modified: May 14, 2025, 4:47 p.m.

5.2

CVSS3.1

CVE-2025-22221 - VMware Aria Operations for Logs stored cross-site scripting vulnerability (CVE-2025-22221)

VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability.ย A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when performing a delete action in the Agent Configurโ€ฆ

๐Ÿ“… Published: Jan. 30, 2025, 3:30 p.m. ๐Ÿ”„ Last Modified: May 14, 2025, 4:47 p.m.

6.8

CVSS3.1

CVE-2025-23216 - Argo CD does not scrub secret values from patch errors

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that exposed secret values in error messages and the diff view when an invalid Kubernetes Secret resource was synced from a repository. The vulnerability assumes the user has write acโ€ฆ

๐Ÿ“… Published: Jan. 30, 2025, 3:30 p.m. ๐Ÿ”„ Last Modified: June 6, 2025, 3:44 p.m.
Total resulsts: 349182
Page 6906 of 34,919
ยซ previous page ยป next page
Filters