9.3

CVSS4.0

CVE-2025-4658 - Authentication Bypass in OPKSSH

Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification. As OPKSSH depends on the OpenPubkey library for authentication, this vulnerability in OpenPubkey also applies to OPKSSH versions prior to 0.5.0 and woโ€ฆ

๐Ÿ“… Published: May 13, 2025, 4:33 p.m. ๐Ÿ”„ Last Modified: May 22, 2025, 6:43 p.m.

9.3

CVSS4.0

CVE-2025-3757 - Authentication Bypass in OpenPubKey

Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification.

๐Ÿ“… Published: May 13, 2025, 4:33 p.m. ๐Ÿ”„ Last Modified: May 23, 2025, 6:56 p.m.

1.8

CVSS4.0

CVE-2025-47278 - Flask uses fallback key instead of current signing key

Flask is a web server gateway interface (WSGI) web application framework. In Flask 3.1.0, the way fallback key configuration was handled resulted in the last fallback key being used for signing, rather than the current signing key. Signing is provided by the `itsdangerous` library. A list of keys cโ€ฆ

๐Ÿ“… Published: May 13, 2025, 3:57 p.m. ๐Ÿ”„ Last Modified: May 13, 2025, 8:14 p.m.

7.2

CVSS3.1

CVE-2025-4428 - Remote Code Execution

Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.

๐Ÿ“… Published: May 13, 2025, 3:46 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

5.3

CVSS3.1

CVE-2025-4427 - Authentication Bypass

An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.

๐Ÿ“… Published: May 13, 2025, 3:45 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

7.5

CVSS3.1

CVE-2025-47276 - Actualizer Uses OpenSSL's "-passwd" Function Which Uses SHA512 Under The Hood Instead of Proper Paโ€ฆ

Actualizer is a single shell script solution to allow developers and embedded engineers to create Debian operating systems (OS). Prior to version 1.2.0, Actualizer uses OpenSSL's "-passwd" function, which uses SHA512 instead of a more suitable password hasher like Yescript/Argon2i. All Actualizer โ€ฆ

๐Ÿ“… Published: May 13, 2025, 3:34 p.m. ๐Ÿ”„ Last Modified: May 13, 2025, 7:35 p.m.

6

CVSS4.0

CVE-2025-46721 - nosurf vulnerable to CSRF due to non-functional same-origin request checks

nosurf is cross-site request forgery (CSRF) protection middleware for Go. A vulnerability in versions prior to 1.2.0 allows an attacker who controls content on the target site, or on a subdomain of the target site (either via XSS, or otherwise) to bypass CSRF checks and issue requests on user's behโ€ฆ

๐Ÿ“… Published: May 13, 2025, 3:29 p.m. ๐Ÿ”„ Last Modified: June 23, 2025, 2:55 p.m.

6.3

CVSS4.0

CVE-2025-31493 - Path traversal of collection names during file system lookup

Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby sites that use the `collection()` helper or `$kirby->collection()` method with a dynamic collection name (such as a collection name that depends on request or user โ€ฆ

๐Ÿ“… Published: May 13, 2025, 3:24 p.m. ๐Ÿ”„ Last Modified: Aug. 26, 2025, 2:33 p.m.

2.3

CVSS4.0

CVE-2025-30207 - Kirby vulnerable to path traversal in the router for PHP's built-in server

Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby setups that use PHP's built-in server. Such setups are commonly only used during local development. Sites that use other server software (such as Apache, nginx or Cโ€ฆ

๐Ÿ“… Published: May 13, 2025, 3:20 p.m. ๐Ÿ”„ Last Modified: Aug. 26, 2025, 2:44 p.m.

9.8

CVSS3.1

CVE-2025-22462 -

An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Security Patch allows a remote unauthenticated attacker to gain administrative access to the system.

๐Ÿ“… Published: May 13, 2025, 3:10 p.m. ๐Ÿ”„ Last Modified: July 16, 2025, 6:32 p.m.
Total resulsts: 342847
Page 4806 of 34,285
ยซ previous page ยป next page
Filters