6.1

CVSS3.1

CVE-2025-32802 - Insecure handling of file paths allows multiple local attacks

Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in insecure paths. This issue affects Kea versions 2.4โ€ฆ

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-48749 -

Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent Data.

๐Ÿ“… Published: May 28, 2025, midnight ๐Ÿ”„ Last Modified: June 18, 2025, 11:59 p.m.

5.5

CVSS3.1

CVE-2024-45094 - IBM DS8900F and DS8A00 Hardware Management Console (HMC) cross-site scripting

IBM DS8900F and DS8A00 Hardware Management Console (HMC)ย is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trustedโ€ฆ

๐Ÿ“… Published: May 27, 2025, 10:41 p.m. ๐Ÿ”„ Last Modified: Aug. 26, 2025, 3:03 p.m.

2.6

CVSS3.1

CVE-2025-2826 - n affected platforms running Arista EOS, ACL policies may not be enforced. IPv4 ingress ACL, MAC inโ€ฆ

n affected platforms running Arista EOS, ACL policies may not be enforced. IPv4 ingress ACL, MAC ingress ACL, or IPv6 standard ingress ACL enabled on one or more ethernet or LAG interfaces may result in ACL policies not being enforced for ingress packets. This can cause incoming packets to incorrecโ€ฆ

๐Ÿ“… Published: May 27, 2025, 10:22 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-2796 - On affected platforms with hardware IPSec support running Arista EOS with IPsec enabled and anti-reโ€ฆ

On affected platforms with hardware IPSec support running Arista EOS with IPsec enabled and anti-replay protection configured, EOS may exhibit unexpected behavior in specific cases. Received duplicate encrypted packets, which should be dropped under normal anti-replay protection, will instead be foโ€ฆ

๐Ÿ“… Published: May 27, 2025, 10:16 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-11185 - On affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain condiโ€ฆ

On affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain conditions, be improperly forwarded to ports associated with different VLANs, resulting in a breach of VLAN isolation and segmentation boundaries.

๐Ÿ“… Published: May 27, 2025, 10:11 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS3.1

CVE-2025-32440 - NetAlertX Vulnerable to Authentication Bypass

NetAlertX is a network, presence scanner and alert framework. Prior to version 25.4.14, it is possible to bypass the authentication mechanism of NetAlertX to update settings without authentication. An attacker can trigger sensitive functions within util.php by sending crafted requests to /index.phpโ€ฆ

๐Ÿ“… Published: May 27, 2025, 9:59 p.m. ๐Ÿ”„ Last Modified: July 11, 2025, 6:58 p.m.

6.5

CVSS3.1

CVE-2025-40911 - Net::CIDR::Set versions 0.10 through 0.13 for Perl does not properly consider leading zero characteโ€ฆ

Net::CIDR::Set versions 0.10 through 0.13 for Perl does not properly handle leading zero characters in IP CIDR address strings, which could allow attackers to bypass access control that is based on IP addresses. Leading zeros are used to indicate octal numbers, which can confuse users who are inteโ€ฆ

๐Ÿ“… Published: May 27, 2025, 9:17 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-5067 -

Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

๐Ÿ“… Published: May 27, 2025, 8:43 p.m. ๐Ÿ”„ Last Modified: May 29, 2025, 3:50 p.m.

5.4

CVSS3.1

CVE-2025-5281 -

Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially obtain user information via a crafted HTML page. (Chromium security severity: Medium)

๐Ÿ“… Published: May 27, 2025, 8:43 p.m. ๐Ÿ”„ Last Modified: May 29, 2025, 3:50 p.m.
Total resulsts: 345925
Page 4914 of 34,593
ยซ previous page ยป next page
Filters