8.5

CVSS4.0

CVE-2025-2288 - Local Code Execution Vulnerability in Arena®

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose information and execute arbit…

📅 Published: April 8, 2025, 3:19 p.m. 🔄 Last Modified: July 14, 2025, 7:14 p.m.

8.5

CVSS4.0

CVE-2025-2287 - Local Code Execution Vulnerability in Arena®

A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerabili…

📅 Published: April 8, 2025, 3:16 p.m. 🔄 Last Modified: July 14, 2025, 7:14 p.m.

8.5

CVSS4.0

CVE-2025-2286 - Local Code Execution Vulnerability in Arena®

A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerabili…

📅 Published: April 8, 2025, 3:16 p.m. 🔄 Last Modified: July 14, 2025, 7:13 p.m.

8.5

CVSS4.0

CVE-2025-2285 - Local Code Execution Vulnerability in Arena®

A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerabili…

📅 Published: April 8, 2025, 3:15 p.m. 🔄 Last Modified: July 14, 2025, 7:14 p.m.

6.9

CVSS4.0

CVE-2025-32025 - bep/imagemeta allows a potentially large memory allocation in PNG and WebP parsing

bep/imagemeta is a Go library for reading EXIF, IPTC and XMP image meta data from JPEG, TIFF, PNG, and WebP files. The buffer created for parsing metadata for PNG and WebP images was only bounded by their input data type, which could lead to potentially large memory allocation, and unreasonably hig…

📅 Published: April 8, 2025, 3:13 p.m. 🔄 Last Modified: April 8, 2025, 6:13 p.m.

8.8

CVSS3.1

CVE-2025-1095 - IBM Personal Communications command execution

IBM Personal Communications v14 and v15 include a Windows service that is vulnerable to local privilege escalation (LPE). The vulnerability allows any interactively logged in users on the target computer to run commands with full privileges in the context of NT AUTHORITY\SYSTEM. This allows for a l…

📅 Published: April 8, 2025, 3:11 p.m. 🔄 Last Modified: Feb. 26, 2026, 6:28 p.m.

6.9

CVSS4.0

CVE-2025-32024 - bep/imagemeta allows excessively large EXIF data structures

bep/imagemeta is a Go library for reading EXIF, IPTC and XMP image meta data from JPEG, TIFF, PNG, and WebP files. The EXIF data format allows for defining excessively large data structures in relatively small payloads. Before v0.10.0, If you didn't trust the input images, this could be abused to c…

📅 Published: April 8, 2025, 3:10 p.m. 🔄 Last Modified: April 8, 2025, 6:13 p.m.

9.3

CVSS4.0

CVE-2025-32020 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in crud-query-…

The crud-query-parser library parses query parameters from HTTP requests and converts them to database queries. Improper neutralization of the order/sort parameter in the TypeORM adapter, which allows SQL injection. You are impacted by this vulnerability if you are using the TypeORM adapter, orderi…

📅 Published: April 8, 2025, 3:05 p.m. 🔄 Last Modified: April 8, 2025, 6:13 p.m.

8.2

CVSS3.1

CVE-2025-22466 -

Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.

📅 Published: April 8, 2025, 2:27 p.m. 🔄 Last Modified: May 16, 2025, 2 p.m.

6.1

CVSS3.1

CVE-2025-22465 -

Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to execute arbitrary javascript in a victim's browser. Unlikely user interaction is required.

📅 Published: April 8, 2025, 2:27 p.m. 🔄 Last Modified: May 16, 2025, 2 p.m.
Total resulsts: 344126
Page 5462 of 34,413
« previous page » next page
Filters