9.1

CVSS3.1

CVE-2025-20125 - Cisco Identity Services Engine Insufficient Authorization Bypass Vulnerability

A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information, change node configurations, and restart the node. This vulnerability is due to a lack of authorization in a specific API and improper validation …

📅 Published: Feb. 5, 2025, 4:12 p.m. 🔄 Last Modified: March 28, 2025, 1:37 p.m.

9.9

CVSS3.1

CVE-2025-20124 - Cisco Identity Services Engine Java Deserialization Vulnerability

A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands as the root user on an affected device. This vulnerability is due to insecure deserialization of user-supplied Java byte streams by the affected software. An attacker could exploit …

📅 Published: Feb. 5, 2025, 4:12 p.m. 🔄 Last Modified: Feb. 26, 2026, 7:09 p.m.

8.7

CVSS4.0

CVE-2024-39564 - Junos OS and Junos OS Evolved: Receipt of malformed BGP path attributes leads to RPD crash

This is a similar, but different vulnerability than the issue reported as CVE-2024-39549. A double-free vulnerability in the routing process daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a malformed BGP Path attribute update which allocates memory used t…

📅 Published: Feb. 5, 2025, 3:31 p.m. 🔄 Last Modified: Jan. 26, 2026, 6:28 p.m.

5.5

CVSS3.1

CVE-2024-42207 - HCL iAutomate is affected by a session fixation vulnerability

HCL iAutomate is affected by a session fixation vulnerability.  An attacker could hijack a victim's session ID from their authenticated session.

📅 Published: Feb. 5, 2025, 3:11 p.m. 🔄 Last Modified: Oct. 10, 2025, 4:27 p.m.

5.8

CVSS4.0

CVE-2025-0858 - Certain Poly Devices – Path Traversal Vulnerability - Arbitrary File Access by Unauthorized User

A vulnerability was discovered in the firmware builds up to 8.2.1.0820 in certain Poly devices. The firmware flaw does not properly prevent path traversal and could lead to information disclosure.

📅 Published: Feb. 5, 2025, 2:28 p.m. 🔄 Last Modified: March 27, 2025, 2:15 p.m.

6.6

CVSS3.1

CVE-2025-21117 -

Dell Avamar, version 19.4 or later, contains an access token reuse vulnerability in the AUI. A low privileged local attacker could potentially exploit this vulnerability, leading to fully impersonating the user.

📅 Published: Feb. 5, 2025, 1:10 p.m. 🔄 Last Modified: March 28, 2025, 1:24 p.m.

3.5

CVSS3.1

CVE-2024-9097 - IDOR

ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacker to change the username in the chat.

📅 Published: Feb. 5, 2025, 12:40 p.m. 🔄 Last Modified: Oct. 22, 2025, 8:27 p.m.

7.5

CVSS3.1

CVE-2024-2878 - Allocation of Resources Without Limits or Throttling in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible for an attacker to cause a denial of service by crafting unusual search terms for branch names.

📅 Published: Feb. 5, 2025, 12:21 p.m. 🔄 Last Modified: Aug. 6, 2025, 8:17 p.m.

6.5

CVSS3.1

CVE-2024-3976 - Missing Authorization in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose via the UI the confidential issues title and description from a public project to unaut…

📅 Published: Feb. 5, 2025, 12:02 p.m. 🔄 Last Modified: Aug. 6, 2025, 6:59 p.m.

4.3

CVSS3.1

CVE-2024-49348 - IBM Cloud Pak for Business Automation incorrect privilege assignment

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 allows restricting access to organizational data to valid contexts. The fact that tasks of type comment can be reassigned via API implicitly g…

📅 Published: Feb. 5, 2025, 11:30 a.m. 🔄 Last Modified: Aug. 12, 2025, 4:36 p.m.
Total resulsts: 343939
Page 6317 of 34,394
« previous page » next page
Filters