Latest CVE Feed
-
6.4
MEDIUMCVE-2025-55011
Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, the createTaskFile method in the API does not validate whether the task_id parameter is a valid task id, nor does it check for path traversal. As a re... Read more
Affected Products : kanboard- Published: Aug. 12, 2025
- Modified: Aug. 22, 2025
-
9.1
CRITICALCVE-2025-55010
Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, an unsafe deserialization vulnerability in the ProjectEventActvityFormatter allows admin users the ability to instantiate arbitrary php objects by mod... Read more
Affected Products : kanboard- Published: Aug. 12, 2025
- Modified: Aug. 22, 2025
-
6.9
MEDIUMCVE-2025-54864
Hydra is a continuous integration service for Nix based projects. Prior to commit f7bda02, /api/push-github and /api/push-gitea are called by the corresponding forge without HTTP Basic authentication. Both forges do however feature HMAC signing with a sec... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
7.1
HIGHCVE-2025-54800
Hydra is a continuous integration service for Nix based projects. Prior to commit dea1e16, a malicious package can introduce arbitrary JavaScript code into the Hydra database that is automatically evaluated in a client's browser when anyone visits the bui... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
5.3
MEDIUMCVE-2025-3089
ServiceNow has addressed a Broken Access Control vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could allow a low privileged user to bypass access controls and perform a limited set of actions typically reserved for hi... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
0.0
NACVE-2025-38500
In the Linux kernel, the following vulnerability has been resolved: xfrm: interface: fix use-after-free after changing collect_md xfrm interface collect_md property on xfrm interfaces can only be set on device creation, thus xfrmi_changelink() should fa... Read more
Affected Products : linux_kernel- Published: Aug. 12, 2025
- Modified: Aug. 15, 2025
-
6.5
MEDIUMCVE-2025-8310
Missing authorization in the admin console of Ivanti Virtual Application Delivery Controller before version 22.9 allows a remote authenticated attacker to take over admin accounts by resetting the password... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
7.2
HIGHCVE-2025-8297
Incomplete restriction of configuration in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to achieve remote code execution... Read more
Affected Products : avalanche- Published: Aug. 12, 2025
- Modified: Aug. 15, 2025
-
7.2
HIGHCVE-2025-8296
SQL injection in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to execute arbitrary SQL queries. In certain conditions, this can also lead to remote code execution... Read more
Affected Products : avalanche- Published: Aug. 12, 2025
- Modified: Aug. 15, 2025
-
5.5
MEDIUMCVE-2025-5468
Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025)... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
4.9
MEDIUMCVE-2025-5466
XEE in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker ... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
7.5
HIGHCVE-2025-5462
A heap-based buffer overflow in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remot... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
7.5
HIGHCVE-2025-5456
A buffer over-read vulnerability in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a re... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
8.1
HIGHCVE-2025-3831
Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
6.3
MEDIUMCVE-2024-38805
EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vulnerability may lead to denial of service.... Read more
Affected Products : edk2- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
4.2
MEDIUMCVE-2025-22834
AMI APTIOV contains a vulnerability in BIOS where a user may cause “Improper Initialization” by local accessing. Successful exploitation of this vulnerability may leave the resource in an unexpected state and potentially impact confidentiality, integrity,... Read more
Affected Products : aptio_v- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
-
7.3
HIGHCVE-2025-22830
APTIOV contains a vulnerability in BIOS where a skilled user may cause “Race Condition” by local access. A successful exploitation of this vulnerability may lead to resource exhaustion and impact Confidentiality, Integrity, and Availability.... Read more
Affected Products : aptio_v- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
-
6.9
MEDIUMCVE-2025-43735
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through up... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
-
7.5
HIGHCVE-2025-40770
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions). The affected application uses a monitoring interface that is not operating in a strictly passive mode. This could allow an attacker to interact with the int... Read more
Affected Products : sinec_traffic_analyzer- Published: Aug. 12, 2025
- Modified: Aug. 20, 2025
-
7.5
HIGHCVE-2025-40769
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application uses a Content Security Policy that allows unsafe script execution methods. This could allow an attacker to execute unauthor... Read more
Affected Products : sinec_traffic_analyzer- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025