Medium - CVE-2025-2827 - IBM Sterling File Gateway
6.0.0.0 through...
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 could disclose sensitive installation directory information to an authenticated user that could be used in...
NA - CVE-2025-36600 - Dell Client Platform BIOS contains an Improper...
Dell Client Platform BIOS contains an Improper Access Control Applied to Mirrored or Aliased Memory Regions vulnerability in an externally developed component. A high privileged attacker with local...
Medium - CVE-2025-3630 - IBM Sterling B2B Integrator 6.0.0.0 through...
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 is vulnerable to stored cross-site...
NA - CVE-2025-53372 - node-code-sandbox-mcp is a Node.js–based Model...
node-code-sandbox-mcp is a Node.js–based Model Context Protocol server that spins up disposable Docker containers to execute arbitrary JavaScript. Prior to 1.3.0, a command injection vulnerability...
NA - CVE-2025-53480 - The CheckUser extension’s Special:Investigate...
The CheckUser extension’s Special:Investigate page has a vulnerability in the Account information tab, where specific internationalized messages are rendered without proper escaping. Attackers can...
NA - CVE-2025-53545 - Press, a Frappe custom app that runs Frappe...
Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Users can circumvent 2FA login for users due to a lack of...
NA - CVE-2025-5450 - Improper access control in the certificate...
Improper access control in the certificate management component of Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated admin...
NA - CVE-2025-5451 - A stack-based buffer overflow in Ivanti Connect...
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to trigger a...
NA - CVE-2025-5463 - Insertion of sensitive information into a log...
Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a local authenticated attacker to obtain...
NA - CVE-2025-6770 - OS command injection in Ivanti Endpoint Manager...
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated attacker with high privileges to achieve remote code execution