NA - CVE-2025-53545 - Press, a Frappe custom app that runs Frappe...
Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Users can circumvent 2FA login for users due to a lack of...
NA - CVE-2025-5450 - Improper access control in the certificate...
Improper access control in the certificate management component of Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated admin...
NA - CVE-2025-5451 - A stack-based buffer overflow in Ivanti Connect...
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to trigger a...
NA - CVE-2025-5463 - Insertion of sensitive information into a log...
Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a local authenticated attacker to obtain...
NA - CVE-2025-6770 - OS command injection in Ivanti Endpoint Manager...
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated attacker with high privileges to achieve remote code execution
NA - CVE-2025-6995 - Improper use of encryption in the agent of...
Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.
NA - CVE-2025-6996 - Improper use of encryption in the agent of...
Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.
NA - CVE-2025-7037 - SQL injection in Ivanti Endpoint Manager before...
SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenticated attacker with admin privileges to read arbitrary data from the database
Medium - CVE-2025-7182 - A vulnerability has been found in itsourcecode...
A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file...
High - CVE-2025-7183 - A vulnerability was found in Campcodes Sales...
A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /pages/customer_account.php. The...