NA - CVE-2025-30164 - Icinga Web 2 is an open source monitoring web...
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 vulnerability allows an attacker to craft a...
NA - CVE-2025-30217 - Frappe is a full-stack web application...
Frappe is a full-stack web application framework. Prior to versions 14.93.2 and 15.55.0, a SQL Injection vulnerability has been identified in Frappe Framework which could allow a malicious actor to...
NA - CVE-2025-30225 - Directus is a real-time API and App dashboard...
Directus is a real-time API and App dashboard for managing SQL database content. The `@directus/storage-driver-s3` package starting in version 9.22.0 and prior to version 12.0.1, corresponding to...
NA - CVE-2025-30350 - Directus is a real-time API and App dashboard...
Directus is a real-time API and App dashboard for managing SQL database content. The `@directus/storage-driver-s3` package starting in version 9.22.0 and prior to version 12.0.1, corresponding to...
NA - CVE-2025-2499 - Client side access control bypass in the...
Client side access control bypass in the permission component in Devolutions Remote Desktop Manager on Windows. An authenticated user can exploit this flaw to bypass certain permission...
NA - CVE-2025-2528 - Improper authorization in application password...
Improper authorization in application password policy in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a configuration different from the one mandated by the...
NA - CVE-2025-2562 - Insufficient logging in the autotyping feature...
Insufficient logging in the autotyping feature in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a stored password without generating a corresponding log event,...
NA - CVE-2025-2600 - Improper authorization in the variable...
Improper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticated password to use the ELEVATED_PASSWORD variable even though not allowed by...
NA - CVE-2025-30351 - Directus is a real-time API and App dashboard...
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.10.0 and prior to version 11.5.0, a suspended user can use the token generated in session...