NA - CVE-2024-13842 - A hardcoded key in Ivanti Connect Secure before...
A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
NA - CVE-2024-13843 - Cleartext storage of information in Ivanti...
Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to...
NA - CVE-2024-47908 - OS command injection in the admin web console...
OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
NA - CVE-2025-22467 - A stack-based buffer overflow in Ivanti Connect...
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution.
NA - CVE-2025-24807 - eprosima Fast DDS is a C++ implementation of...
eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.6.10, 2.10.7, 2.14.5, 3.0.2, 3.1.2, and 3.2.0,...
NA - CVE-2025-24896 - Misskey is an open source, federated social...
Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, a login token named `token` is stored in a cookie for authentication...
NA - CVE-2025-24897 - Misskey is an open source, federated social...
Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, due to a lack of CSRF protection and the lack of proper security...
NA - CVE-2025-24900 - Concorde, formerly know as Nexkey, is a fork of...
Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Due to a lack of CSRF countermeasures and improper settings of cookies for MediaProxy authentication,...
NA - CVE-2025-24973 - Concorde, formerly know as Nexkey, is a fork of...
Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Prior to version 12.25Q1.1, due to an improper implementation of the logout process, authentication...
NA - CVE-2025-24976 - Distribution is a toolkit to pack, ship, store,...
Distribution is a toolkit to pack, ship, store, and deliver container content. Systems running registry versions 3.0.0-beta.1 through 3.0.0-rc.2 with token authentication enabled may be vulnerable...