NA - CVE-2024-38524 - GeoServer is an open source server that allows...
GeoServer is an open source server that allows users to share and edit geospatial data. org.geowebcache.GeoWebCacheDispatcher.handleFrontPage(HttpServletRequest, HttpServletResponse) has no check...
NA - CVE-2024-40625 - GeoServer is an open source server that allows...
GeoServer is an open source server that allows users to share and edit geospatial data. The Coverage rest api /workspaces/{workspaceName}/coveragestores/{storeName}/{method}.{format} allows...
NA - CVE-2025-22463 - A hardcoded key in Ivanti Workspace Control...
A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt the stored environment password.
Medium - CVE-2025-26394 - SolarWinds Observability Self-Hosted
is...
SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirect a user to a...
High - CVE-2025-26395 - SolarWinds Observability Self-Hosted
was...
SolarWinds Observability Self-Hosted was susceptible to a cross-site scripting (XSS) vulnerability due to an unsanitized field in the URL. The attack requires authentication using an...
NA - CVE-2025-27505 - GeoServer is an open source server that allows...
GeoServer is an open source server that allows users to share and edit geospatial data. It is possible to bypass the default REST API security and access the index page. The REST API security...
NA - CVE-2025-30145 - GeoServer is an open source server that allows...
GeoServer is an open source server that allows users to share and edit geospatial data. Malicious Jiffle scripts can be executed by GeoServer, either as a rendering transformation in WMS dynamic...
NA - CVE-2025-37100 - A vulnerability in the APIs of HPE Aruba...
A vulnerability in the APIs of HPE Aruba Networking Private 5G Core could potentially expose sensitive information to unauthorized users. A successful exploitation could allow an attacker to...
NA - CVE-2025-46612 - The Panel Designer dashboard in Airleader...
The Panel Designer dashboard in Airleader Master and Easy before 6.36 allows remote attackers to execute arbitrary commands via a wizard/workspace.jsp unrestricted file upload. To exploit this, the...