A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.
CVE-2025-0282
🔥 KEV
Connect Secure
General
⚡ nuclei
9.0
CRITICAL
EPSS
94.1%
CVE-2025-48828
vBulletin
Web
⚡ nuclei
9.0
CRITICAL
EPSS
73.7%
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template code in an alternative PHP function invocation syntax, such as the "var_dump"("test") syntax, attackers can bypass security checks and execute arbitrary PHP code, as exploited in the wild in May 2025.
CVE-2020-4427
🔥 KEV
Data Risk Manager
Web
⚡ nuclei
9.0
CRITICAL
EPSS
92.7%
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532.
← Anterior
Página 40 de 40