Complete feed
No mitigation yet
No fix, workaround or mitigation extracted yet
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2025-22482] Qsync: use of externally-controlled format string vulnerability has been reported to affect Qsync Central.
A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to obtain secret data or modify memory. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.6 ( 2025/03/20 ) and later
High [CVE-2025-22481] QTS: command injection vulnerability has been reported to affect several QNAP operating system versions.
A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.4.3079 build 20250321 and later Affected products named by the advisory: QuTS hero.
High [CVE-2024-13088] improper authentication vulnerability has been reported to affect QHora.
An improper authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: QuRouter 2.5.0.140 and later
High [CVE-2025-22157] Jira Service Management: This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, 10.3.0, 10.4.0, and 10.5.0…
This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Core Data Center and Server This PrivEsc (Privilege Escalation) vulnerability, with a CVSS Score of 7.2, allows an attacker to perform actions as a higher-privileged user. Jira Core Data Center 10.3: Upgrade to a release greater than or equal to 10.3.5 See the release notes. This vulnerability was reported via our Atlassian (Internal) program. Affected product named by the advisory: Jira Service Management.
High May Security Update
Ivanti releases standard security patches on the second Tuesday of every month. For many of our customers, the predictable schedule facilitates better planning and management of IT resources, allowing them to allocate time and personnel efficiently for the timely updates. Today, Ivanti is disclosing vulnerabilities in Ivanti ITSM (on-premises only), Cloud Security Application (CSA) and Neurons for MDM. It is important for customers to know: - We have no evidence of any of these vulnerabilities being exploited in the wild. - These vulnerabilities do not impact any other Ivanti solutions. More information on these vulnerabilities and detailed instructions on how to remediate the issues can be found in these Security Advisories: Our Support team is always available to help customers and partners should they have any questions. Cases can be logged via the Success portal (login credentials required). Want to stay up to date on Ivanti Security Advisories? Paste into your preferred RSS reader / functionality in your email program.
High [CVE-2025-46265] On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+)
On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+) may be authorized with higher privilege F5OS roles. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
High [CVE-2025-41433] When a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is configured…
When a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is configured on a Message Routing virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
High [CVE-2025-41431] BIG-IP: When connection mirroring is configured on a virtual server, undisclosed requests
When connection mirroring is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate in the standby BIG-IP systems in a traffic group. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
High [CVE-2025-41414] When HTTP/2 client and server profile is configured on a virtual server, undisclosed requests can cause TMM to terminate
When HTTP/2 client and server profile is configured on a virtual server, undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
High [CVE-2025-41399] When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests
When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
High [CVE-2025-36557] When an HTTP profile with the Enforce RFC Compliance option is configured on a virtual server, undisclosed requests
When an HTTP profile with the Enforce RFC Compliance option is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
High [CVE-2025-36546] On an F5OS system, if the root user had previously configured the system to allow login
On an F5OS system, if the root user had previously configured the system to allow login via SSH key-based authentication, and then enabled Appliance Mode; access via SSH key-based authentication is still allowed. For an attacker to exploit this vulnerability they must obtain the root user's SSH private key. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
High [CVE-2025-36525] When a BIG-IP APM virtual server is configured to use a PingAccess profile, undisclosed requests can cause TMM to terminate
When a BIG-IP APM virtual server is configured to use a PingAccess profile, undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
High [CVE-2025-36504] When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses
When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
High [CVE-2025-35995] When a BIG-IP PEM system is licensed with URL categorization, and the URL categorization policy or an iRule with the urlcat…
When a BIG-IP PEM system is licensed with URL categorization, and the URL categorization policy or an iRule with the urlcat command is enabled on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
High [CVE-2025-31644] When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell…
When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which may allow an authenticated attacker with administrator role privileges to execute arbitrary system commands. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
High [CVE-2025-25234] UAG: Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability.
Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability. A malicious actor with network access to UAG may be able to bypass administrator-configured CORS restrictions to gain access to sensitive networks. Affected product named by the advisory: Unified Access Gateway.
High [CVE-2025-25230] Horizon Client: Omnissa Horizon Client for Windows contains an LPE Vulnerability.
Omnissa Horizon Client for Windows contains an LPE Vulnerability. A malicious actor with local access where Horizon Client for Windows is installed may be able to elevate privileges.
High [CVE-2024-13861] code injection vulnerability in the Debian package component of Taegis Endpoint Agent (Linux) versions older than 1.3.10
A code injection vulnerability in the Debian package component of Taegis Endpoint Agent (Linux) versions older than 1.3.10 allows local users arbitrary code execution as root. Redhat-based systems using RPM packages are not affected.
High [CVE-2025-27743] Microsoft System Center Elevation of Privilege Vulnerability
Untrusted search path in System Center allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: System Center Data Protection Manager 2019; System Center Data Protection Manager 2022; System Center Data Protection Manager 2025; System Center Operations Manager 2019; and 11 more. Affected products named by the advisory: System Center Operations Manager 2022; System Center Operations Manager 2025; System Center Orchestrator 2019; System Center Orchestrator 2022; and 7 more.