CVE-2024-56404 – One Identity Identity Manager IDOR Privilege Escalation
The following table lists the changes that have been made to the CVE-2024-56404 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 24, 2025 Action […]
CVE-2019-15690 – LibVNCServer Heap Buffer Overflow Remote Code Execution
The following table lists the changes that have been made to the CVE-2019-15690 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 24, 2025 Action […]
CVE-2025-24355 – Updatecli Unauthenticated Maven Repository Credentials Leakage
The following table lists the changes that have been made to the CVE-2025-24355 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 24, 2025 Action […]
CVE-2025-24359 – ASTEVAL Arbitary Code Execution Vulnerability
The following table lists the changes that have been made to the CVE-2025-24359 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 24, 2025 Action […]
CVE-2025-23222 – Deepin dde-api-proxy Root Privilege Escalation
An issue was discovered in Deepin dde-api-proxy through 1.0.19 in which unprivileged users can access D-Bus services as root. Specifically, dde-api-proxy runs as root and forwards messages from arbitrary local users to legacy D-Bus methods in the actual D-Bus services, and the actual D-Bus services don’t know about the proxy situation (they believe that root […]
CVE-2025-22612 – Coolify Key Disclosure and Remote Command Execution Vulnerability
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.374, the missing authorization allows an authenticated user to retrieve any existing private keys on a coolify instance in plain text. If the server configuration of IP / domain, port (most likely 22) and user (root) matches with the […]
CVE-2025-24025 – Coolify Cross-Site Scripting (XSS)
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.380, the tags page allows users to search for tags. If the search does not return any results, the query gets reflected on the error modal, which leads to cross-site scripting. Version 4.0.0-beta.380 fixes the issue.
CVE-2025-22610 – Coolify OAuth Configuration Disclosure and Modification
The following table lists the changes that have been made to the CVE-2025-22610 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 24, 2025 Action […]
CVE-2025-22611 – Coolify Privilege Escalation Vulnerability
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to escalate his or any other team members privileges to any role, including the owner role. He’s also able to kick every other member out of the team, including admins and […]
CVE-2025-22609 – Coolify Remote Command Execution as Unprivileged User
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to attach any existing private key on a coolify instance to his own server. If the server configuration of IP / domain, port (most likely 22) and user (root) matches with […]