CVE-2025-24911 – Hitachi Vantara Pentaho Business Analytics Server XML External Entity Injection
Overview XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define an entity by providing a substitution string in the form of a URI. Once the content of the URI is read, it is fed back into the application that […]
CVE-2025-24910 – Hitachi Vantara Pentaho XML External Entity (XXE) Vulnerability
Overview XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define an entity by providing a substitution string in the form of a URI. Once the content of the URI is read, it is fed back into the application that […]
CVE-2025-24908 – Hitachi Vantara Pentaho Path Traversal Vulnerability
The following table lists the changes that have been made to the CVE-2025-24908 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 16, 2025 Action […]
CVE-2025-24909 – Hitachi Vantara Pentaho Business Analytics Server Cross-Site Scripting (XSS) Vulnerability
Overview The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. (CWE-79) Description Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.2.0.2, including 9.3.x and 8.3.x, allow a malicious URL to inject […]
CVE-2025-2400 – Apache HTTP Server Remote Code Execution
The following table lists the changes that have been made to the CVE-2025-2400 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Rejected by [email protected] Apr. 16, 2025 Action Type […]
CVE-2025-24907 – Hitachi Vantara Pentaho Data Integration & Analytics Path Traversal Vulnerability
The following table lists the changes that have been made to the CVE-2025-24907 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 16, 2025 Action […]
CVE-2025-0757 – Hitachi Vantara Pentaho Business Analytics Server Cross-Site Scripting (XSS) Vulnerability
Overview The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. (CWE-79) Description Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.2.0.2, including 9.3.x and 8.3.x, allow a malicious URL to inject […]
CVE-2025-1704 – Google ChromeOS ComponentInstaller Unenrollment and Device Management Request Interception Vulnerability
The following table lists the changes that have been made to the CVE-2025-1704 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f Apr. 16, 2025 Action […]
CVE-2025-1568 – Google ChromeOS Gerrit Access Control Code Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-1568 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f Apr. 16, 2025 Action […]
CVE-2025-1566 – “Google ChromeOS Native System VPN DNS Leak Vulnerability”
The following table lists the changes that have been made to the CVE-2025-1566 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f Apr. 16, 2025 Action […]