CVE-2025-46826 – INSA Rouen insa-auth Information Disclosure

insa-auth is an authentication server for INSA Rouen. A minor issue allowed third-party websites to access the server’s secondary authentication bridge, potentially revealing basic student information (name and number). However, the issue posed minimal risk, was never exploited, and had limited impact. A fix was implemented promptly on May 3, 2025.

CVE-2025-46821 – Envoy URI Template Path Matching Bypass Vulnerability

Envoy is a cloud-native edge/middle/service proxy. Prior to versions 1.34.1, 1.33.3, 1.32.6, and 1.31.8, Envoy’s URI template matcher incorrectly excludes the `*` character from a set of valid characters in the URI path. As a result URI path containing the `*` character will not match a URI template expressions. This can result in bypass of […]

CVE-2025-46265 – F5OS Improper Authorization Vulnerability

The following table lists the changes that have been made to the CVE-2025-46265 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 07, 2025 Action […]

CVE-2025-36557 – F5 Big-IP HTTP Enforce RFC Compliance Remote Denial of Service

The following table lists the changes that have been made to the CVE-2025-36557 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 07, 2025 Action […]

CVE-2025-43878 – F5OS-C/A Appliance Mode Bypass Vulnerability

The following table lists the changes that have been made to the CVE-2025-43878 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 07, 2025 Action […]

CVE-2025-41433 – F5 BIG-IP SIP MRF ALG Profile Denial of Service Vulnerability

The following table lists the changes that have been made to the CVE-2025-41433 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 07, 2025 Action […]

CVE-2025-41431 – BIG-IP Traffic Management Microkernel (TMM) Denial of Service

The following table lists the changes that have been made to the CVE-2025-41431 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 07, 2025 Action […]

CVE-2025-41414 – F5 BIG-IP HTTP/2 Profile Denial of Service

The following table lists the changes that have been made to the CVE-2025-41414 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 07, 2025 Action […]

CVE-2025-41399 – F5 BIG-IP SCTP Profile Memory Exhaustion Vulnerability

The following table lists the changes that have been made to the CVE-2025-41399 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 07, 2025 Action […]

CVE-2025-36546 – F5OS SSH Key-Based Authentication Privilege Escalation

The following table lists the changes that have been made to the CVE-2025-36546 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 07, 2025 Action […]