#1 · PT-2025-1003 · Ivanti · Ivanti Policy Secure

Sinsinology

·

Published

2025-01-08

·

Updated

2026-02-27

·

CVE-2025-0282

9.0

Critical

Base

AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions Ivanti Connect Secure versions prior to 22.7R2.5 Ivanti Policy Secure versions prior to 22.7R1.2 Ivanti Neurons for ZTA gateways versions prior to 22.7R2.3
Description A stack-based buffer overflow in Ivanti Connect Secure, Policy Secure, and ZTA Gateways allows a remote unauthenticated attacker to achieve remote code execution. The vulnerability is being actively exploited...
More

Exploit

Fix

RCE

LPE

Memory Corruption

Out of bounds Read

Stack Overflow

942 Posts
1.4 KReposts
8.7 M Audience
Graph

#2 · PT-2024-2451 · Fedora · Fedora

Andres Freund

·

Published

2024-03-29

·

Updated

2026-02-28

·

CVE-2024-3094

10

Critical

Base

AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions XZ Utils versions 5.6.0 and 5.6.1
Description A critical vulnerability (CVE-2024-3094) was discovered in XZ Utils, a data compression library used in many Linux distributions. The vulnerability involves a backdoor inserted into the liblzma library through a supply chain attack. This backdoor could allow attackers to bypass SSH authentication and gain unauthorized remote acce...
More

Exploit

RCE

495 Posts
2.1 KReposts
4.0 M Audience
Graph

#3 · PT-2025-32352 · Rarlab · Winrar

Anton Cherepanov

+2

·

Published

2025-07-30

·

Updated

2026-02-28

·

CVE-2025-8088

8.8

High

Base

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions WinRAR versions prior to 7.13
Description WinRAR contains a path traversal vulnerability that allows attackers to execute arbitrary code by crafting malicious archive files. This vulnerability has been actively exploited in the wild by multiple threat actors, including Russia-linked groups (RomCom, Paper Werewolf, Gamaredon, APT44, Turla) and China-linked groups (Amaranth-Dr...
More

Fix

RCE

408 Posts
1.5 KReposts
23.8 M Audience
Graph

#4 · PT-2026-5357 · Ivanti · Ivanti Endpoint Manager Mobile

Published

2026-01-29

·

Updated

2026-02-28

·

CVE-2026-1281

9.8

Critical

Base

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions Ivanti Endpoint Manager Mobile (EPMM) versions prior to 12.8.0.0
Description A critical code injection flaw exists in Ivanti Endpoint Manager Mobile (EPMM) that allows attackers to achieve unauthenticated remote code execution (RCE). This vulnerability, actively exploited in the wild, enables attackers to execute arbitrary code by abusing a template rendering workflow expose...
More

Fix

RCE

Code Injection

161 Posts
400Reposts
235.4 K Audience
Graph

#5 · PT-2026-5358 · Ivanti · Ivanti Endpoint Manager Mobile

Published

2026-01-29

·

Updated

2026-02-27

·

CVE-2026-1340

9.8

Critical

Base

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions Ivanti Endpoint Manager Mobile versions prior to 12.7.x
Description A code injection issue exists in Ivanti Endpoint Manager Mobile, enabling attackers to execute code remotely without authentication. The flaw stems from improper code generation management. Exploitation allows a remote attacker to execute arbitrary code.
Recommendations Ivanti Endpoint Manager Mobile ve...
More

Fix

RCE

Code Injection

115 Posts
317Reposts
182.0 K Audience
Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph