CVE-2025-6724High· 8.8▾ TwilightIn Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in multiple services via improperly neutralized inputs used in an SQL c…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in multiple services via improperly neutralized inputs used in an SQL command.
automate < 4.13.295automate >= 20180319150121, <= 20220329091442Upgrade past the affected range:
automate 4.13.295Connected by shared product, vendor, weakness, or advisory.
CVE-2025-8868Critical· 9.8In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in a…
CVE-2025-11493High· 8.8The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updates, dependencies, and integrations
CVE-2025-11492Critical· 9.6In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS
CVE-2025-10079High· 7.3A flaw has been found in PHPGurukul Small CRM 4.0
CVE-2025-10405High· 7.3A vulnerability was determined in itsourcecode Baptism Information Management System 1.0
CVE-2025-10479High· 7.3A security flaw has been discovered in SourceCodester Online Student File Management System 1.0