Vulnerability Database

299,879

Total vulnerabilities in the database

CVE-2025-8296

SQL injection in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to execute arbitrary SQL queries. In certain conditions, this can also lead to remote code execution

  • Published: Aug 12, 2025
  • Updated: Aug 13, 2025
  • CVE: CVE-2025-8296
  • Exploit:

No technical information available.

CWEs:

OWASP TOP 10: