##
Updated at UTC 2025-11-28T23:11:22.474305
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-13683 | 6.5 | 0.00% | 1 | 0 | 2025-11-28T21:32:24 | Exposure of credentials in unintended requests in Devolutions Server, Remote Des | |
| CVE-2025-40934 | 9.3 | 0.01% | 1 | 0 | 2025-11-28T21:32:24 | XML-Sig versions 0.27 through 0.67 for Perl incorrectly validates XML files if s | |
| CVE-2025-45311 | 8.8 | 0.01% | 1 | 0 | 2025-11-28T21:31:18 | Insecure permissions in fail2ban-client v0.11.2 allows attackers with limited su | |
| CVE-2025-65681 | 3.3 | 0.02% | 1 | 1 | 2025-11-28T21:15:48.280000 | An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0. | |
| CVE-2021-26829 | 5.4 | 0.25% | 5 | 0 | 2025-11-28T19:15:44.900000 | OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stor | |
| CVE-2025-51736 | 6.3 | 0.00% | 1 | 0 | 2025-11-28T18:31:28 | File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0. | |
| CVE-2025-51735 | 7.5 | 0.00% | 1 | 0 | 2025-11-28T18:31:27 | CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0. | |
| CVE-2025-51734 | 5.4 | 0.00% | 1 | 0 | 2025-11-28T18:31:27 | Cross-site scripting (XSS) vulnerability in HCL Technologies Ltd. Unica 12.0.0. | |
| CVE-2025-51733 | 5.5 | 0.00% | 1 | 0 | 2025-11-28T18:31:27 | Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 1 | |
| CVE-2025-13742 | None | 0.04% | 1 | 0 | 2025-11-28T18:31:27 | Emails sent by pretix can utilize placeholders that will be filled with customer | |
| CVE-2025-12183 | None | 0.00% | 2 | 0 | 2025-11-28T18:30:32 | Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remo | |
| CVE-2025-59790 | 5.4 | 0.00% | 1 | 0 | 2025-11-28T18:30:24 | Improper Privilege Management vulnerability in Apache Kvrocks. This issue affec | |
| CVE-2025-59792 | 5.3 | 0.00% | 1 | 0 | 2025-11-28T18:30:24 | Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvr | |
| CVE-2025-59454 | 4.3 | 0.02% | 1 | 0 | 2025-11-28T18:30:23 | In Apache CloudStack, a gap in access control checks affected the APIs - createN | |
| CVE-2025-59302 | 4.7 | 0.03% | 1 | 0 | 2025-11-28T15:31:38 | In Apache CloudStack improper control of generation of code ('Code Injection') | |
| CVE-2025-12638 | 8.0 | 0.00% | 2 | 0 | 2025-11-28T15:30:36 | Keras version 3.11.3 is affected by a path traversal vulnerability in the keras. | |
| CVE-2025-11156 | None | 0.00% | 1 | 0 | 2025-11-28T15:30:36 | Netskope was notified about a potential gap in its agent (NS Client) on Windows | |
| CVE-2025-65202 | 8.0 | 0.16% | 1 | 0 | 2025-11-28T15:16:03.483000 | TRENDnet TEW-657BRM 1.00.1 has an authenticated remote OS command injection vuln | |
| CVE-2025-12143 | 6.1 | 0.00% | 1 | 0 | 2025-11-28T12:30:28 | Stack-based Buffer Overflow vulnerability in ABB Terra AC wallbox.This issue aff | |
| CVE-2025-66385 | None | 0.04% | 3 | 0 | 2025-11-28T09:30:22 | UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privi | |
| CVE-2025-13769 | 6.5 | 0.03% | 1 | 0 | 2025-11-28T09:30:22 | WebITR developed by Uniong has a SQL Injection vulnerability, allowing authentic | |
| CVE-2025-13770 | 6.5 | 0.03% | 1 | 0 | 2025-11-28T09:30:18 | WebITR developed by Uniong has a SQL Injection vulnerability, allowing authentic | |
| CVE-2025-13768 | 7.5 | 0.15% | 1 | 0 | 2025-11-28T09:30:18 | WebITR developed by Uniong has an Authentication Bypass vulnerability, allowing | |
| CVE-2025-13771 | 6.5 | 0.04% | 2 | 0 | 2025-11-28T09:30:17 | WebITR developed by Uniong has an Arbitrary File Read vulnerability, allowing au | |
| CVE-2025-66384 | 8.2 | 0.03% | 2 | 0 | 2025-11-28T09:30:17 | app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in c | |
| CVE-2025-66382 | 2.9 | 0.01% | 1 | 0 | 2025-11-28T09:30:17 | In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can | |
| CVE-2025-66386 | 4.1 | 0.03% | 1 | 0 | 2025-11-28T07:15:59.900000 | app/Model/EventReport.php in MISP before 2.5.27 allows path traversal in view pi | |
| CVE-2025-58308 | 7.3 | 0.01% | 1 | 0 | 2025-11-28T06:32:10 | Vulnerability of improper criterion security check in the call module. Impact: S | |
| CVE-2025-58305 | 6.2 | 0.01% | 1 | 0 | 2025-11-28T06:32:10 | Identity authentication bypass vulnerability in the Gallery app. Impact: Success | |
| CVE-2025-58302 | 8.4 | 0.01% | 3 | 0 | 2025-11-28T06:32:09 | Permission control vulnerability in the Settings module. Impact: Successful expl | |
| CVE-2025-64312 | 4.9 | 0.01% | 1 | 0 | 2025-11-28T06:32:09 | Permission control vulnerability in the file management module. Impact: Successf | |
| CVE-2025-13737 | 4.3 | 0.01% | 1 | 0 | 2025-11-28T06:32:09 | The Nextend Social Login and Register plugin for WordPress is vulnerable to Cros | |
| CVE-2025-66372 | 2.8 | 0.01% | 1 | 0 | 2025-11-28T06:32:07 | Mustang before 2.16.3 allows exfiltrating files via XXE attacks. | |
| CVE-2025-66370 | 5.0 | 0.03% | 1 | 0 | 2025-11-28T06:32:07 | Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice | |
| CVE-2025-66371 | 5.0 | 0.03% | 1 | 0 | 2025-11-28T04:16:01.293000 | Peppol-py before 1.1.1 allows XXE attacks because of the Saxon configuration. Wh | |
| CVE-2025-58311 | 5.8 | 0.01% | 1 | 0 | 2025-11-28T04:16:00.807000 | UAF vulnerability in the USB driver module. Impact: Successful exploitation of t | |
| CVE-2025-58304 | 4.9 | 0.01% | 1 | 0 | 2025-11-28T04:16:00.347000 | Permission control vulnerability in the file management module. Impact: Successf | |
| CVE-2025-58303 | 8.4 | 0.01% | 1 | 0 | 2025-11-28T03:30:34 | UAF vulnerability in the screen recording framework module. Impact: Successful e | |
| CVE-2025-58310 | 8.0 | 0.01% | 1 | 0 | 2025-11-28T03:30:33 | Permission control vulnerability in the distributed component. Impact: Successfu | |
| CVE-2025-64314 | 9.3 | 0.01% | 2 | 0 | 2025-11-28T03:16:00.867000 | Permission control vulnerability in the memory management module. Impact: Succes | |
| CVE-2025-66360 | None | 0.04% | 1 | 0 | 2025-11-28T00:30:28 | An issue was discovered in Logpoint before 7.7.0. An improperly configured acces | |
| CVE-2025-66361 | None | 0.04% | 1 | 0 | 2025-11-28T00:30:27 | An issue was discovered in Logpoint before 7.7.0. Sensitive information is expos | |
| CVE-2025-66359 | 8.5 | 0.05% | 2 | 0 | 2025-11-28T00:15:46.003000 | An issue was discovered in Logpoint before 7.7.0. Insufficient input validation | |
| CVE-2025-13338 | 0 | 0.00% | 1 | 0 | 2025-11-27T23:15:50.550000 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering | |
| CVE-2025-3261 | None | 0.07% | 1 | 0 | 2025-11-27T18:30:34 | ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload m | |
| CVE-2025-12559 | 4.3 | 0.03% | 1 | 0 | 2025-11-27T18:30:26 | Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10 | |
| CVE-2025-12419 | 10.0 | 0.07% | 2 | 0 | 2025-11-27T18:30:26 | Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 1 | |
| CVE-2025-13757 | None | 0.02% | 1 | 0 | 2025-11-27T18:30:26 | SQL Injection vulnerability in last usage logs in Devolutions Server.This issue | |
| CVE-2025-13765 | None | 0.02% | 1 | 0 | 2025-11-27T18:30:26 | Exposure of email service credentials to users without administrative rights in | |
| CVE-2025-12421 | 9.9 | 0.07% | 2 | 0 | 2025-11-27T18:15:46.223000 | Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10 | |
| CVE-2025-13758 | 0 | 0.02% | 1 | 0 | 2025-11-27T16:15:47.257000 | Exposure of credentials in unintended requests in Devolutions Server.This issue | |
| CVE-2025-54057 | None | 0.03% | 1 | 0 | 2025-11-27T15:32:27 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vu | |
| CVE-2025-12140 | None | 0.08% | 2 | 0 | 2025-11-27T15:31:32 | The application contains an insecure 'redirectToUrl' mechanism that incorrectly | |
| CVE-2025-13692 | 7.2 | 0.10% | 1 | 0 | 2025-11-27T15:31:32 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Store | |
| CVE-2025-8890 | 0 | 0.29% | 2 | 0 | 2025-11-27T14:15:52.183000 | Firmware in SDMC NE6037 routers prior to version 7.1.12.2.44 has a network diagn | |
| CVE-2025-12971 | 4.3 | 0.03% | 1 | 0 | 2025-11-27T13:15:58.547000 | The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, | |
| CVE-2025-10476 | 4.3 | 0.03% | 1 | 0 | 2025-11-27T12:30:34 | The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized modifica | |
| CVE-2025-59025 | 6.1 | 0.03% | 1 | 0 | 2025-11-27T12:30:34 | Malicious e-mail content can be used to execute script code. Unintended actions | |
| CVE-2025-30186 | 5.4 | 0.03% | 1 | 0 | 2025-11-27T12:30:34 | Malicious content uploaded as file can be used to execute script code when follo | |
| CVE-2025-13378 | 6.5 | 0.04% | 1 | 0 | 2025-11-27T12:30:34 | The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is | |
| CVE-2025-12584 | 5.3 | 0.03% | 1 | 0 | 2025-11-27T12:30:34 | The Quick View for WooCommerce plugin for WordPress is vulnerable to Information | |
| CVE-2025-30190 | 5.4 | 0.03% | 1 | 0 | 2025-11-27T12:30:29 | Malicious content at office documents can be used to inject script code when edi | |
| CVE-2025-59890 | 7.3 | 0.01% | 1 | 0 | 2025-11-27T11:15:48.080000 | Improper input sanitization in the file archives upload functionality of Eaton G | |
| CVE-2025-59026 | 5.4 | 0.03% | 1 | 0 | 2025-11-27T10:15:52.007000 | Malicious content uploaded as file can be used to execute script code when follo | |
| CVE-2025-13381 | 5.3 | 0.04% | 1 | 0 | 2025-11-27T10:15:51.220000 | The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is | |
| CVE-2025-13536 | 8.8 | 0.22% | 2 | 0 | 2025-11-27T09:30:26 | The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uplo | |
| CVE-2025-13157 | 5.3 | 0.03% | 1 | 0 | 2025-11-27T09:30:26 | The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure | |
| CVE-2025-13441 | 5.3 | 0.05% | 1 | 0 | 2025-11-27T09:30:25 | The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerabl | |
| CVE-2025-66028 | None | 0.04% | 1 | 0 | 2025-11-27T09:01:21 | ### Summary During the login process, the server response included a parameter | |
| CVE-2025-62703 | 8.8 | 0.33% | 1 | 0 | 2025-11-27T09:00:41 | ### Summary The Fugue framework implements an RPC server system for distributed | |
| CVE-2025-13540 | 9.8 | 0.07% | 2 | 0 | 2025-11-27T06:31:33 | The Tiare Membership plugin for WordPress is vulnerable to Privilege Escalation | |
| CVE-2025-13675 | 9.8 | 0.07% | 2 | 0 | 2025-11-27T06:31:33 | The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versi | |
| CVE-2025-12758 | 7.5 | 0.04% | 1 | 0 | 2025-11-27T06:31:32 | Versions of the package validator before 13.15.22 are vulnerable to Incomplete F | |
| CVE-2025-12151 | 6.4 | 0.03% | 1 | 0 | 2025-11-27T06:31:32 | The Simple Folio plugin for WordPress is vulnerable to Stored Cross-Site Scripti | |
| CVE-2025-12185 | 4.4 | 0.02% | 1 | 0 | 2025-11-27T06:31:26 | The StaffList plugin for WordPress is vulnerable to Stored Cross-Site Scripting | |
| CVE-2025-12123 | 6.1 | 0.07% | 1 | 0 | 2025-11-27T06:31:26 | The Customer Reviews Collector for WooCommerce plugin for WordPress is vulnerabl | |
| CVE-2025-13539 | 9.8 | 0.19% | 2 | 0 | 2025-11-27T06:31:26 | The FindAll Membership plugin for WordPress is vulnerable to Authentication Bypa | |
| CVE-2025-7820 | 7.5 | 0.09% | 1 | 0 | 2025-11-27T06:31:26 | The SKT PayPal for WooCommerce plugin for WordPress is vulnerable to Payment Byp | |
| CVE-2025-13525 | 6.1 | 0.09% | 1 | 0 | 2025-11-27T06:15:46.830000 | The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site | |
| CVE-2025-13143 | 4.3 | 0.01% | 1 | 0 | 2025-11-27T06:15:46.657000 | The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vu | |
| CVE-2025-3784 | 5.5 | 0.01% | 1 | 0 | 2025-11-27T05:16:15.467000 | Cleartext Storage of Sensitive Information Vulnerability in GX Works2 all versio | |
| CVE-2025-13680 | 8.8 | 0.04% | 2 | 0 | 2025-11-27T05:16:15.253000 | The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versi | |
| CVE-2025-13538 | 9.8 | 0.07% | 2 | 0 | 2025-11-27T05:16:12.453000 | The FindAll Listing plugin for WordPress is vulnerable to Privilege Escalation i | |
| CVE-2025-66314 | 7.5 | 0.03% | 1 | 0 | 2025-11-27T03:30:32 | Improper Privilege Management vulnerability in ZTE ElasticNet UME R32 on Linux a | |
| CVE-2025-34351 | None | 0.47% | 2 | 0 | 2025-11-27T03:30:32 | Anyscale Ray 2.52.0 contains an insecure default configuration in which token-ba | |
| CVE-2024-5539 | None | 0.04% | 2 | 0 | 2025-11-27T03:30:32 | The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in | |
| CVE-2024-5540 | None | 0.05% | 1 | 0 | 2025-11-27T03:30:32 | The reflective cross-site scripting vulnerability found in ALC WebCTRL and Carri | |
| CVE-2025-0657 | None | 0.04% | 2 | 0 | 2025-11-27T03:30:26 | A weakness in Automated Logic and Carrier i-Vu Gen5 router on driver version | |
| CVE-2025-0658 | 0 | 0.08% | 2 | 0 | 2025-11-27T01:15:46.583000 | A vulnerability in Automated Logic and Carrier's Zone Controller via BACnet prot | |
| CVE-2020-36871 | None | 0.34% | 2 | 0 | 2025-11-27T00:30:38 | ESCAM QD-900 WIFI HD cameras contain an unauthenticated configuration disclosure | |
| CVE-2020-36874 | None | 0.36% | 1 | 0 | 2025-11-27T00:30:27 | ACE SECURITY WIP-90113 HD cameras contain an unauthenticated configuration discl | |
| CVE-2020-36872 | None | 0.16% | 1 | 0 | 2025-11-27T00:30:27 | BACnet Test Server versions up to and including 1.01 contains a remote denial of | |
| CVE-2019-25226 | None | 0.22% | 1 | 0 | 2025-11-27T00:30:27 | Dongyoung Media DM-AP240T/W wireless access points contain an unauthenticated co | |
| CVE-2025-66040 | 3.6 | 0.03% | 1 | 0 | 2025-11-27T00:15:55.343000 | Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, th | |
| CVE-2025-59390 | 9.8 | 0.09% | 1 | 1 | 2025-11-26T23:19:19 | Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `drui | |
| CVE-2025-66035 | None | 0.05% | 1 | 0 | 2025-11-26T23:18:51 | The vulnerability is a **Credential Leak by App Logic** that leads to the **unau | |
| CVE-2025-66030 | 0 | 0.03% | 1 | 0 | 2025-11-26T23:15:49.237000 | Forge (also called `node-forge`) is a native implementation of Transport Layer S | |
| CVE-2025-64335 | 7.5 | 0.05% | 1 | 0 | 2025-11-26T23:15:48.913000 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Inform | |
| CVE-2025-64330 | 7.5 | 0.04% | 1 | 0 | 2025-11-26T23:15:48.093000 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Inform | |
| CVE-2025-62593 | 0 | 0.02% | 2 | 1 | 2025-11-26T23:15:47.927000 | Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ra | |
| CVE-2020-36873 | 0 | 0.17% | 1 | 0 | 2025-11-26T23:15:47.397000 | Astak CM-818T3 2.4GHz wireless security surveillance cameras contain an unauthen | |
| CVE-2019-25227 | 0 | 0.21% | 2 | 0 | 2025-11-26T23:15:46.880000 | Tellion HN-2204AP routers contain an unauthenticated configuration disclosure vu | |
| CVE-2025-66031 | None | 0.09% | 2 | 0 | 2025-11-26T22:08:40 | ### Summary An Uncontrolled Recursion (CWE-674) vulnerability in node-forge ver | |
| CVE-2025-6195 | 4.3 | 0.01% | 1 | 0 | 2025-11-26T21:31:37 | GitLab has remediated an issue in GitLab EE affecting all versions from 13.7 bef | |
| CVE-2025-7449 | 6.5 | 0.03% | 1 | 0 | 2025-11-26T21:31:37 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 b | |
| CVE-2025-13611 | 2.0 | 0.01% | 1 | 0 | 2025-11-26T21:31:37 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 | |
| CVE-2025-65676 | None | 0.02% | 1 | 1 | 2025-11-26T21:31:37 | Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows | |
| CVE-2025-65675 | None | 0.02% | 1 | 1 | 2025-11-26T21:31:26 | Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows | |
| CVE-2025-12653 | 6.5 | 0.03% | 1 | 0 | 2025-11-26T20:15:49.023000 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 | |
| CVE-2025-12571 | 7.5 | 0.04% | 1 | 0 | 2025-11-26T20:15:47.943000 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 | |
| CVE-2025-66020 | 7.5 | 0.04% | 1 | 0 | 2025-11-26T19:33:36 | ### Summary The `EMOJI_REGEX` used in the `emoji` action is vulnerable to a Reg | |
| CVE-2025-65966 | None | 0.04% | 2 | 0 | 2025-11-26T19:33:10 | ### Summary A low-permission user can create new accounts through a direct API r | |
| CVE-2025-64128 | 10.0 | 3.18% | 1 | 0 | 2025-11-26T18:31:15 | An OS command injection vulnerability exists due to incomplete validation of us | |
| CVE-2025-64127 | 10.0 | 3.18% | 1 | 0 | 2025-11-26T18:31:15 | An OS command injection vulnerability exists due to insufficient sanitization o | |
| CVE-2025-64126 | 10.0 | 3.18% | 1 | 0 | 2025-11-26T18:31:15 | An OS command injection vulnerability exists due to improper input validation. | |
| CVE-2025-65239 | 4.3 | 0.03% | 1 | 0 | 2025-11-26T18:31:15 | Incorrect access control in the /aux1/ocussd/trace endpoint of OpenCode Systems | |
| CVE-2025-65238 | None | 0.02% | 1 | 0 | 2025-11-26T18:31:15 | Incorrect access control in the getSubUsersByProvider function of OpenCode Syste | |
| CVE-2025-64130 | 9.8 | 0.11% | 1 | 0 | 2025-11-26T18:15:50.243000 | Zenitel TCIV-3+ is vulnerable to a reflected cross-site scripting vulnerability | |
| CVE-2025-2486 | 0 | 0.01% | 2 | 0 | 2025-11-26T18:15:48.357000 | The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be | |
| CVE-2025-63938 | 6.5 | 0.03% | 1 | 0 | 2025-11-26T17:15:46.440000 | Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip | |
| CVE-2025-66257 | 0 | 0.07% | 2 | 0 | 2025-11-26T16:15:51.030000 | Unauthenticated Arbitrary File Deletion (patch_contents.php) in DB Electronica T | |
| CVE-2025-66026 | 6.1 | 0.04% | 1 | 0 | 2025-11-26T16:15:50.917000 | REDAXO is a PHP-based CMS. Prior to version 5.20.1, a reflected Cross-Site Scrip | |
| CVE-2025-66021 | 0 | 0.05% | 2 | 0 | 2025-11-26T16:15:50.413000 | OWASP Java HTML Sanitizer is a configureable HTML Sanitizer written in Java, all | |
| CVE-2025-9163 | 6.1 | 0.07% | 1 | 0 | 2025-11-26T15:34:20 | The Houzez theme for WordPress is vulnerable to Stored Cross-Site Scripting via | |
| CVE-2025-13601 | 7.7 | 0.01% | 1 | 0 | 2025-11-26T15:34:20 | A heap-based buffer overflow problem was found in glib through an incorrect calc | |
| CVE-2025-12061 | 8.6 | 0.03% | 1 | 0 | 2025-11-26T15:15:51.087000 | The TAX SERVICE Electronic HDM WordPress plugin before 1.2.1 does not authorizat | |
| CVE-2025-9191 | 6.3 | 0.05% | 1 | 0 | 2025-11-26T13:16:00.923000 | The Houzez theme for WordPress is vulnerable to PHP Object Injection in all vers | |
| CVE-2025-13674 | 5.5 | 0.01% | 1 | 0 | 2025-11-26T12:30:16 | BPv7 dissector crash in Wireshark 4.6.0 allows denial of service | |
| CVE-2025-62728 | None | 0.02% | 1 | 0 | 2025-11-26T09:31:30 | SQL injection vulnerability in Hive Metastore Server (HMS) when processing delet | |
| CVE-2025-13735 | 7.4 | 0.04% | 1 | 0 | 2025-11-26T07:16:00.173000 | Out-of-bounds Read vulnerability in ASR1903、ASR3901 in ASR Lapwing_Linux on Linu | |
| CVE-2025-64983 | 8.0 | 0.03% | 2 | 0 | 2025-11-26T06:31:34 | Smart Video Doorbell firmware versions prior to 2.01.078 contain an active debug | |
| CVE-2025-66233 | None | 0.00% | 1 | 0 | 2025-11-26T06:31:34 | Rejected reason: Not used | |
| CVE-2025-66231 | None | 0.00% | 1 | 0 | 2025-11-26T06:31:34 | Rejected reason: Not used | |
| CVE-2025-66229 | None | 0.00% | 1 | 0 | 2025-11-26T06:31:34 | Rejected reason: Not used | |
| CVE-2025-55174 | 3.2 | 0.01% | 1 | 0 | 2025-11-26T06:31:28 | In KDE Skanpage before 25.08.0, an attempt at file overwrite can result in the c | |
| CVE-2025-59820 | 6.7 | 0.02% | 1 | 0 | 2025-11-26T06:31:28 | In KDE Krita before 5.2.13, loading a manipulated TGA file could result in a hea | |
| CVE-2025-66235 | None | 0.00% | 1 | 0 | 2025-11-26T06:31:28 | Rejected reason: Not used | |
| CVE-2025-66232 | None | 0.00% | 1 | 0 | 2025-11-26T06:31:28 | Rejected reason: Not used | |
| CVE-2025-9557 | 7.6 | 0.01% | 1 | 0 | 2025-11-26T06:15:46.007000 | An out-of-bound write can lead to an arbitrary code execution. Even on devices | |
| CVE-2025-66234 | 0 | 0.00% | 1 | 0 | 2025-11-26T04:15:57.677000 | Rejected reason: Not used | |
| CVE-2025-66230 | 0 | 0.00% | 1 | 0 | 2025-11-26T04:15:57.393000 | Rejected reason: Not used | |
| CVE-2025-66250 | None | 0.04% | 1 | 0 | 2025-11-26T03:30:28 | Unauthenticated Arbitrary File Upload (status_contents.php) in DB Electronica Te | |
| CVE-2025-66253 | None | 0.93% | 1 | 0 | 2025-11-26T03:30:28 | Unauthenticated OS Command Injection (start_upgrade.php) in DB Electronica Telec | |
| CVE-2025-66258 | None | 0.05% | 1 | 0 | 2025-11-26T03:30:28 | Stored Cross-Site Scripting via XML Injection in DB Electronica Telecomunicazion | |
| CVE-2025-66261 | None | 0.93% | 2 | 0 | 2025-11-26T03:30:28 | Unauthenticated OS Command Injection (restore_settings.php) in DB Electronica Te | |
| CVE-2025-66259 | None | 0.36% | 2 | 0 | 2025-11-26T03:30:28 | Authenticated Root Remote Code Execution via improrer user input filtering in DB | |
| CVE-2025-66266 | None | 0.02% | 2 | 0 | 2025-11-26T03:30:28 | The RupsMon.exe service executable in UPSilon 2000 has insecure permissions, all | |
| CVE-2025-66269 | None | 0.01% | 1 | 0 | 2025-11-26T03:30:28 | The RupsMon and USBMate services in UPSilon 2000 run with SYSTEM privileges and | |
| CVE-2025-12848 | None | 0.07% | 1 | 0 | 2025-11-26T03:30:28 | Webform Multiple File Upload module for Drupal 7.x contains a cross-site scripti | |
| CVE-2025-66265 | None | 0.01% | 1 | 0 | 2025-11-26T03:30:28 | CMService.exe creates the C:\\usr directory and subdirectories with insecure per | |
| CVE-2025-66251 | None | 0.17% | 1 | 0 | 2025-11-26T03:30:27 | Unauthenticated Path Traversal with Arbitrary File Deletion in DB Electronica Te | |
| CVE-2025-66252 | None | 0.04% | 1 | 0 | 2025-11-26T03:30:27 | Infinite Loop Denial of Service via Failed File Deletion in DB Electronica Telec | |
| CVE-2025-64657 | 9.8 | 0.09% | 1 | 0 | 2025-11-26T03:30:27 | Stack-based buffer overflow in Azure Application Gateway allows an unauthorized | |
| CVE-2025-66263 | None | 0.04% | 2 | 0 | 2025-11-26T03:30:22 | Unauthenticated Arbitrary File Read via Null Byte Injection in DB Electronica Te | |
| CVE-2025-66262 | None | 0.07% | 2 | 0 | 2025-11-26T03:30:22 | Arbitrary File Overwrite via Tar Extraction Path Traversal in DB Electronica Tel | |
| CVE-2025-66260 | None | 0.03% | 1 | 0 | 2025-11-26T03:30:22 | PostgreSQL SQL Injection (status_sql.php) in DB Electronica Telecomunicazioni S. | |
| CVE-2025-66256 | None | 0.04% | 1 | 0 | 2025-11-26T03:30:22 | Unauthenticated Arbitrary File Upload (patch_contents.php) in DB Electronica Tel | |
| CVE-2025-64656 | 9.4 | 0.09% | 1 | 0 | 2025-11-26T03:30:21 | Out-of-bounds read in Application Gateway allows an unauthorized attacker to ele | |
| CVE-2025-66264 | 0 | 0.01% | 1 | 0 | 2025-11-26T01:16:10.023000 | The CMService.exe service runs with SYSTEM privileges and contains an unquoted s | |
| CVE-2025-66255 | 0 | 0.10% | 1 | 0 | 2025-11-26T01:16:08.710000 | Unauthenticated Arbitrary File Upload (upgrade_contents.php) in DB Electronica T | |
| CVE-2025-66254 | 0 | 0.07% | 1 | 0 | 2025-11-26T01:16:08.570000 | Unauthenticated Arbitrary File Deletion (upgrade_contents.php) in DB Electronica | |
| CVE-2025-13597 | 9.8 | 0.19% | 1 | 1 | 2025-11-26T00:30:31 | The AI Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to | |
| CVE-2025-13595 | 9.8 | 0.19% | 1 | 1 | 2025-11-26T00:30:31 | The CIBELES AI plugin for WordPress is vulnerable to arbitrary file uploads due | |
| CVE-2025-65952 | 0 | 0.04% | 1 | 0 | 2025-11-25T23:15:48.097000 | Console is a network used to control Gorilla Tag mods' users and other users on | |
| CVE-2025-41115 | 10.0 | 0.02% | 1 | 1 | 2025-11-25T22:16:42.557000 | SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in Apri | |
| CVE-2025-59372 | 0 | 0.15% | 2 | 0 | 2025-11-25T22:16:16.690000 | A path traversal vulnerability has been identified in certain router models. A r | |
| CVE-2025-59369 | 0 | 0.10% | 2 | 0 | 2025-11-25T22:16:16.690000 | A SQL injection vulnerability has been identified in bwdpi. A remote, authentica | |
| CVE-2025-59371 | 0 | 0.15% | 2 | 0 | 2025-11-25T22:16:16.690000 | An authentication bypass vulnerability has been identified in the IFTTT integrat | |
| CVE-2025-59365 | 0 | 0.04% | 2 | 0 | 2025-11-25T22:16:16.690000 | A stack buffer overflow vulnerability has been identified in certain router mode | |
| CVE-2025-59368 | 0 | 0.04% | 2 | 0 | 2025-11-25T22:16:16.690000 | An integer underflow vulnerability has been identified in Aicloud. An authentica | |
| CVE-2025-59366 | 0 | 0.10% | 4 | 0 | 2025-11-25T22:16:16.690000 | An authentication-bypass vulnerability exists in AiCloud. This vulnerability can | |
| CVE-2025-59370 | 0 | 0.52% | 2 | 0 | 2025-11-25T22:16:16.690000 | A command injection vulnerability has been identified in bwdpi. A remote, authen | |
| CVE-2025-12003 | 0 | 0.20% | 2 | 0 | 2025-11-25T22:16:16.690000 | A path traversal vulnerability has been identified in WebDAV, which may allow un | |
| CVE-2025-58360 | 8.2 | 7.96% | 3 | 2 | template | 2025-11-25T22:16:16.690000 | GeoServer is an open source server that allows users to share and edit geospatia |
| CVE-2025-33203 | 7.6 | 0.03% | 1 | 0 | 2025-11-25T22:16:16.690000 | NVIDIA NeMo Agent Toolkit UI for Web contains a vulnerability in the chat API en | |
| CVE-2025-12816 | 8.6 | 0.06% | 1 | 0 | 2025-11-25T22:16:16.690000 | An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 | |
| CVE-2025-64064 | 8.8 | 0.03% | 1 | 0 | 2025-11-25T21:32:13 | Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check us | |
| CVE-2025-33187 | 9.4 | 0.01% | 3 | 0 | 2025-11-25T18:32:29 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT, where an attacker could | |
| CVE-2025-33205 | 7.3 | 0.01% | 1 | 0 | 2025-11-25T18:32:29 | NVIDIA NeMo framework contains a vulnerability in a predefined variable, where a | |
| CVE-2025-33204 | 7.8 | 0.02% | 1 | 0 | 2025-11-25T18:32:29 | NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP and | |
| CVE-2025-59373 | None | 0.01% | 2 | 0 | 2025-11-25T03:30:20 | A local privilege escalation vulnerability exists in the restore mechanism of | |
| CVE-2025-9900 | 8.8 | 0.03% | 1 | 0 | 2025-11-24T21:30:58 | A flaw was found in Libtiff. This vulnerability is a "write-what-where" conditio | |
| CVE-2025-7425 | 7.8 | 0.04% | 1 | 0 | 2025-11-22T03:31:17 | A flaw was found in libxslt where the attribute type, atype, flags are modified | |
| CVE-2025-61757 | 9.8 | 60.96% | 1 | 2 | template | 2025-11-21T21:30:16 | Vulnerability in the Identity Manager product of Oracle Fusion Middleware (compo |
| CVE-2025-11001 | 7.0 | 0.38% | 3 | 6 | 2025-11-20T00:31:21 | 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. | |
| CVE-2025-37899 | 7.8 | 0.01% | 1 | 2 | 2025-11-19T15:32:29 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix | |
| CVE-2025-48593 | 8.0 | 0.03% | 1 | 6 | 2025-11-18T12:31:19 | In bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote co | |
| CVE-2025-46817 | 7.0 | 26.29% | 1 | 2 | template | 2025-11-12T11:34:13.390000 | Redis is an open source, in-memory database that persists on disk. Versions 8.2. |
| CVE-2025-59287 | 9.8 | 64.04% | 1 | 22 | template | 2025-11-11T15:32:22 | Deserialization of untrusted data in Windows Server Update Service allows an una |
| CVE-2024-9680 | 9.8 | 24.62% | 1 | 2 | 2025-11-04T00:31:33 | An attacker was able to achieve code execution in the content process by exploit | |
| CVE-2023-44487 | 5.3 | 94.50% | 1 | 19 | 2025-10-22T19:24:09 | ## HTTP/2 Rapid reset attack The HTTP/2 protocol allows clients to indicate to t | |
| CVE-2023-29357 | 9.8 | 94.36% | 1 | 7 | template | 2025-10-22T00:33:51 | Microsoft SharePoint Server Elevation of Privilege Vulnerability |
| CVE-2025-59821 | 6.5 | 0.04% | 1 | 0 | 2025-09-23T19:13:36 | # Summary A reflected cross-site scripting (XSS) vulnerability exists under cert | |
| CVE-2023-48733 | 6.7 | 0.01% | 1 | 0 | 2025-05-08T18:31:34 | An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK | |
| CVE-2021-32682 | 9.8 | 93.47% | 1 | 0 | template | 2023-01-29T05:02:39 | ### Impact We recently fixed several vulnerabilities affect elFinder 2.1.58. Th |
| CVE-2022-31806 | 9.8 | 0.30% | 1 | 0 | 2023-01-27T05:04:35 | In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 pas | |
| CVE-2022-22515 | 8.1 | 0.08% | 1 | 0 | 2023-01-27T05:01:23 | A remote, unauthenticated attacker could utilize the control programmer of the C | |
| CVE-2025-13086 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2025-64344 | 0 | 0.04% | 1 | 0 | N/A | ||
| CVE-2025-64332 | 0 | 0.04% | 1 | 0 | N/A | ||
| CVE-2025-64331 | 0 | 0.04% | 1 | 0 | N/A | ||
| CVE-2025-66270 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2025-64334 | 0 | 0.04% | 1 | 0 | N/A | ||
| CVE-2025-64333 | 0 | 0.04% | 1 | 0 | N/A | ||
| CVE-2025-13084 | 0 | 0.04% | 1 | 0 | N/A | ||
| CVE-2025-66022 | 0 | 0.18% | 2 | 1 | N/A | ||
| CVE-2025-9558 | 0 | 0.01% | 1 | 0 | N/A | ||
| CVE-2025-66025 | 0 | 0.03% | 1 | 0 | N/A | ||
| CVE-2025-65957 | 0 | 0.04% | 1 | 0 | N/A |
updated 2025-11-28T21:32:24
1 posts
CVE-2025-13683 - Devolutions Server and Remote Desktop Manager Credential Exposure https://cvefeed.io/vuln/detail/CVE-2025-13683
##updated 2025-11-28T21:32:24
1 posts
CVE-2025-40934 - XML-Sig prior to 0.68 for Perl improperly validates XML without signatures https://cvefeed.io/vuln/detail/CVE-2025-40934
##updated 2025-11-28T21:31:18
1 posts
updated 2025-11-28T21:15:48.280000
1 posts
1 repos
CVE-2025-65681 - Overhang.IO (tutor-open-edx) Information Disclosure https://cvefeed.io/vuln/detail/CVE-2025-65681
##updated 2025-11-28T19:15:44.900000
5 posts
🚨CVE-2021-26829: OpenPLC ScadaBR Cross-site Scripting Vulnerability
Vendor: OpenPLC
Product: ScadaBR
CWE: CWE-79
CVSS: 5.4
This vulnerability has been added to the CISA KEV Catalog.
##🚨 [CISA-2025:1128] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2025:1128)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2021-26829 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-26829)
- Name: OpenPLC ScadaBR Cross-site Scripting Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: OpenPLC
- Product: ScadaBR
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/SCADA-LTS/Scada-LTS/pull/3211 ; https://nvd.nist.gov/vuln/detail/CVE-2021-26829
#SecDB #InfoSec #CVE #CISA_KEV #cisa_20251128 #cisa20251128 #cve_2021_26829 #cve202126829
##CVE ID: CVE-2021-26829
Vendor: OpenPLC
Product: ScadaBR
Date Added: 2025-11-28
Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/SCADA-LTS/Scada-LTS/pull/3211 ; https://nvd.nist.gov/vuln/detail/CVE-2021-26829
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2021-26829
🚨CVE-2021-26829: OpenPLC ScadaBR Cross-site Scripting Vulnerability
Vendor: OpenPLC
Product: ScadaBR
CWE: CWE-79
CVSS: 5.4
This vulnerability has been added to the CISA KEV Catalog.
##CVE ID: CVE-2021-26829
Vendor: OpenPLC
Product: ScadaBR
Date Added: 2025-11-28
Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/SCADA-LTS/Scada-LTS/pull/3211 ; https://nvd.nist.gov/vuln/detail/CVE-2021-26829
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2021-26829
updated 2025-11-28T18:31:28
1 posts
CVE-2025-51736 - HCL Unica File Upload Remote Code Execution Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-51736
##updated 2025-11-28T18:31:27
1 posts
CVE-2025-51735 - HCL Technologies Ltd. Unica CSV Formula Injection Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-51735
##updated 2025-11-28T18:31:27
1 posts
CVE-2025-51734 - HCL Unica Unauthenticated Cross-Site Scripting Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-51734
##updated 2025-11-28T18:31:27
1 posts
CVE-2025-51733 - HCL Unica CSRF Attack Vector https://cvefeed.io/vuln/detail/CVE-2025-51733
##updated 2025-11-28T18:31:27
1 posts
CVE-2025-13742 - Limited HTML injection in emails https://cvefeed.io/vuln/detail/CVE-2025-13742
##updated 2025-11-28T18:30:32
2 posts
CVE-2025-12183 - org.lz4:lz4-java - Out-of-Bounds Memory Access https://cvefeed.io/vuln/detail/CVE-2025-12183
##CVE-2025-12183 - org.lz4:lz4-java - Out-of-Bounds Memory Access https://cvefeed.io/vuln/detail/CVE-2025-12183
##updated 2025-11-28T18:30:24
1 posts
CVE-2025-59790 - Apache Kvrocks: RESET command grants admin privileges https://cvefeed.io/vuln/detail/CVE-2025-59790
##updated 2025-11-28T18:30:24
1 posts
CVE-2025-59792 - Apache Kvrocks: MONITOR command reveals plaintext credentials to non-admins https://cvefeed.io/vuln/detail/CVE-2025-59792
##updated 2025-11-28T18:30:23
1 posts
CVE-2025-59454 - Apache CloudStack: Lack of user permission validation leading to data leak for few APIs https://cvefeed.io/vuln/detail/CVE-2025-59454
##updated 2025-11-28T15:31:38
1 posts
CVE-2025-59302 - Apache CloudStack: Potential remote code execution on Javascript engine defined rules https://cvefeed.io/vuln/detail/CVE-2025-59302
##updated 2025-11-28T15:30:36
2 posts
CVE-2025-12638 - Path Traversal Vulnerability in keras-team/keras via Tar Archive Extraction in keras.utils.get_file() https://cvefeed.io/vuln/detail/CVE-2025-12638
##CVE-2025-12638 - Path Traversal Vulnerability in keras-team/keras via Tar Archive Extraction in keras.utils.get_file() https://cvefeed.io/vuln/detail/CVE-2025-12638
##updated 2025-11-28T15:30:36
1 posts
CVE-2025-11156 - Improper Service Loading Vulnerability in Netskope Endpoint DLP Driver https://cvefeed.io/vuln/detail/CVE-2025-11156
##updated 2025-11-28T15:16:03.483000
1 posts
updated 2025-11-28T12:30:28
1 posts
CVE-2025-12143 - Stack Memory Corruption Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-12143
##updated 2025-11-28T09:30:22
3 posts
🚨 CRITICAL: CVE-2025-66385 in Cerebrate <1.30 lets auth'd users escalate privileges via user-edit endpoint (role_id/org_id). Upgrade ASAP, monitor logs, and apply stricter validation. https://radar.offseq.com/threat/cve-2025-66385-cwe-472-external-control-of-assumed-6cd61d91 #OffSeq #CVE202566385 #infosec #PrivilegeEscalation
##CVE-2025-66385 - Cerebrate Privilege Escalation Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-66385
##CVE-2025-66385 - Cerebrate Privilege Escalation Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-66385
##updated 2025-11-28T09:30:22
1 posts
CVE-2025-13769 - Uniong|WebITR - SQL Injection https://cvefeed.io/vuln/detail/CVE-2025-13769
##updated 2025-11-28T09:30:18
1 posts
CVE-2025-13770 - Uniong|WebITR - SQL Injection https://cvefeed.io/vuln/detail/CVE-2025-13770
##updated 2025-11-28T09:30:18
1 posts
CVE-2025-13768 - Uniong|WebITR - Authorization Bypass https://cvefeed.io/vuln/detail/CVE-2025-13768
##updated 2025-11-28T09:30:17
2 posts
CVE-2025-13771: HIGH severity path traversal in Uniong WebITR lets authenticated users read any file on the server. Review input validation, tighten access, and monitor logins. No patch yet—mitigate now! https://radar.offseq.com/threat/cve-2025-13771-cwe-23-relative-path-traversal-in-u-c33e17b9 #OffSeq #infosec #vulnerability #WebITR
##CVE-2025-13771 - Uniong|WebITR - Arbitrary File Read https://cvefeed.io/vuln/detail/CVE-2025-13771
##updated 2025-11-28T09:30:17
2 posts
CVE-2025-66384 - MISP File Upload Validation Bypass https://cvefeed.io/vuln/detail/CVE-2025-66384
##CVE-2025-66384 - MISP File Upload Validation Bypass https://cvefeed.io/vuln/detail/CVE-2025-66384
##updated 2025-11-28T09:30:17
1 posts
CVE-2025-66382 - Apache libexpat XML Entity Expansion Denial of Service https://cvefeed.io/vuln/detail/CVE-2025-66382
##updated 2025-11-28T07:15:59.900000
1 posts
CVE-2025-66386 - MISP Path Traversal Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-66386
##updated 2025-11-28T06:32:10
1 posts
CVE-2025-58308 - Apache Call Module Authentication Bypass Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-58308
##updated 2025-11-28T06:32:10
1 posts
CVE-2025-58305 - Gallery App Authentication Bypass https://cvefeed.io/vuln/detail/CVE-2025-58305
##updated 2025-11-28T06:32:09
3 posts
🔒 CVE-2025-58302 (HIGH, CVSS 8.4) in Huawei HarmonyOS (2.0.0–4.3.1): Local attackers can bypass Settings module permission checks, risking data exposure. Restrict device access & monitor for unusual activity. https://radar.offseq.com/threat/cve-2025-58302-cwe-264-permissions-privileges-and--7634fe98 #OffSeq #Huawei #Infosec #Vuln
##CVE-2025-58302 - "Acme Settings Module Unsecured Configuration" https://cvefeed.io/vuln/detail/CVE-2025-58302
##CVE-2025-58302 - "Acme Settings Module Unsecured Configuration" https://cvefeed.io/vuln/detail/CVE-2025-58302
##updated 2025-11-28T06:32:09
1 posts
CVE-2025-64312 - Apache File Manager Unauthenticated File Access Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-64312
##updated 2025-11-28T06:32:09
1 posts
CVE-2025-13737 - Nextend Social Login and Register <= 3.1.21 - Cross-Site Request Forgery to Unlink User Social Login https://cvefeed.io/vuln/detail/CVE-2025-13737
##updated 2025-11-28T06:32:07
1 posts
CVE-2025-66372 - Mustang XML External Entity (XXE) Exfiltration Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-66372
##updated 2025-11-28T06:32:07
1 posts
CVE-2025-66370 - Kivitendo XXE Filesystem Exfiltration https://cvefeed.io/vuln/detail/CVE-2025-66370
##updated 2025-11-28T04:16:01.293000
1 posts
CVE-2025-66371 - Peppol-py XXE File Disclosure Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-66371
##updated 2025-11-28T04:16:00.807000
1 posts
CVE-2025-58311 - "USB Driver Uninitialized Free Memory UAF Vulnerability" https://cvefeed.io/vuln/detail/CVE-2025-58311
##updated 2025-11-28T04:16:00.347000
1 posts
CVE-2025-58304 - Apache File Manager Unauthorized Access Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-58304
##updated 2025-11-28T03:30:34
1 posts
CVE-2025-58303 - Adobe Screen Recorder Use-After-Free Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-58303
##updated 2025-11-28T03:30:33
1 posts
CVE-2025-58310 - Apache Distributed Component Permission Control Bypass https://cvefeed.io/vuln/detail/CVE-2025-58310
##updated 2025-11-28T03:16:00.867000
2 posts
CVE-2025-64314 - Cisco Memory Management Permission Control Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-64314
##⚠️ CRITICAL: CVE-2025-64314 in Huawei HarmonyOS 5.1.0 enables type confusion attacks via faulty permission controls. Potential for sensitive data exposure—no patch yet. Restrict device access & monitor for updates. https://radar.offseq.com/threat/cve-2025-64314-cwe-843-access-of-resource-using-in-e6e520d9 #OffSeq #Huawei #CVE #Infosec #Vulnerability
##updated 2025-11-28T00:30:28
1 posts
CVE-2025-66360 - Logpoint Access Control Policy Privilege Escalation Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-66360
##updated 2025-11-28T00:30:27
1 posts
CVE-2025-66361 - Logpoint Exposes Sensitive Information https://cvefeed.io/vuln/detail/CVE-2025-66361
##updated 2025-11-28T00:15:46.003000
2 posts
CVE-2025-66359 - Logpoint Cross-Site Scripting Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-66359
##CVE-2025-66359 - Logpoint Cross-Site Scripting Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-66359
##updated 2025-11-27T23:15:50.550000
1 posts
CVE-2025-13338 - Apache HTTP Server Cross-Site Scripting https://cvefeed.io/vuln/detail/CVE-2025-13338
##updated 2025-11-27T18:30:34
1 posts
CVE-2025-3261 - Stored Cross-Site Scripting (XSS) in ThingsBoard https://cvefeed.io/vuln/detail/CVE-2025-3261
##updated 2025-11-27T18:30:26
1 posts
CVE-2025-12559 - Information Disclosure in Common Teams API https://cvefeed.io/vuln/detail/CVE-2025-12559
##updated 2025-11-27T18:30:26
2 posts
CVE-2025-12419 - Account takeover on OAuth/OpenID-enabled servers https://cvefeed.io/vuln/detail/CVE-2025-12419
##CVE-2025-12419 - Account takeover on OAuth/OpenID-enabled servers https://cvefeed.io/vuln/detail/CVE-2025-12419
##updated 2025-11-27T18:30:26
1 posts
CVE-2025-13757 - Devolutions Server SQL Injection https://cvefeed.io/vuln/detail/CVE-2025-13757
##updated 2025-11-27T18:30:26
1 posts
CVE-2025-13765 - Devolutions Server Unsecured Email Credentials Exposure https://cvefeed.io/vuln/detail/CVE-2025-13765
##updated 2025-11-27T18:15:46.223000
2 posts
CVE-2025-12421 - Account Takeover via Code Exchange Endpoint https://cvefeed.io/vuln/detail/CVE-2025-12421
##CVE-2025-12421 - Account Takeover via Code Exchange Endpoint https://cvefeed.io/vuln/detail/CVE-2025-12421
##updated 2025-11-27T16:15:47.257000
1 posts
CVE-2025-13758 - Devolutions Server Exposed Credentials Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-13758
##updated 2025-11-27T15:32:27
1 posts
CVE-2025-54057 - Apache SkyWalking: Stored XSS vulnerability https://cvefeed.io/vuln/detail/CVE-2025-54057
##updated 2025-11-27T15:31:32
2 posts
CVE-2025-12140 - RCE in Wirtualna Uczelnia https://cvefeed.io/vuln/detail/CVE-2025-12140
##CVE-2025-12140 - RCE in Wirtualna Uczelnia https://cvefeed.io/vuln/detail/CVE-2025-12140
##updated 2025-11-27T15:31:32
1 posts
CVE-2025-13692 - Unlimited Elements For Elementor and Unlimited Elements For Elementor (Premium) <= 2.0 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload https://cvefeed.io/vuln/detail/CVE-2025-13692
##updated 2025-11-27T14:15:52.183000
2 posts
CVE-2025-8890 - Authenticated RCE in SDMC NE6037 router https://cvefeed.io/vuln/detail/CVE-2025-8890
##CVE-2025-8890 - Authenticated RCE in SDMC NE6037 router https://cvefeed.io/vuln/detail/CVE-2025-8890
##updated 2025-11-27T13:15:58.547000
1 posts
CVE-2025-12971 - Folders <= 3.1.5 - Incorrect Authorization to Authenticated (Contributor+) Folder Content Manipulation https://cvefeed.io/vuln/detail/CVE-2025-12971
##updated 2025-11-27T12:30:34
1 posts
CVE-2025-10476 - WP Fastest Cache <= 1.4.0 - Missing Authorization to Authenticated (Subscriber+) DB Cleanup Actions https://cvefeed.io/vuln/detail/CVE-2025-10476
##updated 2025-11-27T12:30:34
1 posts
CVE-2025-59025 - Apache Email Script Execution Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-59025
##updated 2025-11-27T12:30:34
1 posts
CVE-2025-30186 - Apache File Upload Cross-Site Scripting (XSS) https://cvefeed.io/vuln/detail/CVE-2025-30186
##updated 2025-11-27T12:30:34
1 posts
CVE-2025-13378 - AI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.0 - Unauthenticated Server-Side Request Forgery via 'pinecone_url' Parameter https://cvefeed.io/vuln/detail/CVE-2025-13378
##updated 2025-11-27T12:30:34
1 posts
CVE-2025-12584 - Quick View for WooCommerce <= 2.2.17 - Unauthenticated Private Product Disclosure https://cvefeed.io/vuln/detail/CVE-2025-12584
##updated 2025-11-27T12:30:29
1 posts
CVE-2025-30190 - Microsoft Office Document Code Injection Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-30190
##updated 2025-11-27T11:15:48.080000
1 posts
CVE-2025-59890 - Eaton Galileo Local File Inclusion Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-59890
##updated 2025-11-27T10:15:52.007000
1 posts
CVE-2025-59026 - Apache File Upload Cross-Site Scripting https://cvefeed.io/vuln/detail/CVE-2025-59026
##updated 2025-11-27T10:15:51.220000
1 posts
CVE-2025-13381 - AI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.0 - Missing Authorization to Unauthenticated Media File Uploads https://cvefeed.io/vuln/detail/CVE-2025-13381
##updated 2025-11-27T09:30:26
2 posts
CVE-2025-13536 - Blubrry PowerPress <= 11.15.2 - Authenticated (Contributor+) Arbitrary File Upload via 'powerpress_edit_post' https://cvefeed.io/vuln/detail/CVE-2025-13536
##CVE-2025-13536 - Blubrry PowerPress <= 11.15.2 - Authenticated (Contributor+) Arbitrary File Upload via 'powerpress_edit_post' https://cvefeed.io/vuln/detail/CVE-2025-13536
##updated 2025-11-27T09:30:26
1 posts
CVE-2025-13157 - QODE Wishlist for WooCommerce <= 1.2.7 - Unauthenticated Insecure Direct Object Reference to Wishlist Update https://cvefeed.io/vuln/detail/CVE-2025-13157
##updated 2025-11-27T09:30:25
1 posts
CVE-2025-13441 - Hide Category by User Role for WooCommerce <= 2.3.1 - Missing Authorization to Unauthenticated Cache Flushing https://cvefeed.io/vuln/detail/CVE-2025-13441
##updated 2025-11-27T09:01:21
1 posts
CVE-2025-66028 - OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulation https://cvefeed.io/vuln/detail/CVE-2025-66028
##updated 2025-11-27T09:00:41
1 posts
CVE-2025-62703 - Fugue is Vulnerable to Remote Code Execution by Pickle Deserialization via FlaskRPCServer https://cvefeed.io/vuln/detail/CVE-2025-62703
##updated 2025-11-27T06:31:33
2 posts
CVE-2025-13540 - Tiare Membership <= 1.2 - Unauthenticated Privilege Escalation https://cvefeed.io/vuln/detail/CVE-2025-13540
##CVE-2025-13540 - Tiare Membership <= 1.2 - Unauthenticated Privilege Escalation https://cvefeed.io/vuln/detail/CVE-2025-13540
##updated 2025-11-27T06:31:33
2 posts
CVE-2025-13675 - Tiger <= 101.2.1 - Unauthenticated Privilege Escalation https://cvefeed.io/vuln/detail/CVE-2025-13675
##CVE-2025-13675 - Tiger <= 101.2.1 - Unauthenticated Privilege Escalation https://cvefeed.io/vuln/detail/CVE-2025-13675
##updated 2025-11-27T06:31:32
1 posts
CVE-2025-12758 - Validator Package Unicode Filtering Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-12758
##updated 2025-11-27T06:31:32
1 posts
CVE-2025-12151 - Simple Folio <= 1.1.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting https://cvefeed.io/vuln/detail/CVE-2025-12151
##updated 2025-11-27T06:31:26
1 posts
CVE-2025-12185 - StaffList <= 3.2.6 - Authenticated (Admin+) Stored Cross-Site Scripting https://cvefeed.io/vuln/detail/CVE-2025-12185
##updated 2025-11-27T06:31:26
1 posts
CVE-2025-12123 - Customer Reviews Collector for WooCommerce <= 4.6.1 - Reflected Cross-Site Scripting https://cvefeed.io/vuln/detail/CVE-2025-12123
##updated 2025-11-27T06:31:26
2 posts
CVE-2025-13539 - FindAll Membership <= 1.0.4 - Authentication Bypass via Social Login https://cvefeed.io/vuln/detail/CVE-2025-13539
##CVE-2025-13539 - FindAll Membership <= 1.0.4 - Authentication Bypass via Social Login https://cvefeed.io/vuln/detail/CVE-2025-13539
##updated 2025-11-27T06:31:26
1 posts
CVE-2025-7820 - SKT PayPal for WooCommerce <= 1.4 - Unauthenticated Payment Bypass https://cvefeed.io/vuln/detail/CVE-2025-7820
##updated 2025-11-27T06:15:46.830000
1 posts
CVE-2025-13525 - WP Directory Kit <= 1.4.5 - Reflected Cross-Site Scripting via 'order_by' Parameter https://cvefeed.io/vuln/detail/CVE-2025-13525
##updated 2025-11-27T06:15:46.657000
1 posts
CVE-2025-13143 - Poll, Survey & Quiz Maker Plugin by Opinion Stage <= 19.12.0 - Cross-Site Request Forgery to Account Disconnection https://cvefeed.io/vuln/detail/CVE-2025-13143
##updated 2025-11-27T05:16:15.467000
1 posts
CVE-2025-3784 - Information Disclosure Vulnerability in GX Works2 https://cvefeed.io/vuln/detail/CVE-2025-3784
##updated 2025-11-27T05:16:15.253000
2 posts
CVE-2025-13680 - Tiger <= 101.2.1 - Authenticated (Subscriber+) Privilege Escalation https://cvefeed.io/vuln/detail/CVE-2025-13680
##CVE-2025-13680 - Tiger <= 101.2.1 - Authenticated (Subscriber+) Privilege Escalation https://cvefeed.io/vuln/detail/CVE-2025-13680
##updated 2025-11-27T05:16:12.453000
2 posts
CVE-2025-13538 - FindAll Listing <= 1.0.5 - Unauthenticated Privilege Escalation https://cvefeed.io/vuln/detail/CVE-2025-13538
##CVE-2025-13538 - FindAll Listing <= 1.0.5 - Unauthenticated Privilege Escalation https://cvefeed.io/vuln/detail/CVE-2025-13538
##updated 2025-11-27T03:30:32
1 posts
CVE-2025-66314 - ZTE ElasticNet UME R32 ACL Privilege Escalation Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-66314
##updated 2025-11-27T03:30:32
2 posts
CVE-2025-34351 - Anyscale Ray v2.52.0 Token Authentication Disabled by Default Insecure Configuration https://cvefeed.io/vuln/detail/CVE-2025-34351
##CVE-2025-34351 - Anyscale Ray v2.52.0 Token Authentication Disabled by Default Insecure Configuration https://cvefeed.io/vuln/detail/CVE-2025-34351
##updated 2025-11-27T03:30:32
2 posts
CVE-2024-5539 - ALC WebCTRL Carrier i-Vu Access Control Bypass https://cvefeed.io/vuln/detail/CVE-2024-5539
##CVE-2024-5539 - ALC WebCTRL Carrier i-Vu Access Control Bypass https://cvefeed.io/vuln/detail/CVE-2024-5539
##updated 2025-11-27T03:30:32
1 posts
CVE-2024-5540 - ALC WebCTRL Carrier i-Vu Reflected Cross-Site Scripting https://cvefeed.io/vuln/detail/CVE-2024-5540
##updated 2025-11-27T03:30:26
2 posts
CVE-2025-0657 - ALC WebCTRL Carrier i-Vu and Gen5 Controllers Array Index out-of-range https://cvefeed.io/vuln/detail/CVE-2025-0657
##CVE-2025-0657 - ALC WebCTRL Carrier i-Vu and Gen5 Controllers Array Index out-of-range https://cvefeed.io/vuln/detail/CVE-2025-0657
##updated 2025-11-27T01:15:46.583000
2 posts
CVE-2025-0658 - Automated Logic and Carrier Zone Controllers malformed packets denial of service https://cvefeed.io/vuln/detail/CVE-2025-0658
##CVE-2025-0658 - Automated Logic and Carrier Zone Controllers malformed packets denial of service https://cvefeed.io/vuln/detail/CVE-2025-0658
##updated 2025-11-27T00:30:38
2 posts
CVE-2020-36871 - ESCAM QD-900 Unauthenticated Configuration Disclosure https://cvefeed.io/vuln/detail/CVE-2020-36871
##CVE-2020-36871 - ESCAM QD-900 Unauthenticated Configuration Disclosure https://cvefeed.io/vuln/detail/CVE-2020-36871
##updated 2025-11-27T00:30:27
1 posts
CVE-2020-36874 - ACE SECURITY WIP-90113 Unauthenticated Configuration Disclosure https://cvefeed.io/vuln/detail/CVE-2020-36874
##updated 2025-11-27T00:30:27
1 posts
CVE-2020-36872 - BACnet Test Server 1.01 Malformed BVLC Length DoS https://cvefeed.io/vuln/detail/CVE-2020-36872
##updated 2025-11-27T00:30:27
1 posts
CVE-2019-25226 - Dongyoung Media DM-AP240T/W Unauthenticated Configuration Disclosure https://cvefeed.io/vuln/detail/CVE-2019-25226
##updated 2025-11-27T00:15:55.343000
1 posts
CVE-2025-66040 - Spotipy has a XSS vulnerability in OAuth callback server https://cvefeed.io/vuln/detail/CVE-2025-66040
##updated 2025-11-26T23:19:19
1 posts
1 repos
CVE-2025-59390 - Apache Druid: Kerberos authenticaton chooses a cryptographically unsecure secret if not configured explicitly. https://cvefeed.io/vuln/detail/CVE-2025-59390
##updated 2025-11-26T23:18:51
1 posts
CVE-2025-66035 - Angular HTTP Client Has XSRF Token Leakage via Protocol-Relative URLs https://cvefeed.io/vuln/detail/CVE-2025-66035
##updated 2025-11-26T23:15:49.237000
1 posts
CVE-2025-66030 - node-forge ASN.1 OID Integer Truncation https://cvefeed.io/vuln/detail/CVE-2025-66030
##updated 2025-11-26T23:15:48.913000
1 posts
CVE-2025-64335 - Suricata is vulnerable to a null deref when used with base64_data https://cvefeed.io/vuln/detail/CVE-2025-64335
##updated 2025-11-26T23:15:48.093000
1 posts
CVE-2025-64330 - Suricata is vulnerable to a heap buffer overflow on verdict https://cvefeed.io/vuln/detail/CVE-2025-64330
##updated 2025-11-26T23:15:47.927000
2 posts
1 repos
CVE-2025-62593 - Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack https://cvefeed.io/vuln/detail/CVE-2025-62593
##CVE-2025-62593 - Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack https://cvefeed.io/vuln/detail/CVE-2025-62593
##updated 2025-11-26T23:15:47.397000
1 posts
CVE-2020-36873 - Astak CM-818T3 Unauthenticated Configuration Disclosure https://cvefeed.io/vuln/detail/CVE-2020-36873
##updated 2025-11-26T23:15:46.880000
2 posts
CVE-2019-25227 - Tellion HN-2204AP Unauthenticated Configuration Disclosure https://cvefeed.io/vuln/detail/CVE-2019-25227
##CVE-2019-25227 - Tellion HN-2204AP Unauthenticated Configuration Disclosure https://cvefeed.io/vuln/detail/CVE-2019-25227
##updated 2025-11-26T22:08:40
2 posts
CVE-2025-66031 - node-forge ASN.1 Unbounded Recursion https://cvefeed.io/vuln/detail/CVE-2025-66031
##CVE-2025-66031 - node-forge ASN.1 Unbounded Recursion https://cvefeed.io/vuln/detail/CVE-2025-66031
##updated 2025-11-26T21:31:37
1 posts
CVE-2025-6195 - Direct Request ('Forced Browsing') in GitLab https://cvefeed.io/vuln/detail/CVE-2025-6195
##updated 2025-11-26T21:31:37
1 posts
CVE-2025-7449 - Allocation of Resources Without Limits or Throttling in GitLab https://cvefeed.io/vuln/detail/CVE-2025-7449
##updated 2025-11-26T21:31:37
1 posts
CVE-2025-13611 - Insertion of Sensitive Information into Log File in GitLab https://cvefeed.io/vuln/detail/CVE-2025-13611
##updated 2025-11-26T21:31:37
1 posts
1 repos
CVE-2025-65676 - Classroomio LMS Stored Cross-Site Scripting (XSS) https://cvefeed.io/vuln/detail/CVE-2025-65676
##updated 2025-11-26T21:31:26
1 posts
1 repos
CVE-2025-65675 - Classroomio LMS Stored XSS https://cvefeed.io/vuln/detail/CVE-2025-65675
##updated 2025-11-26T20:15:49.023000
1 posts
CVE-2025-12653 - Authentication Bypass by Spoofing in GitLab https://cvefeed.io/vuln/detail/CVE-2025-12653
##updated 2025-11-26T20:15:47.943000
1 posts
CVE-2025-12571 - Allocation of Resources Without Limits or Throttling in GitLab https://cvefeed.io/vuln/detail/CVE-2025-12571
##updated 2025-11-26T19:33:36
1 posts
CVE-2025-66020 - Valibot has a ReDoS vulnerability in `EMOJI_REGEX` https://cvefeed.io/vuln/detail/CVE-2025-66020
##updated 2025-11-26T19:33:10
2 posts
CVE-2025-65966 - OneUptime Unauthorized User Creation via API https://cvefeed.io/vuln/detail/CVE-2025-65966
##CVE-2025-65966 - OneUptime Unauthorized User Creation via API https://cvefeed.io/vuln/detail/CVE-2025-65966
##updated 2025-11-26T18:31:15
1 posts
CVE-2025-64128 - Zenitel TCIV-3+ OS Command Injection https://cvefeed.io/vuln/detail/CVE-2025-64128
##updated 2025-11-26T18:31:15
1 posts
CVE-2025-64127 - Zenitel TCIV-3+ OS Command Injection https://cvefeed.io/vuln/detail/CVE-2025-64127
##updated 2025-11-26T18:31:15
1 posts
CVE-2025-64126 - Zenitel TCIV-3+ OS Command Injection https://cvefeed.io/vuln/detail/CVE-2025-64126
##updated 2025-11-26T18:31:15
1 posts
CVE-2025-65239 - OpenCode Systems USSD Gateway Access Control Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-65239
##updated 2025-11-26T18:31:15
1 posts
CVE-2025-65238 - OpenCode Systems USSD Gateway Privilege Escalation Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-65238
##updated 2025-11-26T18:15:50.243000
1 posts
CVE-2025-64130 - Zenitel TCIV-3+ Cross-site Scripting https://cvefeed.io/vuln/detail/CVE-2025-64130
##updated 2025-11-26T18:15:48.357000
2 posts
CVE-2025-2486 - UEFI Shell accessible in AAVMF with Secure Boot enabled on Ubuntu https://cvefeed.io/vuln/detail/CVE-2025-2486
##Not the most confidence-inspiring CVE description.
https://www.cve.org/CVERecord?id=CVE-2025-2486
##The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Secure Boot constraints. Versions 2024.05-2ubuntu0.3 and 2024.02-2ubuntu0.3 disable the Shell. Some previous versions inserted a secure-boot-based decision to continue running inside the Shell itself, which is believed to be sufficient to enforce Secure Boot restrictions. This is an additional repair on top of the incomplete fix for CVE-2023-48733.
updated 2025-11-26T17:15:46.440000
1 posts
Hey @Viss :
https://github.com/rayinaw/my-hub/blob/main/CVE-2025-63938/DISCLOSURE.md
##Tinyproxy up to 1.11.2 contains an integer overflow vulnerability in the
strip_return_port()function withinsrc/reqs.c.
updated 2025-11-26T16:15:51.030000
2 posts
Go hack more radio shit.
https://www.abdulmhsblog.com/posts/webfmvulns/
CVE-2025-66257 - Unauthenticated Arbitrary File Deletion (patch_contents.php) https://cvefeed.io/vuln/detail/CVE-2025-66257
##updated 2025-11-26T16:15:50.917000
1 posts
CVE-2025-66026 - REDAXO is Vulnerable to Reflected XSS in Mediapool Info Banner via args[types] https://cvefeed.io/vuln/detail/CVE-2025-66026
##updated 2025-11-26T16:15:50.413000
2 posts
CVE-2025-66021 - OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization https://cvefeed.io/vuln/detail/CVE-2025-66021
##CVE-2025-66021 - OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization https://cvefeed.io/vuln/detail/CVE-2025-66021
##updated 2025-11-26T15:34:20
1 posts
CVE-2025-9163 - Houzez <= 4.1.6 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload https://cvefeed.io/vuln/detail/CVE-2025-9163
##updated 2025-11-26T15:34:20
1 posts
That's an avenue that I admit I hadn't thought to check before. Seems so simple though.
https://access.redhat.com/security/cve/CVE-2025-13601
##A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.
updated 2025-11-26T15:15:51.087000
1 posts
CVE-2025-12061 - Tax Service Electronic HDM < 1.2.1 - Unauthenticated Arbitrary SQL Execution https://cvefeed.io/vuln/detail/CVE-2025-12061
##updated 2025-11-26T13:16:00.923000
1 posts
CVE-2025-9191 - Houzez <= 4.1.6 - Authenticated (Subscriber+) PHP Object Injection via Saved Search https://cvefeed.io/vuln/detail/CVE-2025-9191
##updated 2025-11-26T12:30:16
1 posts
CVE-2025-13674 - Access of Uninitialized Pointer in Wireshark https://cvefeed.io/vuln/detail/CVE-2025-13674
##updated 2025-11-26T09:31:30
1 posts
CVE-2025-62728 - Apache Hive: SQL injection vulnerability when processing delete column statistics requests via the HMS Thrift APIs https://cvefeed.io/vuln/detail/CVE-2025-62728
##updated 2025-11-26T07:16:00.173000
1 posts
CVE-2025-13735 - Out-of-bounds Read in nr flc https://cvefeed.io/vuln/detail/CVE-2025-13735
##updated 2025-11-26T06:31:34
2 posts
CVE-2025-64983 - Ring Video Doorbell Debug Code Remote Code Execution https://cvefeed.io/vuln/detail/CVE-2025-64983
##CVE-2025-64983 - Ring Video Doorbell Debug Code Remote Code Execution https://cvefeed.io/vuln/detail/CVE-2025-64983
##updated 2025-11-26T06:31:34
1 posts
CVE-2025-66233 - Apache HTTP Server Authentication Bypass https://cvefeed.io/vuln/detail/CVE-2025-66233
##updated 2025-11-26T06:31:34
1 posts
CVE-2025-66231 - Apache HTTP Server Cross-Site Request Forgery https://cvefeed.io/vuln/detail/CVE-2025-66231
##updated 2025-11-26T06:31:34
1 posts
CVE-2025-66229 - Apache HTTP Server Remote Code Execution Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-66229
##updated 2025-11-26T06:31:28
1 posts
CVE-2025-55174 - KDE Skanpage Uncontrolled File Truncation Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-55174
##updated 2025-11-26T06:31:28
1 posts
CVE-2025-59820 - KDE Krita TGA File Heap-Based Buffer Overflow Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-59820
##updated 2025-11-26T06:31:28
1 posts
CVE-2025-66235 - Apache Server HTTP Header Injection https://cvefeed.io/vuln/detail/CVE-2025-66235
##updated 2025-11-26T06:31:28
1 posts
CVE-2025-66232 - Apache Struts Cross-Site Request Forgery https://cvefeed.io/vuln/detail/CVE-2025-66232
##updated 2025-11-26T06:15:46.007000
1 posts
CVE-2025-9557 - Bluetooth: Mesh: Out-of-Bound Write in gen_prov_cont https://cvefeed.io/vuln/detail/CVE-2025-9557
##updated 2025-11-26T04:15:57.677000
1 posts
CVE-2025-66234 - Apache HTTP Server Unauthenticated Remote Code Execution https://cvefeed.io/vuln/detail/CVE-2025-66234
##updated 2025-11-26T04:15:57.393000
1 posts
CVE-2025-66230 - Apache HTTP Server Unvalidated Redirect https://cvefeed.io/vuln/detail/CVE-2025-66230
##updated 2025-11-26T03:30:28
1 posts
Go hack more radio shit.
https://www.abdulmhsblog.com/posts/webfmvulns/
updated 2025-11-26T03:30:28
1 posts
Go hack more radio shit.
https://www.abdulmhsblog.com/posts/webfmvulns/
updated 2025-11-26T03:30:28
1 posts
Go hack more radio shit.
https://www.abdulmhsblog.com/posts/webfmvulns/
updated 2025-11-26T03:30:28
2 posts
Go hack more radio shit.
https://www.abdulmhsblog.com/posts/webfmvulns/
CVE-2025-66261 - Unauthenticated OS Command Injection (restore_settings.php) https://cvefeed.io/vuln/detail/CVE-2025-66261
##updated 2025-11-26T03:30:28
2 posts
Go hack more radio shit.
https://www.abdulmhsblog.com/posts/webfmvulns/
CVE-2025-66259 - Authenticated Root Remote Code Execution through improper filtering of HTTP post request parameters https://cvefeed.io/vuln/detail/CVE-2025-66259
##updated 2025-11-26T03:30:28
2 posts
CVE-2025-66266 - Insecure SYSTEM Service Permissions in UPSilon2000V6.0 (RupsMon.exe) leading to trivial Local Privilege Escalation https://cvefeed.io/vuln/detail/CVE-2025-66266
##CVE-2025-66266 - Insecure SYSTEM Service Permissions in UPSilon2000V6.0 (RupsMon.exe) leading to trivial Local Privilege Escalation https://cvefeed.io/vuln/detail/CVE-2025-66266
##updated 2025-11-26T03:30:28
1 posts
CVE-2025-66269 - Unquoted Service Path in UPSilon2000V6.0(RupsMon and USBMate) running as SYSTEM https://cvefeed.io/vuln/detail/CVE-2025-66269
##updated 2025-11-26T03:30:28
1 posts
CVE-2025-12848 - XSS vulnerability when rendering filename in Webform Multiform https://cvefeed.io/vuln/detail/CVE-2025-12848
##updated 2025-11-26T03:30:28
1 posts
CVE-2025-66265 - Insecure permissions in configuration directory (C:\\usr) https://cvefeed.io/vuln/detail/CVE-2025-66265
##updated 2025-11-26T03:30:27
1 posts
Go hack more radio shit.
https://www.abdulmhsblog.com/posts/webfmvulns/
updated 2025-11-26T03:30:27
1 posts
Go hack more radio shit.
https://www.abdulmhsblog.com/posts/webfmvulns/
updated 2025-11-26T03:30:27
1 posts
CVE-2025-64657 - Azure Application Gateway Elevation of Privilege Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-64657
##updated 2025-11-26T03:30:22
2 posts
Go hack more radio shit.
https://www.abdulmhsblog.com/posts/webfmvulns/
CVE-2025-66263 - Unauthenticated Arbitrary File Read via Null Byte Injection https://cvefeed.io/vuln/detail/CVE-2025-66263
##updated 2025-11-26T03:30:22
2 posts
Go hack more radio shit.
https://www.abdulmhsblog.com/posts/webfmvulns/
CVE-2025-66262 - Arbitrary File Overwrite via Tar Extraction Path Traversal https://cvefeed.io/vuln/detail/CVE-2025-66262
##updated 2025-11-26T03:30:22
1 posts
Go hack more radio shit.
https://www.abdulmhsblog.com/posts/webfmvulns/
updated 2025-11-26T03:30:22
1 posts
Go hack more radio shit.
https://www.abdulmhsblog.com/posts/webfmvulns/
updated 2025-11-26T03:30:21
1 posts
CVE-2025-64656 - Azure Application Gateway Elevation of Privilege Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-64656
##updated 2025-11-26T01:16:10.023000
1 posts
CVE-2025-66264 - Unquoted Service path in UPSilon2000V6.0 SYSTEM privilege service https://cvefeed.io/vuln/detail/CVE-2025-66264
##updated 2025-11-26T01:16:08.710000
1 posts
Go hack more radio shit.
https://www.abdulmhsblog.com/posts/webfmvulns/
updated 2025-11-26T01:16:08.570000
1 posts
Go hack more radio shit.
https://www.abdulmhsblog.com/posts/webfmvulns/
updated 2025-11-26T00:30:31
1 posts
1 repos
CVE-2025-13597 - AI Feeds <= 1.0.11 - Unauthenticated Arbitrary File Upload https://cvefeed.io/vuln/detail/CVE-2025-13597
##updated 2025-11-26T00:30:31
1 posts
1 repos
CVE-2025-13595 - CIBELES AI <= 1.10.8 - Unauthenticated Arbitrary File Upload https://cvefeed.io/vuln/detail/CVE-2025-13595
##updated 2025-11-25T23:15:48.097000
1 posts
CVE-2025-65952 - Console is vulnerable to path traversal regarding custom assets https://cvefeed.io/vuln/detail/CVE-2025-65952
##updated 2025-11-25T22:16:42.557000
1 posts
1 repos
⚪ Grafana fixes critical vulnerability allowing admin impersonation
🗨️ Grafana Labs developers have warned about a critical vulnerability, CVE-2025-41115 (10 out of 10 on the CVSS scale), in Grafana Enterprise. The flaw makes it possible to masquerade a new user as an administrator or another internal account.
##updated 2025-11-25T22:16:16.690000
2 posts
⚪ Asus Warns of New Critical Vulnerability in Routers with AiCloud
🗨️ Asus has released firmware updates to fix nine vulnerabilities (CVE-2025-59365, CVE-2025-59366, CVE-2025-59368, CVE-2025-59369, CVE-2025-59370, CVE-2025-59371, CVE-2025-59372, and CVE-2025-12003), including a critical authentication bypass issue in routers with the AiCloud feature enabled.
##⚪ Asus Warns of New Critical Vulnerability in Routers with AiCloud
🗨️ Asus has released firmware updates to fix nine vulnerabilities (CVE-2025-59365, CVE-2025-59366, CVE-2025-59368, CVE-2025-59369, CVE-2025-59370, CVE-2025-59371, CVE-2025-59372, and CVE-2025-12003), including a critical authentication bypass issue in routers with the AiCloud feature enabled.
##updated 2025-11-25T22:16:16.690000
2 posts
⚪ Asus Warns of New Critical Vulnerability in Routers with AiCloud
🗨️ Asus has released firmware updates to fix nine vulnerabilities (CVE-2025-59365, CVE-2025-59366, CVE-2025-59368, CVE-2025-59369, CVE-2025-59370, CVE-2025-59371, CVE-2025-59372, and CVE-2025-12003), including a critical authentication bypass issue in routers with the AiCloud feature enabled.
##⚪ Asus Warns of New Critical Vulnerability in Routers with AiCloud
🗨️ Asus has released firmware updates to fix nine vulnerabilities (CVE-2025-59365, CVE-2025-59366, CVE-2025-59368, CVE-2025-59369, CVE-2025-59370, CVE-2025-59371, CVE-2025-59372, and CVE-2025-12003), including a critical authentication bypass issue in routers with the AiCloud feature enabled.
##updated 2025-11-25T22:16:16.690000
2 posts
⚪ Asus Warns of New Critical Vulnerability in Routers with AiCloud
🗨️ Asus has released firmware updates to fix nine vulnerabilities (CVE-2025-59365, CVE-2025-59366, CVE-2025-59368, CVE-2025-59369, CVE-2025-59370, CVE-2025-59371, CVE-2025-59372, and CVE-2025-12003), including a critical authentication bypass issue in routers with the AiCloud feature enabled.
##⚪ Asus Warns of New Critical Vulnerability in Routers with AiCloud
🗨️ Asus has released firmware updates to fix nine vulnerabilities (CVE-2025-59365, CVE-2025-59366, CVE-2025-59368, CVE-2025-59369, CVE-2025-59370, CVE-2025-59371, CVE-2025-59372, and CVE-2025-12003), including a critical authentication bypass issue in routers with the AiCloud feature enabled.
##updated 2025-11-25T22:16:16.690000
2 posts
⚪ Asus Warns of New Critical Vulnerability in Routers with AiCloud
🗨️ Asus has released firmware updates to fix nine vulnerabilities (CVE-2025-59365, CVE-2025-59366, CVE-2025-59368, CVE-2025-59369, CVE-2025-59370, CVE-2025-59371, CVE-2025-59372, and CVE-2025-12003), including a critical authentication bypass issue in routers with the AiCloud feature enabled.
##⚪ Asus Warns of New Critical Vulnerability in Routers with AiCloud
🗨️ Asus has released firmware updates to fix nine vulnerabilities (CVE-2025-59365, CVE-2025-59366, CVE-2025-59368, CVE-2025-59369, CVE-2025-59370, CVE-2025-59371, CVE-2025-59372, and CVE-2025-12003), including a critical authentication bypass issue in routers with the AiCloud feature enabled.
##updated 2025-11-25T22:16:16.690000
2 posts
⚪ Asus Warns of New Critical Vulnerability in Routers with AiCloud
🗨️ Asus has released firmware updates to fix nine vulnerabilities (CVE-2025-59365, CVE-2025-59366, CVE-2025-59368, CVE-2025-59369, CVE-2025-59370, CVE-2025-59371, CVE-2025-59372, and CVE-2025-12003), including a critical authentication bypass issue in routers with the AiCloud feature enabled.
##⚪ Asus Warns of New Critical Vulnerability in Routers with AiCloud
🗨️ Asus has released firmware updates to fix nine vulnerabilities (CVE-2025-59365, CVE-2025-59366, CVE-2025-59368, CVE-2025-59369, CVE-2025-59370, CVE-2025-59371, CVE-2025-59372, and CVE-2025-12003), including a critical authentication bypass issue in routers with the AiCloud feature enabled.
##updated 2025-11-25T22:16:16.690000
4 posts
⚪ Asus Warns of New Critical Vulnerability in Routers with AiCloud
🗨️ Asus has released firmware updates to fix nine vulnerabilities (CVE-2025-59365, CVE-2025-59366, CVE-2025-59368, CVE-2025-59369, CVE-2025-59370, CVE-2025-59371, CVE-2025-59372, and CVE-2025-12003), including a critical authentication bypass issue in routers with the AiCloud feature enabled.
##⚪ Asus Warns of New Critical Vulnerability in Routers with AiCloud
🗨️ Asus has released firmware updates to fix nine vulnerabilities (CVE-2025-59365, CVE-2025-59366, CVE-2025-59368, CVE-2025-59369, CVE-2025-59370, CVE-2025-59371, CVE-2025-59372, and CVE-2025-12003), including a critical authentication bypass issue in routers with the AiCloud feature enabled.
##ASUS reports vulnerabilities in MyASUS application and router firmware
ASUS released security patches addressing multiple vulnerabilities in their MyASUS application and router firmware, including a critical remote code execution flaw (CVE-2025-59366) in routers and a local privilege escalation issue (CVE-2025-59373) in the System Control Interface Service.
**For ASUS routers, update firmware and for end-of-life models that can't be updated, disable all internet-accessible services (AiCloud, remote WAN access, port forwarding, DDNS, VPN server, DMZ, FTP) and use strong unique passwords. For MyASUS software, update to the latest patched version (3.1.48.0 for x64 or 4.2.48.0 for ARM) through Windows Update or download directly from the ASUS support site.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/asus-reports-vulnerabilities-in-myasus-application-and-router-firmware-1-o-x-5-9/gD2P6Ple2L
The CVE-2025-59366 vulnerability "can be triggered by an unintended side effect of the Samba functionality, potentially leading to allow execution of specific functions without proper authorization." https://www.bleepingcomputer.com/news/security/asus-warns-of-new-critical-auth-bypass-flaw-in-aicloud-routers/
##updated 2025-11-25T22:16:16.690000
2 posts
⚪ Asus Warns of New Critical Vulnerability in Routers with AiCloud
🗨️ Asus has released firmware updates to fix nine vulnerabilities (CVE-2025-59365, CVE-2025-59366, CVE-2025-59368, CVE-2025-59369, CVE-2025-59370, CVE-2025-59371, CVE-2025-59372, and CVE-2025-12003), including a critical authentication bypass issue in routers with the AiCloud feature enabled.
##⚪ Asus Warns of New Critical Vulnerability in Routers with AiCloud
🗨️ Asus has released firmware updates to fix nine vulnerabilities (CVE-2025-59365, CVE-2025-59366, CVE-2025-59368, CVE-2025-59369, CVE-2025-59370, CVE-2025-59371, CVE-2025-59372, and CVE-2025-12003), including a critical authentication bypass issue in routers with the AiCloud feature enabled.
##updated 2025-11-25T22:16:16.690000
2 posts
⚪ Asus Warns of New Critical Vulnerability in Routers with AiCloud
🗨️ Asus has released firmware updates to fix nine vulnerabilities (CVE-2025-59365, CVE-2025-59366, CVE-2025-59368, CVE-2025-59369, CVE-2025-59370, CVE-2025-59371, CVE-2025-59372, and CVE-2025-12003), including a critical authentication bypass issue in routers with the AiCloud feature enabled.
##⚪ Asus Warns of New Critical Vulnerability in Routers with AiCloud
🗨️ Asus has released firmware updates to fix nine vulnerabilities (CVE-2025-59365, CVE-2025-59366, CVE-2025-59368, CVE-2025-59369, CVE-2025-59370, CVE-2025-59371, CVE-2025-59372, and CVE-2025-12003), including a critical authentication bypass issue in routers with the AiCloud feature enabled.
##updated 2025-11-25T22:16:16.690000
3 posts
2 repos
CVE-2025-58360: GeoServer XXE Vulnerability Analysis https://helixguard.ai/blog/CVE-2025-58360
##CVE-2025-58360: GeoServer XXE Vulnerability Analysis https://helixguard.ai/blog/CVE-2025-58360
##CVE-2025-58360 - GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature https://cvefeed.io/vuln/detail/CVE-2025-58360
##updated 2025-11-25T22:16:16.690000
1 posts
Nvidia posted three advisories yesterday, if you missed them:
- CVE-2025-33203: NVIDIA NeMo Agent Toolkit https://nvidia.custhelp.com/app/answers/detail/a_id/5726
- CVE-2025-33204 and CVE-2025-33205: NVIDIA NeMo Framework https://nvidia.custhelp.com/app/answers/detail/a_id/5729
- Several vulnerabilities affected here: NVIDIA DGX Spark https://nvidia.custhelp.com/app/answers/detail/a_id/5720 #Nvidia #infosec #vulnerability
##updated 2025-11-25T22:16:16.690000
1 posts
CVE-2025-12816 - CVE-2025-12816 https://cvefeed.io/vuln/detail/CVE-2025-12816
##updated 2025-11-25T21:32:13
1 posts
CVE-2025-64064 - Primakon Pi Portal Privilege Escalation Vulnerability https://cvefeed.io/vuln/detail/CVE-2025-64064
##updated 2025-11-25T18:32:29
3 posts
NVIDIA has released a critical DGX Spark firmware update addressing 14 vulnerabilities - including CVE-2025-33187 (CVSS 9.3), which enables malicious code execution and access to protected SoC regions.
Firmware flaws in AI workstations can impact model integrity, training data, and system stability.
Organizations using DGX Spark should patch immediately.
Source: https://cybersecuritynews.com/nvidia-dgx-spark-vulnerabilities/#google_vignette
What’s your view on firmware security in AI-focused hardware?
Follow us for more analysis.
#infosec #NVIDIA #DGXSpark #CVE #AIsecurity #firmwaresecurity #patchnow #securityupdate
##NVIDIA has released a critical DGX Spark firmware update addressing 14 vulnerabilities - including CVE-2025-33187 (CVSS 9.3), which enables malicious code execution and access to protected SoC regions.
Firmware flaws in AI workstations can impact model integrity, training data, and system stability.
Organizations using DGX Spark should patch immediately.
Source: https://cybersecuritynews.com/nvidia-dgx-spark-vulnerabilities/#google_vignette
What’s your view on firmware security in AI-focused hardware?
Follow us for more analysis.
#infosec #NVIDIA #DGXSpark #CVE #AIsecurity #firmwaresecurity #patchnow #securityupdate
##NVIDIA releases security update for DGX Spark AI computing platform, patches at least one critical flaw
NVIDIA released a security update (OTA0) for its DGX Spark GB10 AI platform to patch 14 vulnerabilities in SROOT firmware, including a critical flaw (CVE-2025-33187) that could allow privileged attackers to access protected SoC areas and execute code. The vulnerabilities enable code execution, privilege escalation, information disclosure, and denial of service attacks on systems running DGX OS versions prior to OTA0.
**If you have NVIDIA DGX Spark GB10 devices, ensure they are isolated from the internet and accessible only from trusted networks. Then immediately download and install the OTA0 update from the NVIDIA DGX site.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/nvidia-releases-security-update-for-dgx-spark-ai-computing-platform-patches-at-least-one-critical-flaw-f-d-y-e-1/gD2P6Ple2L
updated 2025-11-25T18:32:29
1 posts
Nvidia posted three advisories yesterday, if you missed them:
- CVE-2025-33203: NVIDIA NeMo Agent Toolkit https://nvidia.custhelp.com/app/answers/detail/a_id/5726
- CVE-2025-33204 and CVE-2025-33205: NVIDIA NeMo Framework https://nvidia.custhelp.com/app/answers/detail/a_id/5729
- Several vulnerabilities affected here: NVIDIA DGX Spark https://nvidia.custhelp.com/app/answers/detail/a_id/5720 #Nvidia #infosec #vulnerability
##updated 2025-11-25T18:32:29
1 posts
Nvidia posted three advisories yesterday, if you missed them:
- CVE-2025-33203: NVIDIA NeMo Agent Toolkit https://nvidia.custhelp.com/app/answers/detail/a_id/5726
- CVE-2025-33204 and CVE-2025-33205: NVIDIA NeMo Framework https://nvidia.custhelp.com/app/answers/detail/a_id/5729
- Several vulnerabilities affected here: NVIDIA DGX Spark https://nvidia.custhelp.com/app/answers/detail/a_id/5720 #Nvidia #infosec #vulnerability
##updated 2025-11-25T03:30:20
2 posts
ASUS reports vulnerabilities in MyASUS application and router firmware
ASUS released security patches addressing multiple vulnerabilities in their MyASUS application and router firmware, including a critical remote code execution flaw (CVE-2025-59366) in routers and a local privilege escalation issue (CVE-2025-59373) in the System Control Interface Service.
**For ASUS routers, update firmware and for end-of-life models that can't be updated, disable all internet-accessible services (AiCloud, remote WAN access, port forwarding, DDNS, VPN server, DMZ, FTP) and use strong unique passwords. For MyASUS software, update to the latest patched version (3.1.48.0 for x64 or 4.2.48.0 for ARM) through Windows Update or download directly from the ASUS support site.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/asus-reports-vulnerabilities-in-myasus-application-and-router-firmware-1-o-x-5-9/gD2P6Ple2L
ASUS has patched a high-severity local privilege escalation flaw (CVE-2025-59373) in MyASUS that allowed elevation to NT AUTHORITY/SYSTEM via the System Control Interface Service. Patch now shipped through Windows Update with updated versions for x64 and ARM.
#infosec #vulnerability #ASUS #WindowsSecurity #patchmanagement #CVE2025
##updated 2025-11-24T21:30:58
1 posts
To be a little more specific about the problem I'm interested in solving, this is a potential building block for an image processing pipeline for ActivityPub software. Mastodon uses ImageMagick, which is an old and well tested image manipulation tool, but it's only as sandboxed as the Mastodon server itself. Any vulnerability in ImageMagick leaves an attacker in a position to do anything the Mastodon server can do. That's an uncomfortable place to be because image library compromise isn't an outlandish possibility. It has happened a lot (check out this recent libtiff CVE: https://nvd.nist.gov/vuln/detail/CVE-2025-9900). And I don't mean to say their developers are bad at what they do. Images are complex and this is a really hard problem!
##updated 2025-11-22T03:31:17
1 posts
updated 2025-11-21T21:30:16
1 posts
2 repos
https://github.com/Jinxia62/Oracle-Identity-Manager-CVE-2025-61757
updated 2025-11-20T00:31:21
3 posts
6 repos
https://github.com/mbanyamer/CVE-2025-11001---7-Zip
https://github.com/shalevo13/Se7enSlip
https://github.com/pacbypass/CVE-2025-11001
https://github.com/ranasen-rat/CVE-2025-11001
Exploit PoC para una vulnerabilidad en 7-Zip (CVE-2025-11001)
https://blog.elhacker.net/2025/11/exploit-poc-para-una-vulnerabilidad-7-zip.html
🧩 3️⃣ Vulnerabilidad crítica en 7-Zip: hackers la están explotando ahora.
Una falla grave en el popular programa de compresión 7-Zip (CVE-2025-11001) permite a atacantes ejecutar código de forma remota cuando un usuario descomprime un archivo ZIP malicioso.
El problema radica en cómo 7-Zip maneja enlaces simbólicos (symlinks): un ZIP confeccionado puede hacer que el programa acceda a carpetas no deseadas y ejecute código con permisos elevados.
La vulnerabilidad afecta a todas las versiones anteriores a la 25.00 (es decir, versiones usadas desde 21.02 hasta 24.09).
Ya existe un exploit de prueba de concepto (PoC) público, lo que facilita que delincuentes lo usen en ataques reales.
Aunque 7-Zip lanzó el parche en julio de 2025, muchos sistemas siguen sin actualizarlo: la recomendación urgente es que actualices a la versión 25.00 o superior lo antes posible.
🔒 ¿Herramienta de compresión útil o puerta de entrada para malware?
#Privacidad #Ciberseguridad #7Zip #Vulnerabilidad #Actualiza
https://thehackernews.com/2025/11/hackers-actively-exploiting-7-zip.html
##Exploit PoC para una vulnerabilidad en 7-Zip (CVE-2025-11001) https://blog.elhacker.net/2025/11/exploit-poc-para-una-vulnerabilidad-7-zip.html #vulnerabilidad #7-zip #cve #poc
##updated 2025-11-19T15:32:29
1 posts
2 repos
Accessibilité et design
#accessibilité #design #LLM #NotesHebdo #opensource #security
##updated 2025-11-18T12:31:19
1 posts
6 repos
https://github.com/zhuowei/blueshrimp
https://github.com/Ashwesker/Blackash-CVE-2025-48593
https://github.com/skolepc/CVE-2025-48593
https://github.com/ranasen-rat/CVE-2025-48593
updated 2025-11-12T11:34:13.390000
1 posts
2 repos
updated 2025-11-11T15:32:22
1 posts
22 repos
https://github.com/mrk336/Breaking-the-Update-Chain-Inside-CVE-2025-59287-and-the-WSUS-RCE-Threat
https://github.com/keeganparr1/CVE-2025-59287-hawktrace
https://github.com/jiansiting/CVE-2025-59287
https://github.com/RadzaRr/WSUSResponder
https://github.com/Twodimensionalitylevelcrossing817/CVE-2025-59287
https://github.com/QurtiDev/WSUS-CVE-2025-59287-RCE
https://github.com/dexterm300/cve-2025-59287-exploit-poc
https://github.com/FurkanKAYAPINAR/CVE-2025-59287
https://github.com/garvitv14/CVE-2025-59287
https://github.com/fsanzmoya/wsus_CVE-2025-59287
https://github.com/N3k0t-dev/PoC-CVE-collection
https://github.com/M507/CVE-2025-59287-PoC
https://github.com/Adel-kaka-dz/cve-2025-59287
https://github.com/esteban11121/WSUS-RCE-Mitigation-59287
https://github.com/AdityaBhatt3010/CVE-2025-59287-When-your-patch-server-becomes-the-attack-vector
https://github.com/0x7556/CVE-2025-59287
https://github.com/0xBruno/WSUSploit.NET
https://github.com/Lupovis/Honeypot-for-CVE-2025-59287-WSUS
https://github.com/mubix/Find-WSUS
updated 2025-11-04T00:31:33
1 posts
2 repos
https://github.com/PraiseImafidon/Version_Vulnerability_Scanner
updated 2025-10-22T19:24:09
1 posts
19 repos
https://github.com/imabee101/CVE-2023-44487
https://github.com/pabloec20/rapidreset
https://github.com/bcdannyboy/CVE-2023-44487
https://github.com/nxenon/cve-2023-44487
https://github.com/BMG-Black-Magic/CVE-2023-44487
https://github.com/ByteHackr/CVE-2023-44487
https://github.com/studiogangster/CVE-2023-44487
https://github.com/madhusudhan-in/CVE_2023_44487-Rapid_Reset
https://github.com/zanks08/cve-2023-44487-demo
https://github.com/ReToCode/golang-CVE-2023-44487
https://github.com/moften/CVE-2023-44487-HTTP-2-Rapid-Reset-Attack
https://github.com/gmh5225/CVE_2023_44487-Rapid_Reset
https://github.com/sigridou/CVE-2023-44487-
https://github.com/secengjeff/rapidresetclient
https://github.com/TYuan0816/cve-2023-44487
https://github.com/ndrscodes/http2-rst-stream-attacker
https://github.com/sn130hk/CVE-2023-44487
https://github.com/threatlabindonesia/CVE-2023-44487-HTTP-2-Rapid-Reset-Exploit-PoC
updated 2025-10-22T00:33:51
1 posts
7 repos
https://github.com/AhmedMansour93/Event-ID-189-Rule-Name-SOC227-CVE-2023-29357
https://github.com/LuemmelSec/CVE-2023-29357
https://github.com/Guillaume-Risch/cve-2023-29357-Sharepoint
https://github.com/KeyStrOke95/CVE-2023-29357-ExE
Cảnh báo lỗ hổng zero-day nghiêm trọng (CVSS 9.8) trong Microsoft SharePoint Server, mã CVE-2023-29357.
Lỗ hổng này cho phép kẻ tấn công giả mạo người dùng và chiếm quyền quản trị mà không cần xác thực. Hiện tại, nó đang bị khai thác tích cực.
Quản trị viên sử dụng SharePoint Server 2016, 2019, và Subscription Edition cần cập nhật bản vá ngay lập tức để bảo vệ hệ thống.
#bảomật #antoànthôngtin #lỗhổng #Microsoft #SharePoint
#security #cybersecurity #vulnerability #zeroday #CVE202329357
https
##updated 2025-09-23T19:13:36
1 posts
updated 2025-05-08T18:31:34
1 posts
Not the most confidence-inspiring CVE description.
https://www.cve.org/CVERecord?id=CVE-2025-2486
##The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Secure Boot constraints. Versions 2024.05-2ubuntu0.3 and 2024.02-2ubuntu0.3 disable the Shell. Some previous versions inserted a secure-boot-based decision to continue running inside the Shell itself, which is believed to be sufficient to enforce Secure Boot restrictions. This is an additional repair on top of the incomplete fix for CVE-2023-48733.
updated 2023-01-29T05:02:39
1 posts
This is, um, *alot* of coordinated, calculated, automation to see where "elFinder" is.
New CVE/0-Day coming?
Starting the 6-week countdown.
https://viz.greynoise.io/tags/elfinder-2-1-58-rce-cve-2021-32682-check?days=90
##updated 2023-01-27T05:04:35
1 posts
Multiple culnerabilities reported in Festo Industrial Control Systems
CISA has issued warnings about two critical vulnerabilities (CVE-2022-31806 and CVE-2022-22515) affecting multiple Festo industrial control systems that ship with password protection disabled by default and allow unauthorized access and configuration file modification.
**This is urgent and important, and the fix is trivial. Ensure all Festo industrial control devices are isolated from the internet and accessible only from trusted networks. Immediately enable password protection on all controllers (disabled by default) and manually configure backups to include password settings.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/multiple-culnerabilities-reported-in-festo-industrial-control-systems-3-q-3-k-n/gD2P6Ple2L
updated 2023-01-27T05:01:23
1 posts
Multiple culnerabilities reported in Festo Industrial Control Systems
CISA has issued warnings about two critical vulnerabilities (CVE-2022-31806 and CVE-2022-22515) affecting multiple Festo industrial control systems that ship with password protection disabled by default and allow unauthorized access and configuration file modification.
**This is urgent and important, and the fix is trivial. Ensure all Festo industrial control devices are isolated from the internet and accessible only from trusted networks. Immediately enable password protection on all controllers (disabled by default) and manually configure backups to include password settings.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/multiple-culnerabilities-reported-in-festo-industrial-control-systems-3-q-3-k-n/gD2P6Ple2L
CVE-2025-64344 - Suricata is vulnerable to a stack overflow from unbounded stack allocation in LuaPushStringBuffer https://cvefeed.io/vuln/detail/CVE-2025-64344
##CVE-2025-64332 - Suricata is vulnerable to a stack overflow on larger compressed data https://cvefeed.io/vuln/detail/CVE-2025-64332
##CVE-2025-64331 - Suricata is vulnerable to a stack overflow on large file transfers with http-body-printable https://cvefeed.io/vuln/detail/CVE-2025-64331
##CVE-2025-64334 - Suricata is vulnerable to unbounded memory growth for decompression https://cvefeed.io/vuln/detail/CVE-2025-64334
##CVE-2025-64333 - Suricata is vulnerable to a stack overflow from big content-type https://cvefeed.io/vuln/detail/CVE-2025-64333
##CVE-2025-13084 - Opto 22 groov View Exposure of Sensitive Information Through Metadata https://cvefeed.io/vuln/detail/CVE-2025-13084
##CVE-2025-66022 - FACTION Unauthenticated Custom Extension Upload leads to RCE https://cvefeed.io/vuln/detail/CVE-2025-66022
##CVE-2025-66022 - FACTION Unauthenticated Custom Extension Upload leads to RCE https://cvefeed.io/vuln/detail/CVE-2025-66022
##CVE-2025-9558 - Bluetooth: Mesh: Out-of-Bound Write in gen_prov_start https://cvefeed.io/vuln/detail/CVE-2025-9558
##CVE-2025-66025 - Caido Improperly Handles External Links in Markdown https://cvefeed.io/vuln/detail/CVE-2025-66025
##CVE-2025-65957 - Core Bot is Leaking Sensitive Credentials in Logs, Errors, and Messages https://cvefeed.io/vuln/detail/CVE-2025-65957
##