Posts

Showing posts from July, 2025

CVE-2025-51384 - D-Link DI-8200 IPsec Buffer Overflow

CVE ID : CVE-2025-51384 Published : July 31, 2025, 6:15 p.m. | 49 minutes ago Description : D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_net_asp function via the remot_ip parameter. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/frwK5W2 via IFTTT

CVE-2024-34327 - Sielox AnyWare SQL Injection

CVE ID : CVE-2024-34327 Published : July 31, 2025, 5:15 p.m. | 1 hour, 49 minutes ago Description : Sielox AnyWare v2.1.2 was discovered to contain a SQL injection vulnerability via the email address field of the password reset form. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/mr13Xbl via IFTTT

CVE-2025-25691 - PrestaShop PHAR Deserialization Code Execution Vulnerability

CVE ID : CVE-2025-25691 Published : July 30, 2025, 5:15 p.m. | 1 hour, 46 minutes ago Description : A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request. Severity: 0.0 | NA

CVE-2024-45955 - Rocket Software Rocket Zena SQL Injection Vulnerability

CVE ID : CVE-2024-45955 Published : July 30, 2025, 5:15 p.m. | 1 hour, 46 minutes ago Description : Rocket Software Rocket Zena 4.4.1.26 is vulnerable to SQL Injection via the filter parameter. Severity: 0.0 | NA

CVE-2025-44136 - MapTiler Tileserver-php XSS

CVE ID : CVE-2025-44136 Published : July 29, 2025, 5:15 p.m. | 1 hour, 49 minutes ago Description : MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html encoding. This leads to XSS and allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victim's browser. Severity: 9.8 | CRITICAL

CVE-2025-31965 - HCL BigFix Remote Control Server WebUI Information Disclosure Vulnerability

CVE ID : CVE-2025-31965 Published : July 29, 2025, 5:15 p.m. | 1 hour, 49 minutes ago Description : Improper access restrictions in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0248 and lower) allow non-admin users to view unauthorized information on certain web pages. Severity: 8.2 | HIGH

CVE-2025-50493 - PHPGurukul Doctor Appointment Management System Session Hijacking Vulnerability

CVE ID : CVE-2025-50493 Published : July 28, 2025, 5:15 p.m. | 1 hour, 46 minutes ago Description : Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Doctor Appointment Management System v1 allows attackers to execute a session hijacking attack. Severity: 7.5 | HIGH

CVE-2025-50490 - PHPGurukul Student Result Management System Session Hijacking Vulnerability

CVE ID : CVE-2025-50490 Published : July 28, 2025, 5:15 p.m. | 1 hour, 46 minutes ago Description : Improper session invalidation in the component /elms/emp-changepassword.php of PHPGurukul Student Result Management System v2.0 allows attackers to execute a session hijacking attack. Severity: 7.5 | HIGH

CVE-2025-8246 - A vulnerability was found in TOTOLINK X15 1.0.0-B2

CVE ID : CVE-2025-8246 Published : July 27, 2025, 11:15 p.m. | 9 hours, 46 minutes ago Description : A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been rated as critical. Affected by this issue is some unknown functionality of the file /boafrm/formRoute of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Severity: 8.8 | HIGH

CVE-2025-46686 - Redis Memory Allocation Vulnerability

CVE ID : CVE-2025-46686 Published : July 23, 2025, 7:15 p.m. | 1 hour, 44 minutes ago Description : Redis through 7.4.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated user. This occurs because the server allocates memory for the command arguments of every bulk, even when the command is skipped because of insufficient permissions. Severity: 4.9 | MEDIUM

CVE-2025-4439 - GitLab Cross-Site Scripting (XSS)

CVE ID : CVE-2025-4439 Published : July 23, 2025, 6:15 p.m. | 44 minutes ago Description : An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an authenticated user to perform cross-site scripting attacks when the instance is served through certain content delivery networks. Severity: 7.7 | HIGH

CVE-2025-51482 - Letta AI Remote Code Execution

CVE ID : CVE-2025-51482 Published : July 22, 2025, 5:15 p.m. | 1 hour, 41 minutes ago Description : Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows remote attackers to execute arbitrary Python code and system commands via crafted payloads to the /v1/tools/run endpoint, bypassing intended sandbox restrictions. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/Ebotwd1 via IFTTT

CVE-2025-51481 - Dagster Grpc Local File Inclusion Vulnerability

CVE ID : CVE-2025-51481 Published : July 22, 2025, 5:15 p.m. | 1 hour, 41 minutes ago Description : Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary files by supplying path traversal sequences in the notebook_path field of ExternalNotebookData requests, bypassing the intended extension-based check. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/G5gxFKz via IFTTT

CVE-2025-7319 - IrfanView CADImage Plugin DWG File Parsing Out-Of-

CVE ID : CVE-2025-7319 Published : July 21, 2025, 8:15 p.m. | 4 hours, 41 minutes ago Description : IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26413. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/caLpovU via IFTTT

CVE-2025-7318 - IrfanView CADImage Plugin DWG File Parsing Memory

CVE ID : CVE-2025-7318 Published : July 21, 2025, 8:15 p.m. | 4 hours, 41 minutes ago Description : IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26412. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/tlL3F1W via IFTTT

CVE-2025-47917 - Mbed TLS Use-After-Free Vulnerability

CVE ID : CVE-2025-47917 Published : July 20, 2025, 7:15 p.m. | 1 hour, 40 minutes ago Description : Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance with the documentation. The function mbedtls_x509_string_to_names() takes a head argument that is documented as an output argument. The documentation does not suggest that the function will free that pointer; however, the function does call mbedtls_asn1_free_named_data_list() on that argument, which performs a deep free(). As a result, application code that uses this function (relying only on documented behavior) is likely to still hold pointers to the memory blocks that were freed, resulting in a high risk of use-after-free or double-free. In particular, the two sample programs x509/cert_write and x509/cert_req are affected (use-after-free if the san string contains more than one DN). Severity: 8.9 | HIGH Visit the link for more details, such as CVSS deta...

CVE-2025-7903 - Yangzongzhuan RuoYi Image Source Handler UI Layer Restriction Vulnerability

CVE ID : CVE-2025-7903 Published : July 20, 2025, 5:15 p.m. | 1 hour, 40 minutes ago Description : A vulnerability classified as problematic was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is an unknown functionality of the component Image Source Handler. The manipulation leads to improper restriction of rendered ui layers. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/FH3WgAp via IFTTT

CVE-2025-7831 - "Church Donation System SQL Injection Vulnerability"

CVE ID : CVE-2025-7831 Published : July 19, 2025, 3:15 p.m. | 1 hour, 40 minutes ago Description : A vulnerability classified as critical has been found in code-projects Church Donation System 1.0. This affects an unknown part of the file /members/Tithes.php. The manipulation of the argument trcode leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/txXVynp via IFTTT

CVE-2025-7830 - "Church Donation System SQL Injection Vulnerability"

CVE ID : CVE-2025-7830 Published : July 19, 2025, 3:15 p.m. | 1 hour, 40 minutes ago Description : A vulnerability was found in code-projects Church Donation System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /reg.php. The manipulation of the argument mobile leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/wXlKMBd via IFTTT

CVE-2025-45156 - Splashin iOS Location Spoofing Vulnerability

CVE ID : CVE-2025-45156 Published : July 18, 2025, 5:15 p.m. | 1 hour, 39 minutes ago Description : Splashin iOS v2.0 fails to enforce server-side interval restrictions for location updates for free-tier users. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/GOz945R via IFTTT

CVE-2025-23263 - NVIDIA DOCA-Host and Mellanox OFED VGT+ Privilege Escalation and Denial of Service Vulnerability

CVE ID : CVE-2025-23263 Published : July 17, 2025, 6:15 p.m. | 36 minutes ago Description : NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause escalation of privileges and denial of service on the VLAN. Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/FZOYVyK via IFTTT

CVE-2024-32323 - Cnhcit Haichang OA SQL Injection

CVE ID : CVE-2024-32323 Published : July 17, 2025, 5:15 p.m. | 1 hour, 35 minutes ago Description : SQL Injection vulnerability in cnhcit.com Haichang OA v.1.0.0 allows a remote attacker to obtain sensitive information via the if parameter in hcit.project.rte.agents.UploadImages.class. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/Md0LVJh via IFTTT

CVE-2025-20274 - "Cisco Unified Intelligence Center File Upload Privilege Escalation Vulnerability"

CVE ID : CVE-2025-20274 Published : July 16, 2025, 5:15 p.m. | 1 hour, 32 minutes ago Description : A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to improper validation of files that are uploaded to the web-based management interface. An attacker could exploit this vulnerability by uploading arbitrary files to an affected device. A successful exploit could allow the attacker to store malicious files on the system and execute arbitrary commands on the operating system. The Security Impact Rating (SIR) of this advisory has been raised to High because an attacker could elevate privileges to root. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Report Designer. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affe...

CVE-2025-20272 - Cisco Prime Infrastructure and EPNM Blind SQL Injection

CVE ID : CVE-2025-20272 Published : July 16, 2025, 5:15 p.m. | 1 hour, 32 minutes ago Description : A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-privileged, remote attacker to conduct a blind SQL injection attack. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected API. A successful exploit could allow the attacker to view data in some database tables on an affected device. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/WTFlXvN via IFTTT

CVE-2025-26186 - openSIS SQL Injection Vulnerability

CVE ID : CVE-2025-26186 Published : July 15, 2025, 5:15 p.m. | 1 hour, 30 minutes ago Description : SQL Injection vulnerability in openSIS v.9.1 allows a remote attacker to execute arbitrary code via the id parameter in Ajax.php Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/P9QhoRp via IFTTT

CVE-2024-42648 - NanoMQ MQTT Heap Overflow Denial of Service

CVE ID : CVE-2024-42648 Published : July 14, 2025, 5:15 p.m. | 1 hour, 27 minutes ago Description : NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via a crafted CONNECT message. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/41SBCky via IFTTT

CVE-2024-42646 - NanoMQ Denial of Service (DoS) Vulnerability

CVE ID : CVE-2024-42646 Published : July 14, 2025, 5:15 p.m. | 1 hour, 27 minutes ago Description : A segmentation fault in NanoMQ v0.21.10 allows attackers to cause a Denial of Service (DoS) via crafted messages. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/RaM8oLB via IFTTT

CVE-2025-7532 - Tenda FH1202 Critical Stack-Based Buffer Overflow

CVE ID : CVE-2025-7532 Published : July 13, 2025, 4:15 p.m. | 2 hours, 14 minutes ago Description : A vulnerability has been found in Tenda FH1202 1.2.0.14(408) and classified as critical. This vulnerability affects the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter. The manipulation of the argument page leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/1bnG07k via IFTTT

CVE-2025-7531 - Tenda FH1202 PPTP Remote Stack Buffer Overflow Vulnerability

CVE ID : CVE-2025-7531 Published : July 13, 2025, 4:15 p.m. | 2 hours, 14 minutes ago Description : A vulnerability, which was classified as critical, was found in Tenda FH1202 1.2.0.14(408). This affects the function fromPptpUserSetting of the file /goform/PPTPUserSetting. The manipulation of the argument delno leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/uSz4H5V via IFTTT

CVE-2025-7480 - PHPGurukul Vehicle Parking Management System SQL Injection

CVE ID : CVE-2025-7480 Published : July 12, 2025, 4:15 p.m. | 2 hours, 13 minutes ago Description : A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected by this issue is some unknown functionality of the file /users/signup.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/g4nw9AV via IFTTT

CVE-2025-7479 - PHPGurukul Vehicle Parking Management System SQL Injection

CVE ID : CVE-2025-7479 Published : July 12, 2025, 4:15 p.m. | 2 hours, 13 minutes ago Description : A vulnerability has been found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /users/view--detail.php. The manipulation of the argument viewid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/ecGBxkW via IFTTT

CVE-2025-52980 - Juniper Networks Junos OS BGP Byte Order Denial-of-Service (DoS) Vulnerability

CVE ID : CVE-2025-52980 Published : July 11, 2025, 4:15 p.m. | 2 hours, 12 minutes ago Description : A Use of Incorrect Byte Ordering vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS on SRX300 Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When a BGP update is received over an established BGP session which contains a specific, valid, optional, transitive path attribute, rpd will crash and restart. This issue affects eBGP and iBGP over IPv4 and IPv6. This issue affects: Junos OS: * 22.1 versions from 22.1R1 before 22.2R3-S4, * 22.3 versions before 22.3R3-S3, * 22.4 versions before 22.4R3-S2, * 23.2 versions before 23.2R2, * 23.4 versions before 23.4R2. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/iQqKouZ via IFTTT

CVE-2025-46788 - Zoom Workplace Certificate Validation Information Disclosure Vulnerability

CVE ID : CVE-2025-46788 Published : July 10, 2025, 4:15 p.m. | 2 hours, 12 minutes ago Description : Improper certificate validation in Zoom Workplace for Linux before version 6.4.13 may allow an unauthorized user to conduct an information disclosure via network access. Severity: 7.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/wd4BCLu via IFTTT

CVE-2025-53659 - Jenkins QMetry Test Management Plugin API Key Exposure

CVE ID : CVE-2025-53659 Published : July 9, 2025, 4:15 p.m. | 2 hours, 9 minutes ago Description : Jenkins QMetry Test Management Plugin 1.13 and earlier stores Qmetry Automation API Keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/6FtlsCM via IFTTT

CVE-2025-49723 - Windows StateRepository API Authorization Bypass

CVE ID : CVE-2025-49723 Published : July 8, 2025, 5:16 p.m. | 1 hour, 3 minutes ago Description : Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/FARm57v via IFTTT

CVE-2025-49722 - Windows Print Spooler Unauthenticated Denial of Service

CVE ID : CVE-2025-49722 Published : July 8, 2025, 5:15 p.m. | 1 hour, 3 minutes ago Description : Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over an adjacent network. Severity: 5.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/pjd0z78 via IFTTT

CVE-2025-53374 - Dokploy Information Disclosure Vulnerability

CVE ID : CVE-2025-53374 Published : July 7, 2025, 4:15 p.m. | 2 hours, 1 minute ago Description : Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications and databases. An authenticated low-privileged account can retrieve detailed profile information about another users in the same organization by directly invoking user.one. The response discloses personally-identifiable information (PII) such as e-mail address, role, two-factor status, organization ID, and various account flags. The fix will be available in the v0.23.7. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/rSgw5xG via IFTTT

CVE-2025-7085 - Belkin F9K1122 Remote Stack-Based Buffer Overflow Vulnerability

CVE ID : CVE-2025-7085 Published : July 6, 2025, 5:15 p.m. | 57 minutes ago Description : A vulnerability was found in Belkin F9K1122 1.00.33. It has been rated as critical. This issue affects the function formiNICWpsStart of the file /goform/formiNICWpsStart of the component webs. The manipulation of the argument pinCode leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/WenMIJc via IFTTT

CVE-2025-7084 - "Belkin F9K1122 Web-based Buffer Overflow Vulnerability"

CVE ID : CVE-2025-7084 Published : July 6, 2025, 4:15 p.m. | 1 hour, 57 minutes ago Description : A vulnerability was found in Belkin F9K1122 1.00.33. It has been declared as critical. This vulnerability affects the function formWpsStart of the file /goform/formWpsStart of the component webs. The manipulation of the argument pinCode leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/50ELSZs via IFTTT

CVE-2025-7083 - Belkin Webs mp Command Injection Vulnerability

CVE ID : CVE-2025-7083 Published : July 6, 2025, 4:15 p.m. | 1 hour, 57 minutes ago Description : A vulnerability was found in Belkin F9K1122 1.00.33. It has been classified as critical. This affects the function mp of the file /goform/mp of the component webs. The manipulation of the argument command leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/A6RFBEU via IFTTT

CVE-2025-1297 - CVE-2021-34567: Apache Struts Remote Code Execution Vulnerability

CVE ID : CVE-2025-1297 Published : July 5, 2025, 11:15 p.m. | 57 minutes ago Description : Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/CUIXegm via IFTTT

CVE-2025-1234 - CVE-2021-4034: Apache HTTP Server HTTP Request Smuggling

CVE ID : CVE-2025-1234 Published : July 5, 2025, 11:15 p.m. | 57 minutes ago Description : Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/bj58e0u via IFTTT

CVE-2025-53483 - Mediawiki SecurePoll CSRF

CVE ID : CVE-2025-53483 Published : July 4, 2025, 6:15 p.m. | 1 hour, 8 minutes ago Description : ArchivePage.php, UnarchivePage.php, and VoterEligibilityPage#executeClear() do not validate request methods or CSRF tokens, allowing attackers to trigger sensitive actions if an admin visits a malicious site. This issue affects Mediawiki - SecurePoll extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/vySdw7G via IFTTT

CVE-2025-53481 - WikiMedia Mediawiki IPInfo Extension Uncontrolled Resource Consumption DoS

CVE ID : CVE-2025-53481 Published : July 4, 2025, 4:15 p.m. | 1 hour, 56 minutes ago Description : Uncontrolled Resource Consumption vulnerability in Wikimedia Foundation Mediawiki - IPInfo Extension allows Excessive Allocation.This issue affects Mediawiki - IPInfo Extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/YzpkSeL via IFTTT

CVE-2025-53490 - Wikimedia Foundation Mediawiki CampaignEvents Extension Cross-Site Scripting (XSS)

CVE ID : CVE-2025-53490 Published : July 3, 2025, 4:15 p.m. | 1 hour, 54 minutes ago Description : Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - CampaignEvents Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - CampaignEvents Extension: from 1.43.X before 1.43.2. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/DheXd1G via IFTTT

CVE-2025-20310 - Cisco Enterprise Chat and Email (ECE) Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-20310 Published : July 2, 2025, 4:15 p.m. | 2 hours, 3 minutes ago Description : A vulnerability in the web UI of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web UI does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To successfully exploit this vulnerability, an attacker would need valid agent credentials. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/oQBF1ha via IFTTT

CVE-2025-20308 - Cisco Spaces Connector Privilege Escalation Vulnerability

CVE ID : CVE-2025-20308 Published : July 2, 2025, 4:15 p.m. | 2 hours, 3 minutes ago Description : A vulnerability in Cisco Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. This vulnerability is due to insufficient restrictions during the execution of specific CLI commands. An attacker could exploit this vulnerability by logging in to the Cisco Spaces Connector CLI as the spacesadmin user and executing a specific command with crafted parameters. A successful exploit could allow the attacker to elevate privileges from the spacesadmin user and execute arbitrary commands on the underlying operating system as root. Severity: 6.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/lqnz6rH via IFTTT

CVE-2025-5339 - Adobe Ads Pro Plugin SQL Injection Vulnerability

CVE ID : CVE-2025-5339 Published : July 2, 2025, 4:15 a.m. | 5 hours, 49 minutes ago Description : The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘bsa_pro_id’ parameter in all versions up to, and including, 4.89 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/hL3AqHy via IFTTT

CVE-2025-5014 - The Home Villas | Real Estate WordPress Theme File Deletion Vulnerability (Arbitrary File Deletion)

CVE ID : CVE-2025-5014 Published : July 2, 2025, 4:15 a.m. | 5 hours, 49 minutes ago Description : The Home Villas | Real Estate WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'wp_rem_cs_widget_file_delete' function in all versions up to, and including, 2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/yn82VPH via IFTTT