Posts

Showing posts from October, 2025

CVE-2025-29270 - Deep Sea Electronics DSE855 Unauthenticated Remote Command Execution

CVE ID : CVE-2025-29270 Published : Oct. 31, 2025, 4:15 p.m. | 1 hour, 45 minutes ago Description : Incorrect access control in the realtime.cgi endpoint of Deep Sea Electronics devices DSE855 v1.1.0 to v1.1.26 allows attackers to gain access to the admin panel and complete control of the device. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/fFXP4CZ via IFTTT

CVE-2025-12516 - Lack of Graceful Error Handling - HTTP 5xx Error

CVE ID : CVE-2025-12516 Published : Oct. 30, 2025, 4:15 p.m. | 1 hour, 43 minutes ago Description : Lack of Graceful Error Handling - HTTP 5xx ErrorThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/aZMptg5 via IFTTT

CVE-2025-60542 - TypeORM SQL Injection

CVE ID : CVE-2025-60542 Published : Oct. 29, 2025, 4:15 p.m. | 1 hour, 40 minutes ago Description : SQL Injection vulnerability in TypeORM before 0.3.26 via crafted request to repository.save or repository.update due to the sqlstring call using stringifyObjects default to false. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/YDr84qe via IFTTT

CVE-2025-34294 - Wazuh File Integrity Monitoring (FIM) & Active Response Arbitrary File Deletion as SYSTEM

CVE ID : CVE-2025-34294 Published : Oct. 28, 2025, 4:15 p.m. | 1 hour, 38 minutes ago Description : Wazuh's File Integrity Monitoring (FIM), when configured with automatic threat removal, contains a time-of-check/time-of-use (TOCTOU) race condition that can allow a local, low-privileged attacker to cause the Wazuh service (running as NT AUTHORITY\SYSTEM) to delete attacker-controlled files or paths. The root cause is insufficient synchronization and lack of robust final-path validation in the threat-removal workflow: the agent records an active-response action and proceeds to perform deletion without guaranteeing the deletion target is the originally intended file. This can result in SYSTEM-level arbitrary file or folder deletion and consequent local privilege escalation. Wazuh made an attempted fix via pull request 8697 on 2025-07-10, but that change was incomplete. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline...

CVE-2025-60425 - Nagios Fusion Session Hijacking Vulnerability

CVE ID : CVE-2025-60425 Published : Oct. 27, 2025, 4:15 p.m. | 1 hour, 6 minutes ago Description : Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabled, allowing attackers to perform a session hijacking attack. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/fhe7XwI via IFTTT

CVE-2025-60424 - Nagios Fusion Authentication Bypass

CVE ID : CVE-2025-60424 Published : Oct. 27, 2025, 4:15 p.m. | 1 hour, 6 minutes ago Description : A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication via a bruteforce attack. Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/lv9BLp1 via IFTTT

CVE-2023-49440 - AhnLab EPP SQL Injection Vulnerability

CVE ID : CVE-2023-49440 Published : Oct. 27, 2025, 4:15 p.m. | 1 hour, 6 minutes ago Description : AhnLab EPP 1.0.15 is vulnerable to SQL Injection via the "preview parameter." Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/ozEsbBA via IFTTT

CVE-2023-37749 - HubSpot Unauthenticated Data Disclosure Vulnerability

CVE ID : CVE-2023-37749 Published : Oct. 27, 2025, 4:15 p.m. | 1 hour, 6 minutes ago Description : Incorrect access control in the REST API endpoint of HubSpot v1.29441 allows unauthenticated attackers to view users' data without proper authorization. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/DnHWgev via IFTTT

CVE-2025-12275 - Mail Configuration File Manipulation + Command Execution

CVE ID : CVE-2025-12275 Published : Oct. 26, 2025, 5:15 p.m. | 29 minutes ago Description : Mail Configuration File Manipulation + Command Execution.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/yuMZBl8 via IFTTT

CVE-2025-8709 - SQL Injection in langchain-ai/langchain

CVE ID : CVE-2025-8709 Published : Oct. 26, 2025, 6:15 a.m. | 1 hour, 27 minutes ago Description : A SQL injection vulnerability exists in the langchain-ai/langchain repository, specifically in the LangGraph's SQLite store implementation. The affected version is langgraph-checkpoint-sqlite 2.0.10. The vulnerability arises from improper handling of filter operators ($eq, $ne, $gt, $lt, $gte, $lte) where direct string concatenation is used without proper parameterization. This allows attackers to inject arbitrary SQL, leading to unauthorized access to all documents, data exfiltration of sensitive fields such as passwords and API keys, and a complete bypass of application-level security filters. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/WZYJ8mA via IFTTT

CVE-2025-55757 - Extension - virtuemart.net - XSS in VirtueMart component 1.0.0 - 4.4.10 for Joomla

CVE ID : CVE-2025-55757 Published : Oct. 25, 2025, 7:15 p.m. | 26 minutes ago Description : A unauthenticated reflected XSS vulnerability in VirtueMart 1.0.0-4.4.10 for Joomla was discovered. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/VCASaFj via IFTTT

CVE-2025-60729 - PerfreeBlog Arbitrary File Read Vulnerability

CVE ID : CVE-2025-60729 Published : Oct. 24, 2025, 6:15 p.m. | 1 hour, 24 minutes ago Description : PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/ul1ILnX via IFTTT

CVE-2025-61413 - Piranha CMS Stored XSS

CVE ID : CVE-2025-61413 Published : Oct. 23, 2025, 6:16 p.m. | 33 minutes ago Description : A stored cross-site scripting (XSS) vulnerability in the /manager/pages component of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via creating a page and injecting a crafted payload into the Markdown blocks. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/q34IUAS via IFTTT

CVE-2025-57240 - "17gz International Student Service System XSS Injection"

CVE ID : CVE-2025-57240 Published : Oct. 23, 2025, 6:16 p.m. | 34 minutes ago Description : Cross site scripting (XSS) vulnerability in 17gz International Student service system 1.0 allows attackers to execute arbitrary code via the registration step. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/K2LsPH9 via IFTTT

CVE-2025-11958 - Devolutions Server Denial of Service (DoS) Vulnerability

CVE ID : CVE-2025-11958 Published : Oct. 22, 2025, 5:15 p.m. | 1 hour, 32 minutes ago Description : An improper input validation in the Security Dashboard ignored-tasks API of Devolutions Server 2025.2.15.0 and earlier allows an authenticated user to cause a denial of service to the Security Dashboard via a crafted request. Severity: 4.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/1DZFlg7 via IFTTT

CVE-2025-11957 - Devolutions Server Basic User Privilege Escalation Vulnerability

CVE ID : CVE-2025-11957 Published : Oct. 22, 2025, 5:15 p.m. | 1 hour, 32 minutes ago Description : Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to self-approve or approve the temporary access requests of other users and gain unauthorized access to vaults and entries via crafted API requests. Severity: 8.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/gT8eaAV via IFTTT

CVE-2025-11534 - Authentication Bypass Using an Alternate Path or Channel in Raisecomm RAX701-GC Series

CVE ID : CVE-2025-11534 Published : Oct. 21, 2025, 5:15 p.m. | 1 hour, 29 minutes ago Description : The affected Raisecom devices allow SSH sessions to be established without completing user authentication. This could allow attackers to gain shell access without valid credentials. Severity: 9.3 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/HBe4E9i via IFTTT

CVE-2025-9574 - Missing Authentication Vulnerability

CVE ID : CVE-2025-9574 Published : Oct. 20, 2025, 5:15 p.m. | 1 hour, 27 minutes ago Description : Missing Authentication for Critical Function vulnerability in ABB ALS-mini-s4 IP, ABB ALS-mini-s8 IP.This issue affects .  All firmware versions with the Serial Number from 2000 to 5166 Severity: 9.9 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/0MYd37B via IFTTT

CVE-2025-11940 - LibreWolf Installer setup.nsi uncontrolled search path

CVE ID : CVE-2025-11940 Published : Oct. 19, 2025, 9:15 a.m. | 1 hour, 23 minutes ago Description : A security vulnerability has been detected in LibreWolf up to 143.0.4-1 on Windows. This affects an unknown function of the file assets/setup.nsi of the component Installer. Such manipulation leads to uncontrolled search path. The attack must be carried out locally. Attacks of this nature are highly complex. The exploitability is reported as difficult. Upgrading to version 144.0-1 mitigates this issue. The name of the patch is dd10e31dd873e9cb309fad8aed921d45bf905a55. It is suggested to upgrade the affected component. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/fgtYz0k via IFTTT

CVE-2025-11939 - ChurchCRM Backup Restore RestoreJob.php path traversal

CVE ID : CVE-2025-11939 Published : Oct. 19, 2025, 8:15 a.m. | 23 minutes ago Description : A vulnerability was determined in ChurchCRM up to 5.18.0. This issue affects some unknown processing of the file src/ChurchCRM/Backup/RestoreJob.php of the component Backup Restore Handler. Executing manipulation of the argument restoreFile can lead to path traversal. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/DySon1Z via IFTTT

CVE-2025-11938 - ChurchCRM setup.php deserialization

CVE ID : CVE-2025-11938 Published : Oct. 19, 2025, 8:15 a.m. | 23 minutes ago Description : A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/setup.php. Performing manipulation of the argument DB_PASSWORD/ROOT_PATH/URL results in deserialization. The attack may be initiated remotely. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/zBFD5LG via IFTTT

CVE-2025-62672 - Rplay Denial of Service and Code Execution Vulnerability

CVE ID : CVE-2025-62672 Published : Oct. 19, 2025, 1:15 a.m. | 1 hour, 22 minutes ago Description : rplay through 3.3.2 allows attackers to cause a denial of service (SIGSEGV and daemon crash) or possibly have unspecified other impact. This occurs in memcpy in the RPLAY_DATA case in rplay_unpack in librplay/rplay.c, potentially reachable via packet data with no authentication. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/t4I2Zg8 via IFTTT

CVE-2025-62171 - ImageMagick vulnerable to denial of service via integer overflow in BMP decoder on 32-bit systems

CVE ID : CVE-2025-62171 Published : Oct. 17, 2025, 5:15 p.m. | 1 hour, 19 minutes ago Description : ImageMagick is an open source software suite for displaying, converting, and editing raster image files. In ImageMagick versions prior to 7.1.2-7 and 6.9.13-32, an integer overflow vulnerability exists in the BMP decoder on 32-bit systems. The vulnerability occurs in coders/bmp.c when calculating the extent value by multiplying image columns by bits per pixel. On 32-bit systems with size_t of 4 bytes, a malicious BMP file with specific dimensions can cause this multiplication to overflow and wrap to zero. The overflow check added to address CVE-2025-57803 is placed after the overflow occurs, making it ineffective. A specially crafted 58-byte BMP file with width set to 536,870,912 and 32 bits per pixel can trigger this overflow, causing the bytes_per_line calculation to become zero. This vulnerability only affects 32-bit builds of ImageMagick where default resource limits fo...

CVE-2025-58051 - Nextcloud Tables app allowed to include local file via PhpSpreadsheet when importing a table

CVE ID : CVE-2025-58051 Published : Oct. 16, 2025, 5:15 p.m. | 1 hour, 17 minutes ago Description : Nextcloud Tables allows you to create your own tables with individual columns. Prior 0.7.6, 0.8.8, and 0.9.5, when importing a table, a user was able to specify files on the server and when their format is supported by the used PhpSpreadsheet library they would be included and their content leaked to the user. It is recommended that the Nextcloud Tables app is upgraded to 0.7.6, 0.8.8 or 0.9.5. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/lPUCEIT via IFTTT

CVE-2025-10576 - Sound Research SECOMNService Escalation of Privilege

CVE ID : CVE-2025-10576 Published : Oct. 15, 2025, 5:15 p.m. | 1 hour, 14 minutes ago Description : Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. HP is releasing updated audio packages to mitigate the potential vulnerabilities. Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/7kYVNR2 via IFTTT

CVE-2025-59277 - Windows Authentication Elevation of Privilege Vulnerability

CVE ID : CVE-2025-59277 Published : Oct. 14, 2025, 5:16 p.m. | 1 hour, 12 minutes ago Description : Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/tOiT5lg via IFTTT

CVE-2025-59261 - Windows Graphics Component Elevation of Privilege Vulnerability

CVE ID : CVE-2025-59261 Published : Oct. 14, 2025, 5:16 p.m. | 1 hour, 12 minutes ago Description : Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. Severity: 7.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/qGxrQKa via IFTTT

CVE-2025-59260 - Microsoft Failover Cluster Virtual Driver Information Disclosure Vulnerability

CVE ID : CVE-2025-59260 Published : Oct. 14, 2025, 5:16 p.m. | 1 hour, 12 minutes ago Description : Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an authorized attacker to disclose information locally. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/8jCTLJb via IFTTT

CVE-2025-11695 - Configuration may unexpectedly disable certificate validation

CVE ID : CVE-2025-11695 Published : Oct. 13, 2025, 5:15 p.m. | 1 hour, 8 minutes ago Description : When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5 Severity: 8.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/ArzLHXE via IFTTT

CVE-2025-62243 - Liferay Portal and DXP Insecure Direct Object Reference (IDOR) and Permission Bypass Vulnerability

CVE ID : CVE-2025-62243 Published : Oct. 13, 2025, 5:14 p.m. | 1 hour, 9 minutes ago Description : Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote authenticated attackers to view publication comments via the _com_liferay_change_tracking_web_portlet_PublicationsPortlet_value parameter. Publications comments in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 does not properly check user permissions, which allows remote authenticated users to edit publication comments via crafted URLs. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/YXHvFK9 via IFTTT

CVE-2025-11638 - Tomofun Furbo 360/Furbo Mini Bluetooth denial of service

CVE ID : CVE-2025-11638 Published : Oct. 12, 2025, 5:15 p.m. | 1 hour, 5 minutes ago Description : A flaw has been found in Tomofun Furbo 360 and Furbo Mini. The affected element is an unknown function of the component Bluetooth Handler. Executing manipulation can lead to denial of service. The attacker needs to be present on the local network. The firmware versions determined to be affected are Furbo 360 up to FB0035_FW_036 and Furbo Mini up to MC0020_FW_074. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/J9SNEG5 via IFTTT

CVE-2025-11637 - Tomofun Furbo 360 Audio race condition

CVE ID : CVE-2025-11637 Published : Oct. 12, 2025, 5:15 p.m. | 1 hour, 5 minutes ago Description : A vulnerability was detected in Tomofun Furbo 360 up to FB0035_FW_036. Impacted is an unknown function of the component Audio Handler. Performing manipulation results in race condition. The attack is possible to be carried out remotely. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/hpuBOyC via IFTTT

CVE-2025-11608 - code-projects E-Banking System POST Parameter register.php sql injection

CVE ID : CVE-2025-11608 Published : Oct. 11, 2025, 5:15 p.m. | 1 hour, 3 minutes ago Description : A security vulnerability has been detected in code-projects E-Banking System 1.0. This affects an unknown function of the file /register.php of the component POST Parameter Handler. The manipulation of the argument username/password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/rQkTsH4 via IFTTT

CVE-2025-11607 - harry0703 MoneyPrinterTurbo API Endpoint music.py upload_music path traversal

CVE ID : CVE-2025-11607 Published : Oct. 11, 2025, 5:15 p.m. | 1 hour, 3 minutes ago Description : A weakness has been identified in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function upload_music of the file app/controllers/v1/music.py of the component API Endpoint. Executing manipulation of the argument File can lead to path traversal. The attack may be performed from remote. The exploit has been made available to the public and could be exploited. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/vinbhNP via IFTTT

CVE-2025-60307 - code-projects Computer Laboratory System 1.0 has a

CVE ID : CVE-2025-60307 Published : Oct. 10, 2025, 4:15 p.m. | 2 hours, 1 minute ago Description : code-projects Computer Laboratory System 1.0 has a SQL injection vulnerability, where entering a universal password in the Password field on the login page can bypass login attempts. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/FWiPUyp via IFTTT

CVE-2025-60305 - SourceCodester Online Student Clearance System Privilege Escalation Vulnerability

CVE ID : CVE-2025-60305 Published : Oct. 10, 2025, 4:15 p.m. | 2 hours, 1 minute ago Description : SourceCodester Online Student Clearance System 1.0 is vulnerable to Incorrect Access Control. The application contains a logic flaw which allows low privilege users can forge high privileged sessions and perform sensitive operations. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/eEkaR2L via IFTTT

CVE-2025-59987 - Junos Space: The arbitrary device search field is vulnerable to reflected cross-site script injection

CVE ID : CVE-2025-59987 Published : Oct. 9, 2025, 5:16 p.m. | 59 minutes ago Description : An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the arbitrary device search field that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.This issue affects all versions of Junos Space before 24.1R4. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/ne9dTMK via IFTTT

CVE-2025-60318 - SourceCodester Pet Grooming Management Software XSS

CVE ID : CVE-2025-60318 Published : Oct. 8, 2025, 4:15 p.m. | 1 hour, 54 minutes ago Description : SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the fname (First Name) and lname (Last Name) fields. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/yVNeC4Z via IFTTT

CVE-2025-59303 - HAProxy Kubernetes Ingress Controller Config Snippet Token Secret Exposure

CVE ID : CVE-2025-59303 Published : Oct. 8, 2025, 4:15 p.m. | 1 hour, 54 minutes ago Description : HAProxy Kubernetes Ingress Controller before 3.1.13, when the config-snippets feature flag is used, accepts config snippets from users with create/update permissions. This can result in obtaining an ingress token secret as a response. The fixed versions of HAProxy Enterprise Kubernetes Ingress Controller are 3.0.16-ee1, 1.11.13-ee1, and 1.9.15-ee1. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/zNen6Yg via IFTTT

CVE-2025-11401 - SourceCodester Hotel and Lodge Management System save_curr.php sql injection

CVE ID : CVE-2025-11401 Published : Oct. 7, 2025, 5:15 p.m. | 52 minutes ago Description : A flaw has been found in SourceCodester Hotel and Lodge Management System 1.0. Affected is an unknown function of the file /pages/save_curr.php. This manipulation of the argument currcode causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/flEk5tK via IFTTT

CVE-2025-36355 - IBM Security Verify Access code execution

CVE ID : CVE-2025-36355 Published : Oct. 6, 2025, 5:16 p.m. | 1 hour, 19 minutes ago Description : IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to execute malicious scripts from outside of its control sphere. Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/TRm9zSA via IFTTT

Searpy - Search Engine Toolkit

Image
Searpy tool is an automated and open-source cyber-security tool developed in python language which is is intentionally developed to string for the IP address and the links from various search engines like Shodan, Google, Baidu, Yahoo, etc. However, Searpy tool is available on the Github platform for free. In addition,there are features to display the output in a more verbose mode and detailed manner. Installation Proccess: git clone https://github.com/j3ers3/Searpy   cd Searpy   sudo pip3 install -r   requirements.txt sudo python3 Searpy.py -h Some Example Usage: Usage 1: Searching something on shodan python3 Searpy.py --shodan -s "Maloy" -l 10 Usage 2:  Using favicon.icon hash to find websites with the same icon python3 Searpy.py --shodan_icon https://websecurityinsights.my.id/ Usage 3: Using Google Search Engine for dorking python3 Searpy.py --google -s "inurl:php?id=" References: https://github.com/j3ers3/Searpy Stay with us: Web Security Insights Wanna know ...

CVE-2025-11295 - Belkin F9K1015 formPPPoESetup buffer overflow

CVE ID : CVE-2025-11295 Published : Oct. 5, 2025, 5:15 p.m. | 1 hour, 17 minutes ago Description : A flaw has been found in Belkin F9K1015 1.00.10. This affects an unknown part of the file /goform/formPPPoESetup. This manipulation of the argument pppUserName causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/NE1UT3k via IFTTT

CVE-2023-53592 - gpio: sifive: Fix refcount leak in sifive_gpio_probe

CVE ID : CVE-2023-53592 Published : Oct. 4, 2025, 4:15 p.m. | 1 hour, 27 minutes ago Description : In the Linux kernel, the following vulnerability has been resolved: gpio: sifive: Fix refcount leak in sifive_gpio_probe of_irq_find_parent() returns a node pointer with refcount incremented, We should use of_node_put() on it when not needed anymore. Add missing of_node_put() to avoid refcount leak. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/XZOFN4d via IFTTT

CVE-2025-55971 - TCL Smart TV SSRF Vulnerability

CVE ID : CVE-2025-55971 Published : Oct. 3, 2025, 4:16 p.m. | 1 hour, 26 minutes ago Description : TCL 65C655 Smart TV, running firmware version V8-R75PT01-LF1V269.001116 (Android TV, Kernel 5.4.242+), is vulnerable to a blind, unauthenticated Server-Side Request Forgery (SSRF) vulnerability via the UPnP MediaRenderer service (AVTransport:1). The device accepts unauthenticated SetAVTransportURI SOAP requests over TCP/16398 and attempts to retrieve externally referenced URIs, including attacker-controlled payloads. The blind SSRF allows for sending requests on behalf of the TV, which can be leveraged to probe for other internal or external services accessible by the device (e.g., 127.0.0.1:16XXX, LAN services, or internet targets), potentially enabling additional exploit chains. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/LA5QZF1 via IFTTT

CVE-2025-34226 - OpenPLC Runtime v3 Persistent DoS

CVE ID : CVE-2025-34226 Published : Oct. 3, 2025, 4:16 p.m. | 1 hour, 26 minutes ago Description : OpenPLC Runtime v3 contains an input validation flaw in the /upload-program-action endpoint: the epoch_time field supplied during program uploads is not validated and can be crafted to induce corruption of the programs database. After a successful malformed upload the runtime continues to operate until a restart; on restart the runtime can fail to start because of corrupted database entries, resulting in persistent denial of service requiring complete rebase of the product to recover. This vulnerability was remediated by commit 095ee09623dd229b64ad3a1db38a901a3772f6fc. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/a9f5yqO via IFTTT

CVE-2025-56161 - YOSHOP Unauthenticated Comment Information Disclosure Vulnerability

CVE ID : CVE-2025-56161 Published : Oct. 2, 2025, 4:15 p.m. | 1 hour, 25 minutes ago Description : YOSHOP 2.0 allows unauthenticated information disclosure via comment-list API endpoints in the Goods module. The Comment model eagerly loads the related User model without field filtering; because User.php defines no $hidden or $visible attributes, sensitive fields (bcrypt password hash, mobile number, pay_money, expend_money.) are exposed in JSON responses. Route names vary per deployment (e.g. /api/goods.pinglun/list), but all call the same vulnerable model logic. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/uXbBaOS via IFTTT

CVE-2025-56154 - "htmly XSS Reflected"

CVE ID : CVE-2025-56154 Published : Oct. 2, 2025, 4:15 p.m. | 1 hour, 25 minutes ago Description : htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application. The name parameter is not properly sanitized before being reflected in the HTML response, allowing attackers to inject arbitrary JavaScript payloads. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/6j5Y1rl via IFTTT

CVE-2025-56515 - Fiora Chat Application SVG File Upload Code Execution Vulnerability

CVE ID : CVE-2025-56515 Published : Oct. 1, 2025, 4:15 p.m. | 1 hour, 51 minutes ago Description : File upload vulnerability in Fiora chat application 1.0.0 through user avatar upload functionality. The application fails to validate SVG file content, allowing malicious SVG files with embedded foreignObject elements containing iframe tags and JavaScript event handlers (onmouseover) to be uploaded and stored. When rendered, these SVG files execute arbitrary JavaScript, enabling attackers to steal user sessions, cookies, and perform unauthorized actions in the context of users viewing affected profiles. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/q2dA8i4 via IFTTT

CVE-2025-56514 - Fiora Chat Application SVG File XSS Vulnerability

CVE ID : CVE-2025-56514 Published : Oct. 1, 2025, 4:15 p.m. | 1 hour, 51 minutes ago Description : Cross Site Scripting (XSS) vulnerability in Fiora chat application 1.0.0 allows executes arbitrary JavaScript when malicious SVG files are rendered by other users. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/qVPNzXT via IFTTT