Posts

Showing posts from November, 2025

CVE-2025-35028 - HexStrike AI MCP Server Command Injection

CVE ID : CVE-2025-35028 Published : Nov. 30, 2025, 10:15 p.m. | 1 hour, 18 minutes ago Description : By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecutor class of the HexStrike AI MCP server, the resultant composed command is executed directly in the context of the MCP server’s normal privilege; typically, this is root. There is no attempt to sanitize these arguments in the default configuration of this MCP server at the affected version (as of commit 2f3a5512 in September of 2025). Severity: 9.1 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/C9EkWUB via IFTTT

CVE-2025-13791 - Scada-LTS Project Import ZIPProjectManager.java Common.getHomeDir path traversal

CVE ID : CVE-2025-13791 Published : Nov. 30, 2025, 4:15 p.m. | 1 hour, 17 minutes ago Description : A vulnerability was identified in Scada-LTS up to 2.7.8.1. Affected is the function Common.getHomeDir of the file br/org/scadabr/vo/exporter/ZIPProjectManager.java of the component Project Import. Such manipulation leads to path traversal. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/CXWLGUE via IFTTT

CVE-2025-13782 - taosir WTCMS SlideController SlideController.class.php delete sql injection

CVE ID : CVE-2025-13782 Published : Nov. 30, 2025, 3:02 a.m. | 29 minutes ago Description : A vulnerability was identified in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Affected by this issue is the function delete of the file application/Admin/Controller/SlideController.class.php of the component SlideController. The manipulation of the argument ids leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/JCkxmH3 via IFTTT

CVE-2025-66036 - Retro is vulnerable to XSS vulnerability in input handling component

CVE ID : CVE-2025-66036 Published : Nov. 29, 2025, 1:14 a.m. | 1 hour, 5 minutes ago Description : Retro is an online platform providing items of vintage collections. Prior to version 2.4.7, Retro is vulnerable to a cross-site scripting (XSS) in the input handling component. This issue has been patched in version 2.4.7. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/vbk1EaX via IFTTT

CVE-2025-13683 - Devolutions Server and Remote Desktop Manager Credential Exposure

CVE ID : CVE-2025-13683 Published : Nov. 28, 2025, 5:16 p.m. | 1 hour, 3 minutes ago Description : Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affects Devolutions Server: through 2025.3.8.0; Remote Desktop Manager: through 2025.3.23.0. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/IGuyzL9 via IFTTT

CVE-2025-13338 - Apache HTTP Server Cross-Site Scripting

CVE ID : CVE-2025-13338 Published : Nov. 27, 2025, 11:15 p.m. | 1 hour, 3 minutes ago Description : Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/r49EjlB via IFTTT

CVE-2025-12559 - Information Disclosure in Common Teams API

CVE ID : CVE-2025-12559 Published : Nov. 27, 2025, 5:15 p.m. | 1 hour, 3 minutes ago Description : Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/1uV2j3B via IFTTT

CVE-2025-3747 - Apache Struts Remote Code Execution

CVE ID : CVE-2025-3747 Published : Nov. 26, 2025, 4:15 p.m. | 2 hours, 3 minutes ago Description : Rejected reason: This CVE ID was duplicated of CVE-2025-32801 Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/UqxomyA via IFTTT

CVE-2025-60739 - Ilevia EVE X1 Server Firmware CSRF

CVE ID : CVE-2025-60739 Published : Nov. 25, 2025, 4:16 p.m. | 2 hours, 2 minutes ago Description : Cross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logic Version v6.00 - 2025_07_21 allows a remote attacker to execute arbitrary code via the /bh_web_backend component Severity: 9.6 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/roHxZ4W via IFTTT

CVE-2025-56401 - ZIRA Group WBRM SQL Injection

CVE ID : CVE-2025-56401 Published : Nov. 24, 2025, 4:15 p.m. | 2 hours, 2 minutes ago Description : ZIRA Group WBRM 7.0 is vulnerable to SQL Injection in referenceLookupsByTableNameAndColumnName. Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/hXvbqa6 via IFTTT

CVE-2025-54515 - Arm Versal Adaptive SoC PSCI Secure State Spoofing

CVE ID : CVE-2025-54515 Published : Nov. 23, 2025, 5:15 p.m. | 1 hour, 2 minutes ago Description : The Secure Flag passed to Versal™ Adaptive SoC’s Arm® Trusted Firmware for Cortex®-A processors (TF-A) for Arm’s Power State Coordination Interface (PSCI) commands were incorrectly set to secure instead of using the processor’s actual security state. This would allow the PSCI requests to appear they were from processors in the secure state instead of the non-secure state. Severity: 1.0 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/xg60jsw via IFTTT

CVE-2025-13544 - ashraf-kabir travel-agency customer_register.php unrestricted upload

CVE ID : CVE-2025-13544 Published : Nov. 23, 2025, 9:15 a.m. | 1 hour, 2 minutes ago Description : A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is an unknown function of the file /customer_register.php. Executing manipulation can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/AQdqX6v via IFTTT

CVE-2025-12541 - "Apache Struts Remote Code Execution Vulnerability"

CVE ID : CVE-2025-12541 Published : Nov. 22, 2025, 11:15 p.m. | 1 hour, 2 minutes ago Description : Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/UMQvjEq via IFTTT

CVE-2025-13470 - RNP 0.18.0 Vulnerable PKESK session keys

CVE ID : CVE-2025-13470 Published : Nov. 21, 2025, 5:15 p.m. | 1 hour, 38 minutes ago Description : In RNP version 0.18.0 a refactoring regression causes the symmetric session key used for Public-Key Encrypted Session Key (PKESK) packets to be left uninitialized except for zeroing, resulting in it always being an all-zero byte array. Any data encrypted using public-key encryption in this release can be decrypted trivially by supplying an all-zero session key, fully compromising confidentiality. The vulnerability affects only public key encryption (PKESK packets).  Passphrase-based encryption (SKESK packets) is not affected. Root cause: Vulnerable session key buffer used in PKESK packet generation. The defect was introduced in commit `7bd9a8dc356aae756b40755be76d36205b6b161a` where initialization logic inside `encrypted_build_skesk()` only randomized the key for the SKESK path and omitted it for the PKESK path. Severity: 7.7 | HIGH Visit the link for more details, ...

CVE-2024-31405 - Apache HTTP Server Unauthenticated Remote Code Execution

CVE ID : CVE-2024-31405 Published : Nov. 20, 2025, 4:15 p.m. | 1 hour, 58 minutes ago Description : Rejected reason: Voluntarily withdrawn Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/GgNi9rb via IFTTT

CVE-2025-64521 - authentik deactivated service accounts can authenticate to OAuth

CVE ID : CVE-2025-64521 Published : Nov. 19, 2025, 5:15 p.m. | 57 minutes ago Description : authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authenticating with client_id and client_secret to an OAuth provider, authentik creates a service account for the provider. In previous authentik versions, authentication for this account was possible even when the account was deactivated. Other permissions are correctly applied and federation with other providers still take assigned policies correctly into account. authentik versions 2025.8.5 and 2025.10.2 fix this issue. A workaround involves adding a policy to the application that explicitly checks if the service account is still valid, and deny access if not. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/9uQOHjM via IFTTT

CVE-2025-34324 - GoSign Desktop < 2.4.1 Insecure Update Mechanism RCE

CVE ID : CVE-2025-34324 Published : Nov. 18, 2025, 5:16 p.m. | 51 minutes ago Description : GoSign Desktop versions 2.4.0 and earlier use an unsigned update manifest for distributing application updates. The manifest contains package URLs and SHA-256 hashes but is not digitally signed, so its authenticity relies solely on the underlying TLS channel. In affected versions, TLS certificate validation can be disabled when a proxy is configured, allowing an attacker who can intercept network traffic to supply a malicious update manifest and corresponding package with a matching hash. This can cause the client to download and install a tampered update, resulting in arbitrary code execution with the privileges of the GoSign Desktop user on Windows and macOS, or with elevated privileges on some Linux deployments. A local attacker who can modify proxy settings may also abuse this behavior to escalate privileges by forcing installation of a crafted update. Severity: 7.0 | HIGH Visit ...

CVE-2025-65083 - GoSign Desktop Proxy Server TLS Certificate Validation Bypass

CVE ID : CVE-2025-65083 Published : Nov. 17, 2025, 4:15 p.m. | 1 hour, 43 minutes ago Description : GoSign Desktop through 2.4.1 disables TLS certificate validation when configured to use a proxy server. This can be problematic if the GoSign Desktop user selects an arbitrary proxy server without consideration of whether outbound HTTPS connections from the proxy server to Internet servers succeed even for untrusted or invalid server certificates. In this scenario (which is outside of the product's design objectives), integrity protection could be bypassed. In typical cases of a proxy server for outbound HTTPS traffic from an enterprise, those connections would not succeed. (Admittedly, the usual expectation is that a client application is configured to trust an enterprise CA and does not set SSL_VERIFY_NONE.) Also, it is of course unsafe to place ~/.gosign in the home directory of an untrusted user and then have other users execute downloaded files. Severity: 3.2 | LOW ...

CVE-2025-13254 - projectworlds Advanced Library Management System add_member.php sql injection

CVE ID : CVE-2025-13254 Published : Nov. 17, 2025, 1:15 a.m. | 43 minutes ago Description : A vulnerability was identified in projectworlds Advanced Library Management System 1.0. This vulnerability affects unknown code of the file /add_member.php. Such manipulation of the argument roll_number leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/8KGgxQH via IFTTT

CVE-2025-13252 - shsuishang ShopSuite ModulithShop RSA/OAuth2/Database hard-coded credentials

CVE ID : CVE-2025-13252 Published : Nov. 16, 2025, 11:15 p.m. | 43 minutes ago Description : A vulnerability was found in shsuishang ShopSuite ModulithShop up to 45a99398cec3b7ad7ff9383694f0b53339f2d35a. Affected by this issue is some unknown functionality of the component RSA/OAuth2/Database. The manipulation results in hard-coded credentials. The attack can be executed remotely. The exploit has been made public and could be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/vNx2GDs via IFTTT

CVE-2025-13208 - FantasticLBP Hotels Server hotelList.php sql injection

CVE ID : CVE-2025-13208 Published : Nov. 15, 2025, 6:15 p.m. | 1 hour, 43 minutes ago Description : A security flaw has been discovered in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. The impacted element is an unknown function of the file controller/api/hotelList.php. The manipulation of the argument subjectId/cityName results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be exploited. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/Be2LnZM via IFTTT

CVE-2025-13201 - code-projects Simple Cafe Ordering System login.php sql injection

CVE ID : CVE-2025-13201 Published : Nov. 15, 2025, 4:15 p.m. | 1 hour, 43 minutes ago Description : A vulnerability was identified in code-projects Simple Cafe Ordering System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Such manipulation of the argument Username leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/S4aXCbe via IFTTT

CVE-2024-42749 - Alto CMS Cross Site Scripting Vulnerability

CVE ID : CVE-2024-42749 Published : Nov. 14, 2025, 4:15 p.m. | 1 hour, 42 minutes ago Description : Cross Site Scripting vulnerability in Alto CMS v.1.1.13 allows a local attacker to execute arbitrary code via a crafted script. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/iBS5tq9 via IFTTT

CVE-2025-60689 - Linksys E1200 HTTPd Command Injection Vulnerability

CVE ID : CVE-2025-60689 Published : Nov. 13, 2025, 4:15 p.m. | 1 hour, 42 minutes ago Description : An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The vulnerability occurs because user-supplied CGI parameters (wl_ant, wl_ssid, wl_rate, ttcp_num, ttcp_ip, ttcp_size) are concatenated into system command strings without proper sanitization and executed via wl_exec_cmd. Successful exploitation allows remote attackers to execute arbitrary commands on the device without authentication. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/ZLpvOeJ via IFTTT

CVE-2025-11366 - N-central Authentication bypass via path traversal

CVE ID : CVE-2025-11366 Published : Nov. 12, 2025, 4:15 p.m. | 1 hour, 38 minutes ago Description : N-central < 2025.4 is vulnerable to authentication bypass via path traversal Severity: 9.4 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/qrDo7U2 via IFTTT

CVE-2025-30509 - Intel QuickAssist Technology Ring 3 Escalation of Privilege Vulnerability

CVE ID : CVE-2025-30509 Published : Nov. 11, 2025, 4:50 p.m. | 20 minutes ago Description : Improper input validation for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable data manipulation. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/8ZOGHI4 via IFTTT

CVE-2025-30506 - Intel Driver and Support Assistant Uncontrolled Search Path Privilege Escalation Vulnerability

CVE ID : CVE-2025-30506 Published : Nov. 11, 2025, 4:50 p.m. | 20 minutes ago Description : Uncontrolled search path for some Intel Driver and Support Assistant before version 25.2 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable local code execution. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts. Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/ah9d2Mk via IFTTT

CVE-2025-12924 - rymcu forest BankController.java GlobalResult authorization

CVE ID : CVE-2025-12924 Published : Nov. 10, 2025, 1:02 a.m. | 44 minutes ago Description : A vulnerability was identified in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. This issue affects the function GlobalResult of the file src/main/java/com/rymcu/forest/web/api/bank/BankController.java. The manipulation leads to missing authorization. The attack may be initiated remotely. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/B75xHhN via IFTTT

CVE-2025-12920 - qianfox FoxCMS Product.php edit cross site scripting

CVE ID : CVE-2025-12920 Published : Nov. 9, 2025, 11:15 p.m. | 30 minutes ago Description : A flaw has been found in qianfox FoxCMS up to 1.2.16. Affected by this vulnerability is the function add/edit of the file app/admin/controller/Product.php. This manipulation of the argument Title causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/7fpYKeb via IFTTT

CVE-2025-12919 - EverShop Order Order.resolvers.js resource injection

CVE ID : CVE-2025-12919 Published : Nov. 9, 2025, 8:15 p.m. | 1 hour, 30 minutes ago Description : A vulnerability was detected in EverShop up to 2.0.1. Affected is an unknown function of the file /src/modules/oms/graphql/types/Order/Order.resolvers.js of the component Order Handler. The manipulation of the argument uuid results in improper control of resource identifiers. The attack may be performed from remote. This attack is characterized by high complexity. The exploitability is told to be difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/sXdYCN6 via IFTTT

CVE-2025-12916 - Sangfor Operation and Maintenance Security Management System Frontend portal_login command injection

CVE ID : CVE-2025-12916 Published : Nov. 9, 2025, 12:15 a.m. | 1 hour, 29 minutes ago Description : A vulnerability was determined in Sangfor Operation and Maintenance Security Management System 3.0. Impacted is an unknown function of the file /fort/portal_login of the component Frontend. This manipulation of the argument loginUrl causes command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 3.0.11 and 3.0.12 is recommended to address this issue. It is advisable to upgrade the affected component. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/KO7vZpT via IFTTT

CVE-2025-12914 - aaPanel BaoTa Backend database sql injection

CVE ID : CVE-2025-12914 Published : Nov. 8, 2025, 10:15 p.m. | 1 hour, 29 minutes ago Description : A vulnerability has been found in aaPanel BaoTa up to 11.1.0. This vulnerability affects unknown code of the file /database?action=GetDatabaseAccess of the component Backend. The manipulation of the argument Name leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/0pBMCkK via IFTTT

CVE-2025-12913 - code-projects Responsive Hotel Site roomdel.php sql injection

CVE ID : CVE-2025-12913 Published : Nov. 8, 2025, 8:15 p.m. | 1 hour, 28 minutes ago Description : A flaw has been found in code-projects Responsive Hotel Site 1.0. This affects an unknown part of the file /admin/roomdel.php. Executing manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/bANdg6G via IFTTT

CVE-2025-63686 - GuoMinJim PersonManage Arbitrary File Download Vulnerability

CVE ID : CVE-2025-63686 Published : Nov. 7, 2025, 4:15 p.m. | 1 hour, 25 minutes ago Description : There is an arbitrary file download vulnerability in GuoMinJim PersonManage thru commit 5a02b1ab208feacf3a34fc123c9381162afbaa95 (2020-11-23) in the document query function under the Download Center menu in the PersonManage system. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/0chCtFQ via IFTTT

CVE-2025-62066 - WordPress Revolution theme < 2.5.8 - Local File Inclusion vulnerability

CVE ID : CVE-2025-62066 Published : Nov. 6, 2025, 4:16 p.m. | 1 hour, 21 minutes ago Description : Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes Revolution revolution.This issue affects Revolution: from n/a through < 2.5.8. Severity: 7.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/P0194mH via IFTTT

CVE-2025-61304 - "Dynatrace ActiveGate Ping Extension OS Command Injection"

CVE ID : CVE-2025-61304 Published : Nov. 5, 2025, 4:15 p.m. | 1 hour, 18 minutes ago Description : OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/vm4lOVC via IFTTT

CVE-2025-61945 - Missing Authentication for Critical Function in Radiometrics VizAir

CVE ID : CVE-2025-61945 Published : Nov. 4, 2025, 4:10 p.m. | 25 minutes ago Description : Radiometrics VizAir is vulnerable to any remote attacker via access to the admin panel of the VizAir system without authentication. Once inside, the attacker can modify critical weather parameters such as wind shear alerts, inversion depth, and CAPE values, which are essential for accurate weather forecasting and flight safety. This unauthorized access could result in the disabling of vital alerts, causing hazardous conditions for aircraft, and manipulating runway assignments, which could result in mid-air conflicts or runway incursions. Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/ApZSOu3 via IFTTT

CVE-2025-12607 - itsourcecode Online Loan Management System manage_payment.php sql injection

CVE ID : CVE-2025-12607 Published : Nov. 3, 2025, 12:02 a.m. | 1 hour, 26 minutes ago Description : A vulnerability was identified in itsourcecode Online Loan Management System 1.0. Impacted is an unknown function of the file /manage_payment.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/gyKQRZA via IFTTT

CVE-2025-12605 - itsourcecode Online Loan Management System manage_loan.php sql injection

CVE ID : CVE-2025-12605 Published : Nov. 2, 2025, 11:02 p.m. | 25 minutes ago Description : A vulnerability was found in itsourcecode Online Loan Management System 1.0. This vulnerability affects unknown code of the file /manage_loan.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/qF6Qem3 via IFTTT

CVE-2025-12604 - itsourcecode Online Loan Management System load_fields.php sql injection

CVE ID : CVE-2025-12604 Published : Nov. 2, 2025, 10:15 p.m. | 1 hour, 12 minutes ago Description : A vulnerability has been found in itsourcecode Online Loan Management System 1.0. This affects an unknown part of the file /load_fields.php. The manipulation of the argument loan_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/de1afw5 via IFTTT

CVE-2025-12599 - Multiple Devices are Sharing the Same Secrets for SDKSocket (TCP/5000)

CVE ID : CVE-2025-12599 Published : Nov. 1, 2025, 6:39 p.m. | 44 minutes ago Description : Multiple Devices are Sharing the Same Secrets for SDKSocket (TCP/5000).This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/bgIRHuv via IFTTT