Posts

Showing posts from December, 2025

CVE-2025-68618 - Magick's failure to limit the depth of SVG file reads caused a DoS attack.

CVE ID : CVE-2025-68618 Published : Dec. 30, 2025, 4:14 p.m. | 1 hour, 5 minutes ago Description : ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, using Magick to read a malicious SVG file resulted in a DoS attack. Version 7.1.2-12 fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/7QWq9DK via IFTTT

CVE-2025-57462 - Machsol Machpanel Reflected XSS

CVE ID : CVE-2025-57462 Published : Dec. 29, 2025, 3:16 p.m. | 2 hours ago Description : Reflected Cross site scripting (xss) in machsol machpanel 8.0.32 allows attackers to execute arbitrary web scripts or HTML via a crafted PDF file. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/3vleA2J via IFTTT

CVE-2025-15145 - SohuTV CacheCloud TotalManageController.java doTotalList cross site scripting

CVE ID : CVE-2025-15145 Published : Dec. 28, 2025, 5:16 p.m. | 1 hour, 57 minutes ago Description : A security vulnerability has been detected in SohuTV CacheCloud up to 3.2.0. This affects the function doTotalList of the file src/main/java/com/sohu/cache/web/controller/TotalManageController.java. Such manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/onrzT1j via IFTTT

CVE-2025-14177 - Information Leak of Memory in getimagesize

CVE ID : CVE-2025-14177 Published : Dec. 27, 2025, 8:15 p.m. | 55 minutes ago Description : In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/uwxgDvK via IFTTT

CVE-2025-15109 - jackq XCMS upload.php unrestricted upload

CVE ID : CVE-2025-15109 Published : Dec. 27, 2025, 6:32 p.m. | 39 minutes ago Description : A flaw has been found in jackq XCMS up to 3fab5342cc509945a7ce1b8ec39d19f701b89261. This impacts an unknown function of the file Public/javascripts/admin/plupload-2.1.2/examples/upload.php. This manipulation causes unrestricted upload. It is possible to initiate the attack remotely. The exploit has been published and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/xEQ1hvS via IFTTT

CVE-2025-61914 - n8n's Possible Stored XSS in "Respond to Webhook" Node May Execute Outside iframe Sandbox

CVE ID : CVE-2025-61914 Published : Dec. 26, 2025, 10:15 p.m. | 52 minutes ago Description : n8n is an open source workflow automation platform. Prior to version 1.114.0, a stored Cross-Site Scripting (XSS) vulnerability may occur in n8n when using the “Respond to Webhook” node. When this node responds with HTML content containing executable scripts, the payload may execute directly in the top-level window, rather than within the expected sandbox introduced in version 1.103.0. This behavior can enable a malicious actor with workflow creation permissions to execute arbitrary JavaScript in the context of the n8n editor interface. This issue has been patched in version 1.114.0. Workarounds for this issue involve restricting workflow creation and modification privileges to trusted users only, avoiding use of untrusted HTML responses in the “Respond to Webhook” node, and using an external reverse proxy or HTML sanitizer to filter responses that include executable scripts. Severity...

CVE-2024-42718 - Croogo CMS Path Traversal Vulnerability

CVE ID : CVE-2024-42718 Published : Dec. 26, 2025, 5:15 p.m. | 1 hour, 52 minutes ago Description : A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially crafted path in the 'edit-file' parameter. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/snxoB4N via IFTTT

CVE-2025-15084 - youlaitech youlai-mall Order Payment OrderController.java orderService.payOrder access control

CVE ID : CVE-2025-15084 Published : Dec. 25, 2025, 7:15 p.m. | 44 minutes ago Description : A vulnerability was identified in youlaitech youlai-mall 1.0.0/2.0.0. The impacted element is the function orderService.payOrder of the file mall-oms/oms-boot/src/main/java/com/youlai/mall/oms/controller/app/OrderController.java of the component Order Payment Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is regarded as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 3.1 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/arekfK0 via IFTTT

CVE-2025-15082 - TOZED ZLT M30s Web Management proc_post information disclosure

CVE ID : CVE-2025-15082 Published : Dec. 25, 2025, 5:15 p.m. | 44 minutes ago Description : A vulnerability was found in TOZED ZLT M30s up to 1.47. Impacted is an unknown function of the file /reqproc/proc_post of the component Web Management Interface. Performing manipulation of the argument goformId results in information disclosure. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/XcCZ7GL via IFTTT

CVE-2024-35322 - MyNET Reflected Cross-Site Scripting (XSS) Vulnerability

CVE ID : CVE-2024-35322 Published : Dec. 24, 2025, 4:15 p.m. | 1 hour, 41 minutes ago Description : MyNET up to v26.08 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the ficheiro parameter. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/qZnHUeo via IFTTT

CVE-2024-10398 - Apache Struts Deserialization RCE

CVE ID : CVE-2024-10398 Published : Dec. 23, 2025, 4:16 p.m. | 1 hour, 40 minutes ago Description : Rejected reason: This CVE id was assigned but later discarded. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/421WCuE via IFTTT

CVE-2025-10021 - Open Design Alliance Drawings SDK Uninitialized Variable Use leading to Denial of Service and Potential Arbitrary Code Execution

CVE ID : CVE-2025-10021 Published : Dec. 22, 2025, 4:15 p.m. | 1 hour, 40 minutes ago Description : A Use of Uninitialized Variable vulnerability exists in Open Design Alliance Drawings SDK static versions (mt) before 2026.12. Static object `COdaMfcAppApp theApp` may access `OdString::kEmpty` before its initialization. Due to undefined initialization order of static objects across translation units (Static Initialization Order Fiasco), the application accesses uninitialized memory. This results in application crash on startup, causing denial of service. Due to undefined behavior,  memory corruption and potential arbitrary code execution cannot be ruled out in specific exploitation scenarios. Severity: 7.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/C8q3pSj via IFTTT

CVE-2025-15002 - SeaCMS mysqli.class.php sql injection

CVE ID : CVE-2025-15002 Published : Dec. 21, 2025, 11:15 p.m. | 40 minutes ago Description : A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dmku/class/mysqli.class.php. Such manipulation of the argument page/limit leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/o3B7EHQ via IFTTT

CVE-2025-12700 - Apache Struts Remote Code Execution

CVE ID : CVE-2025-12700 Published : Dec. 20, 2025, 11:15 p.m. | 40 minutes ago Description : Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/cYCJIEs via IFTTT

CVE-2025-34290 - Versa SASE Client for Windows < 7.9.5 Arbitrary Folder Deletion Leading to Local Privilege Escalation

CVE ID : CVE-2025-34290 Published : Dec. 20, 2025, 8:15 p.m. | 1 hour, 40 minutes ago Description : Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerability in the audit log export functionality. The client communicates user-controlled file paths to a privileged service, which performs file system operations without impersonating the requesting user. Due to improper privilege handling and a time-of-check time-of-use race condition combined with symbolic link and mount point manipulation, a local authenticated attacker can coerce the service into deleting arbitrary directories with SYSTEM privileges. This can be exploited to delete protected system folders such as C:\\Config.msi and subsequently achieve execution as NT AUTHORITY\\SYSTEM via MSI rollback techniques. Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabili...

CVE-2025-66906 - Turms Admin API CSRF Privilege Escalation

CVE ID : CVE-2025-66906 Published : Dec. 19, 2025, 4:15 p.m. | 1 hour, 39 minutes ago Description : Cross Site Request Forgery (CSRF) vulnerability in Turms Admin API thru v0.10.0-SNAPSHOT allows attackers to gain escalated privileges. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/jA6uyPS via IFTTT

CVE-2025-14823 - Certificate Signing Extension Returns Encrypted Values

CVE ID : CVE-2025-14823 Published : Dec. 18, 2025, 4:15 p.m. | 1 hour, 39 minutes ago Description : In deployments using the ScreenConnect™ Certificate Signing Extension, encrypted configuration values including an Azure Key Vault-related key, could be returned to unauthenticated users through a client-facing endpoint under certain conditions. The values remained encrypted and securely stored at rest; however, an encrypted representation could be exposed in client responses. Updating the Certificate Signing Extension to version 1.0.12 or higher ensures configuration handling occurs exclusively on the server side, preventing encrypted values from being transmitted to or rendered by client-side components. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/wgukIiJ via IFTTT

CVE-2024-29370 - "Python-Jose: JSON Web Encryption Denial-of-Service Vulnerability"

CVE ID : CVE-2024-29370 Published : Dec. 17, 2025, 4:16 p.m. | 1 hour, 38 minutes ago Description : In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/q2XcYMF via IFTTT

CVE-2025-68322 - parisc: Avoid crash due to unaligned access in unwinder

CVE ID : CVE-2025-68322 Published : Dec. 16, 2025, 4:16 p.m. | 1 hour, 38 minutes ago Description : In the Linux kernel, the following vulnerability has been resolved: parisc: Avoid crash due to unaligned access in unwinder Guenter Roeck reported this kernel crash on his emulated B160L machine: Starting network: udhcpc: started, v1.36.1 Backtrace: [<104320d4>] unwind_once+0x1c/0x5c [<10434a00>] walk_stackframe.isra.0+0x74/0xb8 [<10434a6c>] arch_stack_walk+0x28/0x38 [<104e5efc>] stack_trace_save+0x48/0x5c [<105d1bdc>] set_track_prepare+0x44/0x6c [<105d9c80>] ___slab_alloc+0xfc4/0x1024 [<105d9d38>] __slab_alloc.isra.0+0x58/0x90 [<105dc80c>] kmem_cache_alloc_noprof+0x2ac/0x4a0 [<105b8e54>] __anon_vma_prepare+0x60/0x280 [<105a823c>] __vmf_anon_prepare+0x68/0x94 [<105a8b34>] do_wp_page+0x8cc/0xf10 [<105aad88>] handle_mm_fault+0x6c0/0xf08 [<10425568>] do_page_fault+0x110/0x440 [<10427938>] handl...

CVE-2024-44598 - FNT Command Code Execution Vulnerability

CVE ID : CVE-2024-44598 Published : Dec. 15, 2025, 4:15 p.m. | 1 hour, 38 minutes ago Description : FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/Fmkxj36 via IFTTT

CVE-2025-14667 - itsourcecode COVID Tracking System page sql injection

CVE ID : CVE-2025-14667 Published : Dec. 14, 2025, 4:15 p.m. | 1 hour, 38 minutes ago Description : A security vulnerability has been detected in itsourcecode COVID Tracking System 1.0. The impacted element is an unknown function of the file /admin/?page=system_info. Such manipulation of the argument meta_value leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/78Z3n5W via IFTTT

CVE-2025-67863 - Apache HTTP Server Unvalidated User-Input

CVE ID : CVE-2025-67863 Published : Dec. 13, 2025, 4:16 p.m. | 1 hour, 36 minutes ago Description : Rejected reason: Not used Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/l8PGfAa via IFTTT

CVE-2025-13733 - BuhoNTFS 1.3.2 - Local Privilege Escalation

CVE ID : CVE-2025-13733 Published : Dec. 12, 2025, 4:15 p.m. | 1 hour, 37 minutes ago Description : BuhoNTFS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via insecure functions.This issue affects BuhoNTFS: 1.3.2. Severity: 8.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/DGxei7d via IFTTT

CVE-2025-55313 - Foxit PDF and Editor Arbitrary Code Execution Vulnerability

CVE ID : CVE-2025-55313 Published : Dec. 11, 2025, 4:16 p.m. | 1 hour, 36 minutes ago Description : An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. They allow potential arbitrary code execution when processing crafted PDF files. The vulnerability stems from insufficient handling of memory allocation failures after assigning an extremely large value to a form field's charLimit property via JavaScript. This can result in memory corruption and may allow an attacker to execute arbitrary code by persuading a user to open a malicious file. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/w9sOEvS via IFTTT

CVE-2025-34416 - MailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAIPO.DLL

CVE ID : CVE-2025-34416 Published : Dec. 10, 2025, 4:16 p.m. | 1 hour, 36 minutes ago Description : MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAIPO.DLL from its installation directory without sufficient integrity validation or a secure search order. A local attacker with write access to that directory can plant a malicious MEAIPO.DLL, which is then loaded when the executable starts, resulting in execution of attacker-controlled code with the privileges of the process. Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/gXM6P1y via IFTTT

CVE-2025-63739 - Xinhu Rainrock RockOA PHP Configuration File Modification

CVE ID : CVE-2025-63739 Published : Dec. 9, 2025, 5:15 p.m. | 36 minutes ago Description : An issue was discovered in function phpinisaveAction in file webmain/system/cogini/coginiAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers to authenticated users to modify PHP configuration files via the a parameter to the index.php endpoint. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/tNJR4sl via IFTTT

CVE-2025-48621 - Android DefaultTransitionHandler Tapjacking Vulnerability

CVE ID : CVE-2025-48621 Published : Dec. 8, 2025, 5:16 p.m. | 36 minutes ago Description : In DefaultTransitionHandler.java, there is a possible way to enable a tapjacking attack due to a insecure default. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/9Ju8px3 via IFTTT

CVE-2025-14197 - Verysync 微力同步 Web Administration f96956469e7be39d information disclosure

CVE ID : CVE-2025-14197 Published : Dec. 7, 2025, 4:15 p.m. | 1 hour, 36 minutes ago Description : A security vulnerability has been detected in Verysync 微力同步 up to 2.21.3. The impacted element is an unknown function of the file /rest/f/api/resources/f96956469e7be39d of the component Web Administration Module. Such manipulation leads to information disclosure. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/EBZtOv0 via IFTTT

CVE-2025-40267 - io_uring/rw: ensure allocated iovec gets cleared for early failure

CVE ID : CVE-2025-40267 Published : Dec. 6, 2025, 10:15 p.m. | 1 hour, 35 minutes ago Description : In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: ensure allocated iovec gets cleared for early failure A previous commit reused the recyling infrastructure for early cleanup, but this is not enough for the case where our internal caches have overflowed. If this happens, then the allocated iovec can get leaked if the request is also aborted early. Reinstate the previous forced free of the iovec for that situation. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/720niIf via IFTTT

CVE-2025-14141 - UTT 进取 520W formArpBindConfig strcpy buffer overflow

CVE ID : CVE-2025-14141 Published : Dec. 6, 2025, 4:15 p.m. | 1 hour, 35 minutes ago Description : A flaw has been found in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /goform/formArpBindConfig. Executing manipulation of the argument pools can lead to buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/Wf9JG53 via IFTTT

CVE-2025-66511 - Nextcloud Calendar app used predictable proposal participant tokens

CVE ID : CVE-2025-66511 Published : Dec. 5, 2025, 5:16 p.m. | 32 minutes ago Description : Nextcloud Calendar is a calendar app for Nextcloud. Prior to 6.0.3, the Calendar app generates participant tokens for meeting proposals using a hash function, allowing an attacker to compute valid participant tokens, which allowed them to request details and submit dates in meeting proposals. The tokens are not purely random generated. This vulnerability is fixed in 6.0.3. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/UzNgyr0 via IFTTT

CVE-2025-40259 - scsi: sg: Do not sleep in atomic context

CVE ID : CVE-2025-40259 Published : Dec. 4, 2025, 4:16 p.m. | 1 hour, 29 minutes ago Description : In the Linux kernel, the following vulnerability has been resolved: scsi: sg: Do not sleep in atomic context sg_finish_rem_req() calls blk_rq_unmap_user(). The latter function may sleep. Hence, call sg_finish_rem_req() with interrupts enabled instead of disabled. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/MnRvd4K via IFTTT

CVE-2025-7044 - Privilege Escalation in MAAS via Websocket Request Manipulation

CVE ID : CVE-2025-7044 Published : Dec. 3, 2025, 4:16 p.m. | 1 hour, 26 minutes ago Description : An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged attacker can intercept a user.update websocket request and inject the is_superuser property set to true. The server improperly validates this input, allowing the attacker to self-promote to an administrator role. This results in full administrative control over the MAAS deployment. Severity: 7.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/W1gNZQO via IFTTT

CVE-2025-13631 - Google Chrome Mac Privilege Escalation Vulnerability

CVE ID : CVE-2025-13631 Published : Dec. 2, 2025, 7:15 p.m. | 23 minutes ago Description : Inappropriate implementation in Google Updater in Google Chrome on Mac prior to 143.0.7499.41 allowed a remote attacker to perform privilege escalation via a crafted file. (Chromium security severity: High) Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/XgEGlMo via IFTTT

CVE-2025-3500 - Integer Overflow in Avast Antiviurs 25.1.981.6 on Windows may result in privilege escalation

CVE ID : CVE-2025-3500 Published : Dec. 1, 2025, 4:15 p.m. | 1 hour, 19 minutes ago Description : Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3. Severity: 9.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/5UhBXyW via IFTTT