CVE-2025-21666 – Linux Kernel vsock Null Pointer Dereference Vulnerability
In the Linux kernel, the following vulnerability has been resolved: vsock: prevent null-ptr-deref in vsock_*[has_data|has_space] Recent reports have shown how we sometimes call vsock_*_has_data() when a vsock socket has been de-assigned from a transport (see attached links), but we shouldn’t. Previous commits should have solved the real problems, but we may have more in the […]
CVE-2025-21667 – XFS Linux Kernel 64-bit Offset Truncation Vulnerability
The following table lists the changes that have been made to the CVE-2025-21667 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Jan. 31, 2025 Action […]
Patient monitors with backdoor are sending info to China, CISA warns
Patient monitors with backdoor are sending info to China, CISA warns Contec CMS8000, a patient monitor manufactured by a Chinese company, and Epsimed MN-120, which is the same monitor but relabeled, exfiltrate patients’ data to a hard-coded IP address and have a backdo … Read more Published Date: Jan 31, 2025 (3 hours, 38 minutes ago) Vulnerabilities […]
Critical Flaws in Contec CMS8000 Allow Remote Code Execution and Patient Data Theft
Critical Flaws in Contec CMS8000 Allow Remote Code Execution and Patient Data Theft A new set of critical vulnerabilities has been identified in Contec Health’s CMS8000 Patient Monitor, posing significant cybersecurity and patient safety risks. These vulnerabilities, which have recei … Read more Published Date: Jan 31, 2025 (4 hours, 24 minutes ago) Vulnerabilities has been mentioned […]
GarageBand-lek laat aanvaller via malafide afbeelding code op macOS uitvoeren
GarageBand-lek laat aanvaller via malafide afbeelding code op macOS uitvoeren Een kwetsbaarheid in Apples muzieksoftware GarageBand maakt het mogelijk voor een aanvaller om via een malafide afbeelding willekeurige code op het systeem uit te voeren. Dat laat Apple in een beveili … Read more Published Date: Jan 31, 2025 (4 hours, 43 minutes ago) Vulnerabilities has been […]
VS waarschuwt voor datalek, backdoor in patiëntenmonitor ziekenhuizen
VS waarschuwt voor datalek, backdoor in patiëntenmonitor ziekenhuizen De Amerikaanse autoriteiten waarschuwen voor een backdoor en een datalek in twee type patiëntenmonitoren die onder andere in ziekenhuizen worden gebruikt. Het gaat om de Contec CMS8000 en Epsimed MN-1 … Read more Published Date: Jan 31, 2025 (5 hours, 13 minutes ago) Vulnerabilities has been mentioned in this […]
CVE-2024-13472 – WooCommerce Product Table Lite Plugin Arbitrary Shortcode Execution and Reflected Cross-Site Scripting Vulnerability
CVE ID : CVE-2024-13472 Published : Jan. 31, 2025, 10:15 a.m. | 39 minutes ago Description : The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.9.4. This is due to the software allowing users to execute an action that does not properly […]
CVE-2025-24718 – SWIT WP Sessions Time Monitoring Full Automatic Cross-site Scripting
The following table lists the changes that have been made to the CVE-2025-24718 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 31, 2025 Action […]
CVE-2025-24710 – Gwolle Guestbook Cross-Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2025-24710 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 31, 2025 Action […]
CVE-2025-24686 – Metagauss RegistrationMagic Cross-site Scripting
The following table lists the changes that have been made to the CVE-2025-24686 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 31, 2025 Action […]