CVE-2025-21666 – Linux Kernel vsock Null Pointer Dereference Vulnerability

In the Linux kernel, the following vulnerability has been resolved: vsock: prevent null-ptr-deref in vsock_*[has_data|has_space] Recent reports have shown how we sometimes call vsock_*_has_data() when a vsock socket has been de-assigned from a transport (see attached links), but we shouldn’t. Previous commits should have solved the real problems, but we may have more in the […]

CVE-2025-21667 – XFS Linux Kernel 64-bit Offset Truncation Vulnerability

The following table lists the changes that have been made to the CVE-2025-21667 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Jan. 31, 2025 Action […]

Patient monitors with backdoor are sending info to China, CISA warns

Patient monitors with backdoor are sending info to China, CISA warns Contec CMS8000, a patient monitor manufactured by a Chinese company, and Epsimed MN-120, which is the same monitor but relabeled, exfiltrate patients’ data to a hard-coded IP address and have a backdo … Read more Published Date: Jan 31, 2025 (3 hours, 38 minutes ago) Vulnerabilities […]

Critical Flaws in Contec CMS8000 Allow Remote Code Execution and Patient Data Theft

Critical Flaws in Contec CMS8000 Allow Remote Code Execution and Patient Data Theft A new set of critical vulnerabilities has been identified in Contec Health’s CMS8000 Patient Monitor, posing significant cybersecurity and patient safety risks. These vulnerabilities, which have recei … Read more Published Date: Jan 31, 2025 (4 hours, 24 minutes ago) Vulnerabilities has been mentioned […]

GarageBand-lek laat aanvaller via malafide afbeelding code op macOS uitvoeren

GarageBand-lek laat aanvaller via malafide afbeelding code op macOS uitvoeren Een kwetsbaarheid in Apples muzieksoftware GarageBand maakt het mogelijk voor een aanvaller om via een malafide afbeelding willekeurige code op het systeem uit te voeren. Dat laat Apple in een beveili … Read more Published Date: Jan 31, 2025 (4 hours, 43 minutes ago) Vulnerabilities has been […]

VS waarschuwt voor datalek, backdoor in patiëntenmonitor ziekenhuizen

VS waarschuwt voor datalek, backdoor in patiëntenmonitor ziekenhuizen De Amerikaanse autoriteiten waarschuwen voor een backdoor en een datalek in twee type patiëntenmonitoren die onder andere in ziekenhuizen worden gebruikt. Het gaat om de Contec CMS8000 en Epsimed MN-1 … Read more Published Date: Jan 31, 2025 (5 hours, 13 minutes ago) Vulnerabilities has been mentioned in this […]

CVE-2025-24718 – SWIT WP Sessions Time Monitoring Full Automatic Cross-site Scripting

The following table lists the changes that have been made to the CVE-2025-24718 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 31, 2025 Action […]

CVE-2025-24710 – Gwolle Guestbook Cross-Site Scripting Vulnerability

The following table lists the changes that have been made to the CVE-2025-24710 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 31, 2025 Action […]

CVE-2025-24686 – Metagauss RegistrationMagic Cross-site Scripting

The following table lists the changes that have been made to the CVE-2025-24686 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 31, 2025 Action […]