Over 12,000 KerioControl firewalls exposed to exploited RCE flaw

Over 12,000 KerioControl firewalls exposed to exploited RCE flaw Over twelve thousand GFI KerioControl firewall instances are exposed to a critical remote code execution vulnerability tracked as CVE-2024-52875. KerioControl is a network security suite that small an … Read more Published Date: Feb 10, 2025 (2 hours, 47 minutes ago) Vulnerabilities has been mentioned in this article. […]

CVE-2025-25194 – Lemmy ActivityPub Federation SSRF

Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on activitypub_federation, a framework for ActivityPub federation in Rust. This vulnerability, which is present in versions 0.6.2 and prior of activitypub_federation and versions 0.19.8 and prior of Lemmy, allows a user to bypass any predefined hardcoded URL […]

CVE-2025-1162 – Code-Projects Job Recruitment SQL Injection Vulnerability

The following table lists the changes that have been made to the CVE-2025-1162 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 10, 2025 Action […]

CVE-2025-1160 – SourceCodester Employee Management System Default Credentials Vulnerability

The following table lists the changes that have been made to the CVE-2025-1160 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 10, 2025 Action […]

CVE-2025-25193 – Netty Windows Environment File Denial of Service (DoS)

Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including 4.1.118.Final. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts to load a file that does not exist. If an attacker creates such a large […]

CVE-2025-25190 – “ZOO-Project WPS Server XSS EchoProcess Vulnerability”

The ZOO-Project is an open source processing platform. The ZOO-Project Web Processing Service (WPS) Server contains a Cross-Site Scripting (XSS) vulnerability in its EchoProcess service prior to commit 7a5ae1a. The vulnerability exists because the EchoProcess service directly reflects user input in its output without proper sanitization when handling complex inputs.The service accepts various input formats […]

CVE-2025-25189 – ZOO-Project Web Processing Service (WPS) Reflected Cross-Site Scripting Vulnerability

The following table lists the changes that have been made to the CVE-2025-25189 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 10, 2025 Action […]

CVE-2025-24970 – Netty SslHandler Native Crash Vulnerability

The following table lists the changes that have been made to the CVE-2025-24970 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 10, 2025 Action […]

CVE-2025-1159 – CampCodes School Management Software Cross-Site Scripting Vulnerability

The following table lists the changes that have been made to the CVE-2025-1159 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 10, 2025 Action […]

CVE-2025-1158 – ESAfenet CDG SQL Injection Vulnerability

The following table lists the changes that have been made to the CVE-2025-1158 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 10, 2025 Action […]