CVE-2025-27109 – Solid-js Unescaped User Input Injection Vulnerability

The following table lists the changes that have been made to the CVE-2025-27109 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 21, 2025 Action […]

CVE-2025-27108 – Solid-Meta DOM-Expressions XSS Vulnerability

dom-expressions is a Fine-Grained Runtime for Performant DOM Rendering. In affected versions the use of javascript’s `.replace()` opens up to potential Cross-site Scripting (XSS) vulnerabilities with the special replacement patterns beginning with `$`. Particularly, when the attributes of `Meta` tag from solid-meta are user-defined, attackers can utilise the special replacement patterns, either `$’` or `$“ […]

CVE-2025-27106 – Binance Trading Bot Command Injection Vulnerability

The following table lists the changes that have been made to the CVE-2025-27106 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 21, 2025 Action […]

CVE-2025-27105 – Vyper Smart Contract Language DynArray AugAssign Out-of-Bounds Write

The following table lists the changes that have been made to the CVE-2025-27105 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 21, 2025 Action […]

CVE-2025-27104 – Vyper Smart Contract Iterator Side-Effect Vulnerability

vyper is a Pythonic Smart Contract Language for the EVM. Multiple evaluation of a single expression is possible in the iterator target of a for loop. While the iterator expression cannot produce multiple writes, it can consume side effects produced in the loop body (e.g. read a storage variable updated in the loop body) and […]

CVE-2025-26622 – Vyper EVM sqrt Function Round-Up Vulnerability

The following table lists the changes that have been made to the CVE-2025-26622 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 21, 2025 Action […]

CVE-2019-8900 – Apple SecureROM Local Boot Code Execution Vulnerability

The following table lists the changes that have been made to the CVE-2019-8900 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 21, 2025 Action […]

CVE-2025-25282 – RAGFlow IDOR: Cross-Tenant Access Vulnerability

The following table lists the changes that have been made to the CVE-2025-25282 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 21, 2025 Action […]

CVE-2025-1555 – Hzmanyun Education and Training System Unrestricted File Upload Vulnerability

The following table lists the changes that have been made to the CVE-2025-1555 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 21, 2025 Action […]

Auto-Generated Password Vulnerability In Sitevision Leaks Signing Key

Auto-Generated Password Vulnerability In Sitevision Leaks Signing Key A critical security flaw in Sitevision CMS versions 10.3.1 and older has exposed SAML authentication signing keys, enabling potential authentication bypass and session hijacking. The vulnerability, tr … Read more Published Date: Feb 21, 2025 (1 hour, 53 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2022-35202