CVE-2025-1412 – Mattermost Privilege Escalation Vulnerability

The following table lists the changes that have been made to the CVE-2025-1412 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 24, 2025 Action […]

CVE-2025-0690 – Grub read Command Integer Overflow Vulnerability

The following table lists the changes that have been made to the CVE-2025-0690 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 24, 2025 Action […]

Parallels Desktop 0-Day Vulnerability Gain Root Privileges – PoC Released

Parallels Desktop 0-Day Vulnerability Gain Root Privileges – PoC Released A critical 0-day vulnerability in Parallels Desktop virtualization software has been publicly disclosed, enabling local attackers to escalate privileges to root-level access on macOS systems. All vers … Read more Published Date: Feb 24, 2025 (2 hours, 24 minutes ago) Vulnerabilities has been mentioned in this article. […]

Exim Mail Transfer Vulnerability Let Attackers Inject Malicious SQL Queries

Exim Mail Transfer Vulnerability Let Attackers Inject Malicious SQL Queries Security researchers have uncovered a critical SQL injection vulnerability (CVE-2025-26794) in Exim, the widely-used mail transfer agent (MTA) that powers over 60% of internet mail servers. The flaw e … Read more Published Date: Feb 24, 2025 (2 hours, 40 minutes ago) Vulnerabilities has been mentioned in […]

PoC Exploit Released for F5 BIG-IP Command Injection Vulnerability

PoC Exploit Released for F5 BIG-IP Command Injection Vulnerability Security researchers have released proof-of-concept (PoC) exploit code for CVE-2025-20029, a high-severity command injection vulnerability affecting F5’s BIG-IP application delivery controllers. The f … Read more Published Date: Feb 24, 2025 (2 hours, 44 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-20029

Nagios XI Vulnerability Allows Unauthenticated Users to View Other User Details & Email

Nagios XI Vulnerability Allows Unauthenticated Users to View Other User Details & Email A significant security vulnerability (CVE-2024-54961) has been identified in Nagios XI 2024R1.2.2, enabling unauthenticated attackers to retrieve sensitive user information, including usernames and em … Read more Published Date: Feb 24, 2025 (3 hours, 5 minutes ago) Vulnerabilities has been mentioned in this article. […]

Fluent Bit 0-day Vulnerabilities Exposes Billions of Production Environments to Cyber Attacks

Fluent Bit 0-day Vulnerabilities Exposes Billions of Production Environments to Cyber Attacks Researchers uncovered critical zero-day vulnerabilities in Fluent Bit, a ubiquitous logging utility embedded in cloud infrastructure across major providers like AWS, Google Cloud, and Microsoft Azure. … Read more Published Date: Feb 24, 2025 (3 hours, 9 minutes ago) Vulnerabilities has been mentioned in this […]

UniFi Protect Camera Vulnerability Allows Remote Code Execution Attacks

UniFi Protect Camera Vulnerability Allows Remote Code Execution Attacks Ubiquiti Networks has issued an urgent security advisory addressing five critical vulnerabilities in its UniFi Protect camera ecosystem, including two flaws enabling unauthenticated remote code execut … Read more Published Date: Feb 24, 2025 (2 hours, 5 minutes ago) Vulnerabilities has been mentioned in this article.

CVE-2024-13822 – WordPress Photo Contest Cross-Site Scripting (XSS)

CVE ID : CVE-2024-13822 Published : Feb. 24, 2025, 6:15 a.m. | 1 hour ago Description : The Photo Contest | Competition | Video Contest WordPress plugin through 2.8.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege […]

CVE-2024-13605 – 10Web Form Maker Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2024-13605 Published : Feb. 24, 2025, 6:15 a.m. | 1 hour ago Description : The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is […]