CVE-2025-2476 – Google Chrome Lens Use-After-Free Vulnerability

The following table lists the changes that have been made to the CVE-2025-2476 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 19, 2025 Action […]

CVE-2025-2536 – Liferay Portal Cross-Site Scripting (XSS) Vulnerability

Cross-site scripting (XSS) vulnerability on Liferay Portal 7.4.3.82 through 7.4.3.128, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 82 through update 92 in the Frontend JS module’s layout-taglib/__liferay__/index.js allows remote attackers to inject arbitrary web script or HTML via toastData parameter

CVE-2025-27704 – Absolute Secure Access Cross-Site Scripting Vulnerability

There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.53. Attackers with system administrator permissions can interfere with another system administrator’s use of the management console when the second administrator logs in. Attack complexity is high, attack requirements are present, privileges required are none, user […]

CVE-2025-27415 – Nuxt CDN Cache Poisoning Vulnerability

The following table lists the changes that have been made to the CVE-2025-27415 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 19, 2025 Action […]

CVE-2024-7631 – OpenShift Console Directory Traversal Vulnerability

The following table lists the changes that have been made to the CVE-2024-7631 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 19, 2025 Action […]

CVE-2024-57061 – Termius Electron Fuses Code Execution Vulnerability

The following table lists the changes that have been made to the CVE-2024-57061 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 19, 2025 Action […]

CVE-2024-51459 – IBM InfoSphere Information Server Privilege Escalation Vulnerability

The following table lists the changes that have been made to the CVE-2024-51459 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 19, 2025 Action […]

CVE-2025-29925 – XWiki Platform Information Disclosure Vulnerability

XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, protected pages are listed when requesting the REST endpoints /rest/wikis/[wikiName]/pages even if the user doesn’t have view rights on them. It’s particularly true if the entire wiki is protected with “Prevent unregistered user to view pages”: the endpoint would still list the […]

CVE-2025-29924 – XWiki Platform Unauthenticated Information Disclosure Vulnerability

XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, it’s possible for an user to get access to private information through the REST API – but could also be through another API – when a sub wiki is using “Prevent unregistered users to view pages”. The vulnerability only affects subwikis, and […]