CVE-2025-30196 – Jenkins AnchorChain Plugin Stored XSS
The following table lists the changes that have been made to the CVE-2025-30196 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 19, 2025 Action […]
CVE-2025-30153 – Kin-OpenAPI Multipart Form Data ZIP Bomb Denial of Service
kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131.0, when validating a request with a multipart/form-data schema, if the OpenAPI schema allows it, an attacker can upload a crafted ZIP file (e.g., a ZIP bomb), causing the server to consume all available system memory. The root cause comes from the ZipFileBodyDecoder, which […]
CVE-2025-30152 – Sylius PayPal Plugin Cart Manipulation Vulnerability
The Syliud PayPal Plugin is the Sylius Core Team’s plugin for the PayPal Commerce Platform. Prior to 1.6.2, 1.7.2, and 2.0.2, a discovered vulnerability allows users to modify their shopping cart after completing the PayPal Checkout process and payment authorization. If a user initiates a PayPal transaction from a product page or the cart page […]
CVE-2025-30144 – Fast-JWT Iss Claim Array Vulnerability
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 5.0.6, the fast-jwt library does not properly validate the iss claim based on the RFC 7519. The iss (issuer) claim validation within the fast-jwt library permits an array of strings as a valid iss value. This design flaw enables a potential attack where a malicious […]
CVE-2025-2324 – Progress MOVEit Transfer SFTP Module Privilege Escalation Vulnerability
The following table lists the changes that have been made to the CVE-2025-2324 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 19, 2025 Action […]
CVE-2025-29783 – vLLM Mooncake Remote Code Execution
The following table lists the changes that have been made to the CVE-2025-29783 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 19, 2025 Action […]
CVE-2025-29770 – OpenAI vLLM Outlines Cache Denial of Service Vulnerability
The following table lists the changes that have been made to the CVE-2025-29770 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 19, 2025 Action […]
CVE-2025-29401 – Emlog Pro Remote Code Execution
The following table lists the changes that have been made to the CVE-2025-29401 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 19, 2025 Action […]
CVE-2025-29137 – Tenda AC7 Buffer Overflow RCE
The following table lists the changes that have been made to the CVE-2025-29137 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 19, 2025 Action […]
CVE-2025-26486 – Beta80 Life 1st Cryptographic Hashing Weakness
The following table lists the changes that have been made to the CVE-2025-26486 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by a6d3dc9e-0591-4a13-bce7-0f5b31ff6158 Mar. 19, 2025 Action […]