CISA KEV Catalog Update Part VII – March 2025
CISA KEV Catalog Update Part VII – March 2025 CISA’s add vulnerabilities related to Sitecore CMS and Reviewdog GitHub Actions to its Known Exploited Vulnerabilities (KEV) catalog1. Sitecore CMS VulnerabilitiesCISA has identified critical vulnerab … Read more Published Date: Mar 27, 2025 (4 hours, 29 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-2783 CVE-2025-30154 CVE-2019-9875 […]
CVE-2025-2848: Synology Mail Server Vulnerability Allows Remote Configuration Tampering
CVE-2025-2848: Synology Mail Server Vulnerability Allows Remote Configuration Tampering A recently disclosed vulnerability in Synology Mail Server could allow remote authenticated attackers to tamper with system configurations, potentially impacting the stability of mail services in ente … Read more Published Date: Mar 27, 2025 (2 hours, 20 minutes ago) Vulnerabilities has been mentioned in this article.
Exim Use-After-Free Vulnerability Allows Privilege Escalation
Exim Use-After-Free Vulnerability Allows Privilege Escalation A critical security vulnerability has been identified in the widely used Exim mail transfer agent (MTA), potentially allowing attackers with command-line access to escalate privileges on affected syst … Read more Published Date: Mar 27, 2025 (2 hours, 38 minutes ago) Vulnerabilities has been mentioned in this article.
CVE-2024-45355 – Xiaomi Phone Framework Unauthorized Access Vulnerability
The following table lists the changes that have been made to the CVE-2024-45355 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 27, 2025 Action […]
CVE-2024-45354 – Xiaomi Shop Code Execution Vulnerability
The following table lists the changes that have been made to the CVE-2024-45354 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 27, 2025 Action […]
CVE-2024-45353 – Xiaomi Quick App Framework Intent Redirection Vulnerability
The following table lists the changes that have been made to the CVE-2024-45353 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 27, 2025 Action […]
CISA Warns of Sitecore RCE Flaws; Active Exploits Hit Next.js and DrayTek Devices
CISA Warns of Sitecore RCE Flaws; Active Exploits Hit Next.js and DrayTek Devices Vulnerability / Threat Intelligence The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two six-year-old security flaws impacting Sitecore CMS and Experience Platform (XP) to it … Read more Published Date: Mar 27, 2025 (1 hour, 52 minutes ago) Vulnerabilities has been mentioned […]
Windows Print Glitch Fixed: KB5053657
Windows Print Glitch Fixed: KB5053657 Microsoft released the optional non-security update (KB5053657) to Windows 10 and 11 yesterday. These updates are typically intended for testing purposes and, if found to be stable, are incorporated i … Read more Published Date: Mar 27, 2025 (1 hour, 53 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2024-21410
CVE-2025-2685 – TablePress WordPress Stored Cross-Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2025-2685 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 27, 2025 Action […]
CVE-2025-2332 – WordPress Export All Posts, Products, Orders, Refunds & Users PHP Object Injection Vulnerability
The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.13 via deserialization of untrusted input in the ‘returnMetaValueAsCustomerInput’ function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the […]