CVE-2025-26817 – Netwrix Password Secure OS Command Injection

The following table lists the changes that have been made to the CVE-2025-26817 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 03, 2025 Action […]

CVE-2024-45198 – Insightsoftware Spark JNDI Injection Remote Code Execution

The following table lists the changes that have been made to the CVE-2024-45198 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 03, 2025 Action […]

China-Linked Threat Group Exploits Ivanti Bug

China-Linked Threat Group Exploits Ivanti Bug Source: David Carillet via ShutterstockA likely China-nexus cyber-espionage group is actively exploiting a vulnerability in certain versions of Ivanti’s Connect Secure, Policy Secure, and ZTA gateway … Read more Published Date: Apr 03, 2025 (1 hour, 38 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-22457 CVE-2025-0283 CVE-2025-0282 CVE-2024-38272 CVE-2024-38271 […]

Disclosure Drama Clouds CrushFTP Vulnerability Exploitation

Disclosure Drama Clouds CrushFTP Vulnerability Exploitation Aleksey Funtap via Alamy Stock PhotoA critical CrushFTP vulnerability now under exploitation in the wild has become mired in controversy and confusion.On March 31, the Shadowserver Foundation reported … Read more Published Date: Apr 03, 2025 (2 hours, 1 minute ago) Vulnerabilities has been mentioned in this article. CVE-2025-31161 CVE-2025-2825 CVE-2024-38272 […]

CVE-2025-3175 – Project Worlds Online Lawyer Management System SQL Injection Vulnerability

The following table lists the changes that have been made to the CVE-2025-3175 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 03, 2025 Action […]

CVE-2025-3174 – “Project Worlds Online Lawyer Management System SQL Injection Vulnerability”

The following table lists the changes that have been made to the CVE-2025-3174 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 03, 2025 Action […]

CVE-2025-3173 – Project Worlds Online Lawyer Management System SQL Injection Vulnerability

The following table lists the changes that have been made to the CVE-2025-3173 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 03, 2025 Action […]

CVE-2025-31487 – XWiki JIRA Extension XML External Entity (XXE) Vulnerability

The following table lists the changes that have been made to the CVE-2025-31487 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 03, 2025 Action […]

CVE-2025-31486 – Vite File Disclosure Vulnerability

Vite is a frontend tooling framework for javascript. The contents of arbitrary files can be returned to the browser. By adding ?.svg with ?.wasm?init or with sec-fetch-dest: script header, the server.fs.deny restriction was able to bypass. This bypass is only possible if the file is smaller than build.assetsInlineLimit (default: 4kB) and when using Vite 6.0+. […]

CVE-2025-29647 – SeaCMS SQL Injection

The following table lists the changes that have been made to the CVE-2025-29647 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 03, 2025 Action […]