CVE-2025-32031 – Apollo Gateway Denial of Service Vulnerability
Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL endpoint. Prior to 2.10.1, a vulnerability in Apollo Gateway allowed queries with deeply nested and reused named fragments to be prohibitively expensive to query plan, specifically due to internal optimizations being frequently bypassed. The query planner includes an optimization that significantly speeds […]
CVE-2025-32030 – Apollo Gateway Nested Fragment Denial of Service Vulnerability
The following table lists the changes that have been made to the CVE-2025-32030 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 07, 2025 Action […]
CVE-2025-31496 – Apollo Compiler Named Fragment Denial of Service Vulnerability
The following table lists the changes that have been made to the CVE-2025-31496 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 07, 2025 Action […]
CVE-2025-32029 – Apache TS ASN1 DER Denial of Service Vulnerability
The following table lists the changes that have been made to the CVE-2025-32029 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 07, 2025 Action […]
ToddyCat APT Targets ESET Bug to Load Silent Malware
ToddyCat APT Targets ESET Bug to Load Silent Malware Source: DSlight_photography via ShutterstockThe Chinese-speaking ToddyCat advanced persistent threat (APT) group is targeting a security vulnerability in ESET’s antivirus software to silently execute … Read more Published Date: Apr 07, 2025 (2 hours, 1 minute ago) Vulnerabilities has been mentioned in this article. CVE-2024-11859 CVE-2021-36276
CVE-2025-3382 – Joey-Zhou Xiaozhi-ESP32-Server-Java SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-3382 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 07, 2025 Action […]
CVE-2025-3381 – Zhangyanbo2007 Youkefu File Upload Java Path Traversal Vulnerability
The following table lists the changes that have been made to the CVE-2025-3381 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 07, 2025 Action […]
CVE-2025-29769 – Libvips HEIF Alpha Channel Buffer Overflow
libvips is a demand-driven, horizontally threaded image processing library. The heifsave operation could incorrectly determine the presence of an alpha channel in an input when it was not possible to determine the colour interpretation, known internally within libvips as “multiband”. There aren’t many ways to create a “multiband” input, but it is possible with a […]
CVE-2025-29594 – Apache CS2-WeaponPaints Website Unvalidated Input XSS
The following table lists the changes that have been made to the CVE-2025-29594 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 07, 2025 Action […]
CVE-2025-29482 – Libheif Buffer Overflow Arbitrary Code Execution
The following table lists the changes that have been made to the CVE-2025-29482 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 07, 2025 Action […]