CVE-2025-29018 – Code Astro Internet Banking System Stored XSS
The following table lists the changes that have been made to the CVE-2025-29018 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 09, 2025 Action […]
CrushFTP Exploitation Continues Amid Disclosure Dispute
CrushFTP Exploitation Continues Amid Disclosure Dispute Source: lumerb via Alamy Stock PhotoExploitation activity continues against a critical vulnerability in CrushFTP file transfer software, which has been mired in an ongoing disclosure dispute.On April … Read more Published Date: Apr 09, 2025 (3 hours, 27 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-31161 CVE-2025-2825
Hackers target SSRF bugs in EC2-hosted sites to steal AWS credentials
Hackers target SSRF bugs in EC2-hosted sites to steal AWS credentials A targeted campaign exploited Server-Side Request Forgery (SSRF) vulnerabilities in websites hosted on AWS EC2 instances to extract EC2 Metadata, which could include Identity and Access Management (IA … Read more Published Date: Apr 09, 2025 (1 hour, 31 minutes ago) Vulnerabilities has been mentioned in this article. […]
CVE-2025-30659 – Juniper Networks Junos OS SRX Series Denial-of-Service (DoS) Vulnerability
An Improper Handling of Length Parameter Inconsistency vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When a device configured for Secure Vector Routing (SVR) receives a specifically malformed packet the PFE will crash and restart. This issue affects […]
CVE-2025-30660 – Juniper Networks Junos OS GRE Traffic Denial-of-Service Vulnerability
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).When processing a high rate of specific GRE traffic destined to the device, the respective PFE will hang causing traffic forwarding to stop. […]
CVE-2025-30658 – Juniper Networks Junos OS SRX Series Anti-Virus Memory Leak Denial-of-Service Vulnerability
A Missing Release of Memory after Effective Lifetime vulnerability in the Anti-Virus processing of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On all SRX platforms with Anti-Virus enabled, if a server sends specific content in the HTTP body of a response to a client request, these […]
CVE-2025-30657 – Juniper Networks Junos OS Denial of Service Vulnerability
An Improper Encoding or Escaping of Output vulnerability in the Sampling Route Record Daemon (SRRD) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When a device configured for flow-monitoring receives a specific BGP update message, it is correctly processed internally by the routing protocol daemon (rpd), but when […]
CVE-2025-30656 – Juniper Junos OS Packet Forwarding Engine Denial-of-Service Memory Corruption
An Improper Handling of Additional Special Element vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series with MS-MPC, MS-MIC and SPC3, and SRX Series, allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If the SIP ALG processes specifically formatted SIP invites, a memory corruption will occur which […]
CVE-2025-30655 – Juniper Networks Junos OS/Junos OS Evolved BGP RPD Denial-of-Service
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to cause a Denial-of-Service (DoS). When a specific “show bgp neighbor” CLI command is run, the rpd cpu utilization rises and eventually causes a crash and restart. […]
CVE-2025-30654 – Juniper Networks Junos OS and Junos OS Evolved Sensitive Information Disclosure
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged, authenticated attacker with access to the CLI to access sensitive information. Through the execution of a specific show mgd command, a user with limited permissions (e.g., a […]