CVE-2025-29018 – Code Astro Internet Banking System Stored XSS

The following table lists the changes that have been made to the CVE-2025-29018 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 09, 2025 Action […]

CrushFTP Exploitation Continues Amid Disclosure Dispute

CrushFTP Exploitation Continues Amid Disclosure Dispute Source: lumerb via Alamy Stock PhotoExploitation activity continues against a critical vulnerability in CrushFTP file transfer software, which has been mired in an ongoing disclosure dispute.On April … Read more Published Date: Apr 09, 2025 (3 hours, 27 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-31161 CVE-2025-2825

Hackers target SSRF bugs in EC2-hosted sites to steal AWS credentials

Hackers target SSRF bugs in EC2-hosted sites to steal AWS credentials A targeted campaign exploited Server-Side Request Forgery (SSRF) vulnerabilities in websites hosted on AWS EC2 instances to extract EC2 Metadata, which could include Identity and Access Management (IA … Read more Published Date: Apr 09, 2025 (1 hour, 31 minutes ago) Vulnerabilities has been mentioned in this article. […]

CVE-2025-30659 – Juniper Networks Junos OS SRX Series Denial-of-Service (DoS) Vulnerability

An Improper Handling of Length Parameter Inconsistency vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When a device configured for Secure Vector Routing (SVR) receives a specifically malformed packet the PFE will crash and restart. This issue affects […]

CVE-2025-30660 – Juniper Networks Junos OS GRE Traffic Denial-of-Service Vulnerability

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).When processing a high rate of specific GRE traffic destined to the device, the respective PFE will hang causing traffic forwarding to stop. […]

CVE-2025-30657 – Juniper Networks Junos OS Denial of Service Vulnerability

An Improper Encoding or Escaping of Output vulnerability in the Sampling Route Record Daemon (SRRD) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When a device configured for flow-monitoring receives a specific BGP update message, it is correctly processed internally by the routing protocol daemon (rpd), but when […]

CVE-2025-30655 – Juniper Networks Junos OS/Junos OS Evolved BGP RPD Denial-of-Service

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to cause a Denial-of-Service (DoS). When a specific “show bgp neighbor” CLI command is run, the rpd cpu utilization rises and eventually causes a crash and restart. […]