CVE-2025-32382 – Metabase Snowflake Connection Details Information Exposure
Metabase is an open source Business Intelligence and Embedded Analytics tool. When admins change Snowflake connection details in Metabase (either updating a password or changing password to private key or vice versa), Metabase would not always purge older Snowflake connection details from the application database. In order to remove older and stale connection details, Metabase […]
CVE-2025-29150 – BlueCMS File Deletion Vulnerability
The following table lists the changes that have been made to the CVE-2025-29150 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 10, 2025 Action […]
CVE-2025-0362 – GitLab CE/EE Authorization Bypass Vulnerability
The following table lists the changes that have been made to the CVE-2025-0362 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 10, 2025 Action […]
CVE-2025-32743 – ConnMan DNS Truncated Response Denial of Service/Arbitrary Code Execution Vulnerability
The following table lists the changes that have been made to the CVE-2025-32743 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 10, 2025 Action […]
CVE-2025-32395 – “Vite HTTP Request Target Denial of Service”
Vite is a frontend tooling framework for javascript. Prior to 6.2.6, 6.1.5, 6.0.15, 5.4.18, and 4.5.13, the contents of arbitrary files can be returned to the browser if the dev server is running on Node or Bun. HTTP 1.1 spec (RFC 9112) does not allow # in request-target. Although an attacker can send such a […]
CVE-2025-32391 – HedgeDoc SVG Upload Cross-Site Scripting (XSS)
HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.3, a malicious SVG file uploaded to HedgeDoc results in the possibility of XSS when opened in a new tab instead of the editor itself. The XSS is possible by exploiting the JSONP capabilities of GitHub Gist embeddings. Only instances with the local […]
CVE-2025-32383 – MaxKB Reverse Shell Vulnerability
The following table lists the changes that have been made to the CVE-2025-32383 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 10, 2025 Action […]
CVE-2025-2469 – GitLab Information Disclosure
The following table lists the changes that have been made to the CVE-2025-2469 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 10, 2025 Action […]
CVE-2025-29088 – SQLite Denial of Service Vulnerability
The following table lists the changes that have been made to the CVE-2025-29088 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 10, 2025 Action […]
CVE-2025-29017 – Code Astro Internet Banking System RCE File Upload Validation Bypass
The following table lists the changes that have been made to the CVE-2025-29017 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0 Apr. 10, 2025 Action Type […]