CVE-2025-32793 – Cilium Wireguard Transparent Encryption Race Condition

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.15.0 to 1.15.15, 1.16.0 to 1.16.8, and 1.17.0 to 1.17.2, are vulnerable when using Wireguard transparent encryption in a Cilium cluster, packets that originate from a terminating endpoint can leave the source node without encryption due to a race condition in how […]

CVE-2025-32431 – Traefik Path Traversal Vulnerability

Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. In versions prior to 2.11.24, 3.3.6, and 3.4.0-rc2. There is a potential vulnerability in Traefik managing the requests using a PathPrefix, Path or PathRegex matcher. When Traefik is configured to route the requests to a backend using a matcher based on the path, if […]

CVE-2025-28367 – MojoPortal Directory Traversal Vulnerability

The following table lists the changes that have been made to the CVE-2025-28367 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 21, 2025 Action […]

CVE-2024-12543 – OpenText Content Management Barcode Attribute Manipulation

The following table lists the changes that have been made to the CVE-2024-12543 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 21, 2025 Action […]

CVE-2025-2517 – OpenText ArcSight Enterprise Security Manager Domain Reference Leak

The following table lists the changes that have been made to the CVE-2025-2517 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 21, 2025 Action […]

CVE-2025-2298 – Dremio Software File Deletion Authorization Bypass

An improper authorization vulnerability in Dremio Software allows authenticated users to delete arbitrary files that the system has access to, including system files and files stored in remote locations such as S3, Azure Blob Storage, and local filesystems. This vulnerability exists due to insufficient access controls on an API endpoint, enabling any authenticated user to […]

CVE-2025-29660 – Yi IOT XY-3820 Remote Code Execution Vulnerability

The following table lists the changes that have been made to the CVE-2025-29660 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 21, 2025 Action […]

CVE-2025-29659 – Yi IOT XY-3820 Remote Command Execution Vulnerability

The following table lists the changes that have been made to the CVE-2025-29659 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 21, 2025 Action […]

CVE-2025-29287 – MCMS Ueditor Unrestricted File Upload Vulnerability

The following table lists the changes that have been made to the CVE-2025-29287 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 21, 2025 Action […]

CVE-2025-28121 – Code-Projects Online Exam Mastering System XSS Vulnerability

The following table lists the changes that have been made to the CVE-2025-28121 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 21, 2025 Action […]