CVE-2025-3854 – H3C GR-3000AX HTTP POST Request Handler Buffer Overflow Vulnerability

The following table lists the changes that have been made to the CVE-2025-3854 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 22, 2025 Action […]

CVE-2024-58250 – ppp Passprompt Privilege Escalation Vulnerability

The following table lists the changes that have been made to the CVE-2024-58250 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 22, 2025 Action […]

CVE-2025-21204: SYSTEM-Level Privilege Escalation in Windows Update Stack Exposed, PoC Released

CVE-2025-21204: SYSTEM-Level Privilege Escalation in Windows Update Stack Exposed, PoC Released Image: Elli Shlomo Security researcher Elli Shlomo published the technical details and a proof-of-concept exploit code for CVE-2025-21204, a severe local privilege escalation flaw within the Windows U … Read more Published Date: Apr 22, 2025 (23 minutes ago) Vulnerabilities has been mentioned in this […]

Google Spoofed in Sophisticated DKIM Replay Attack Exploiting Email Trust Mechanisms

Google Spoofed in Sophisticated DKIM Replay Attack Exploiting Email Trust Mechanisms What if an email in your inbox looked exactly like it came from Google—passed all authentication checks, had no spelling errors, came from a Google domain, and even discussed a subpoena involving your … Read more Published Date: Apr 22, 2025 (30 minutes ago) Vulnerabilities […]

CVE-2025-33028: WinZip Flaw Exposes Users to Silent Code Execution via MotW Bypass, No Patch

CVE-2025-33028: WinZip Flaw Exposes Users to Silent Code Execution via MotW Bypass, No Patch A security flaw has been unearthed in WinZip, the popular file compression utility, placing millions of users at risk of silent code execution. Tracked as CVE-2025-33028, this vulnerability enables a … Read more Published Date: Apr 22, 2025 (32 minutes ago) Vulnerabilities […]

FOG Ransomware Campaign Targets Multiple Sectors with Phishing and Payload Obfuscation

FOG Ransomware Campaign Targets Multiple Sectors with Phishing and Payload Obfuscation The initial ransom note dropped that uses DOGE-related references to troll | Image: Trend Micro Trend Micro has identified a recent campaign involving FOG ransomware, demonstrating the adaptability of … Read more Published Date: Apr 22, 2025 (36 minutes ago) Vulnerabilities has been mentioned in […]

Critical CVE-2025-1976 Vulnerability in Brocade Fabric OS Actively Exploited

Critical CVE-2025-1976 Vulnerability in Brocade Fabric OS Actively Exploited A critical security vulnerability has been identified in Brocade Fabric OS, posing a significant risk to affected systems. The vulnerability, tracked as CVE-2025-1976, allows a local user with admin p … Read more Published Date: Apr 22, 2025 (56 minutes ago) Vulnerabilities has been mentioned in this […]

CVE-2025-3849 – YXJ2018 SpringBoot-Vue-OnlineExam Remote Unverified Password Change Vulnerability

The following table lists the changes that have been made to the CVE-2025-3849 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 22, 2025 Action […]

CVE-2025-2987 – IBM Maximo Asset Management SSRF

The following table lists the changes that have been made to the CVE-2025-2987 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 22, 2025 Action […]

RustoBot Botnet Exploits Router Flaws in Sophisticated Attacks

RustoBot Botnet Exploits Router Flaws in Sophisticated Attacks FortiGuard Labs recently discovered RustoBot, written in Rust, a memory-safe language known for its performance and security, a sophisticated botnet exploiting vulnerabilities in TOTOLINK and DrayTek … Read more Published Date: Apr 22, 2025 (1 hour, 6 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2024-12987 CVE-2022-26187 CVE-2022-26210