CVE-2025-3859 – Focus URL Truncation Vulnerability

The following table lists the changes that have been made to the CVE-2025-3859 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 30, 2025 Action […]

CVE-2025-3599 – Symantec Endpoint Protection ERASER Engine Elevation of Privilege Vulnerability

The following table lists the changes that have been made to the CVE-2025-3599 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 30, 2025 Action […]

Commvault Confirms 0-Day Exploit Allowed Hackers Access to Its Azure Environment

Commvault Confirms 0-Day Exploit Allowed Hackers Access to Its Azure Environment Commvault, a leading provider of data protection solutions, has confirmed that a nation-state threat actor breached its Azure environment in February by exploiting a zero-day vulnerability. The compan … Read more Published Date: Apr 30, 2025 (3 hours, 46 minutes ago) Vulnerabilities has been mentioned in […]

Commvault says recent breach didn’t impact customer backup data

Commvault says recent breach didn’t impact customer backup data Commvault, a leading provider of data protection solutions, says a nation-state threat actor who breached its Azure environment didn’t gain access to customer backup data. Listed on NASDAQ since March … Read more Published Date: Apr 30, 2025 (2 hours, 19 minutes ago) Vulnerabilities has been mentioned in […]

CISA Adds SAP NetWeaver Vulnerability to KEV Catalog

CISA Adds SAP NetWeaver Vulnerability to KEV Catalog The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting SAP NetWeaver to its Known Exploited Vulnerabilities (KEV) Catalog, emphasizing the urgency of … Read more Published Date: Apr 30, 2025 (48 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-31324

CVE-2025-4122 – Netgear JWNR2000 Command Injection Vulnerability

The following table lists the changes that have been made to the CVE-2025-4122 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 30, 2025 Action […]

CVE-2025-46342 – Kyverno Namespace Selector Bypass Vulnerability

The following table lists the changes that have been made to the CVE-2025-46342 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 30, 2025 Action […]

CVE-2025-32973 – XWiki Privilege Escalation Vulnerability

XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.8.0-rc-1, when a user with programming rights edits a document in XWiki that was last edited by a user without programming rights and contains an XWiki.ComponentClass, there is no warning that […]

CVE-2025-32972 – XWiki LESS Compiler Script Privilege Escalation Vulnerability

XWiki is a generic wiki platform. In versions starting from 6.1-milestone-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.8.0-rc-1, the script API of the LESS compiler in XWiki is incorrectly checking for rights when calling the cache cleaning API, making it possible to clean the cache without having programming […]