SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version

SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version Vulnerability / IT Service Cybersecurity researchers have disclosed multiple security flaw in the on-premise version of SysAid IT support software that could be exploited to achieve pre-authenticated … Read more Published Date: May 07, 2025 (2 hours, 39 minutes ago) Vulnerabilities has been mentioned in this […]

Critical Langflow Vulnerability (CVE-2025-3248) Actively Exploited, Warns CISA

Critical Langflow Vulnerability (CVE-2025-3248) Actively Exploited, Warns CISA CISA warns of active exploitation of critical Langflow vulnerability (CVE-2025-3248). Critical RCE flaw allows full server takeover. Patch to version 1.3.0 now! In April 2025, cybersecurity researcher … Read more Published Date: May 07, 2025 (2 hours, 41 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-3248

CVE-2025-33093 – IBM Sterling Partner Engagement Manager Exposed JWT Secret Vulnerability

The following table lists the changes that have been made to the CVE-2025-33093 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 07, 2025 Action […]

Zero-Day CLFS Vulnerability (CVE-2025-29824) Exploited in Ransomware Attacks

Zero-Day CLFS Vulnerability (CVE-2025-29824) Exploited in Ransomware Attacks Symantec’s Threat Hunter Team has uncovered a sophisticated attack involving a zero-day privilege escalation vulnerability in Microsoft’s Common Log File System (CLFS) driver — CVE-2025-29824 — active … Read more Published Date: May 07, 2025 (3 hours, 18 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-29824 CVE-2024-26169 […]

Play Ransomware Exploited Windows CVE-2025-29824 as Zero-Day to Breach U.S. Organization

Play Ransomware Exploited Windows CVE-2025-29824 as Zero-Day to Breach U.S. Organization Threat actors with links to the Play ransomware family exploited a recently patched security flaw in Microsoft Windows as a zero-day as part of an attack targeting an unnamed organization in the Unite … Read more Published Date: May 07, 2025 (3 hours, 26 minutes ago) […]

CVE-2025-4104 – WordPress Frontend Dashboard Privilege Escalation

CVE ID : CVE-2025-4104 Published : May 7, 2025, 10:15 a.m. | 1 hour, 24 minutes ago Description : The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_wp_ajax_fed_login_form_post() function in versions 1.0 to 2.2.6. This makes it possible for unauthenticated attackers to reset the administrator’s email […]

Microsoft: April updates cause Windows Server auth issues

Microsoft: April updates cause Windows Server auth issues Microsoft says the April 2025 security updates are causing authentication issues on some Windows Server 2025 domain controllers. The list of impacted platforms includes Windows Server 2016, Windows Se … Read more Published Date: May 07, 2025 (2 hours, 1 minute ago) Vulnerabilities has been mentioned in this article. […]

Actively exploited FreeType flaw fixed in Android (CVE-2025-27363)

Actively exploited FreeType flaw fixed in Android (CVE-2025-27363) Google has released fixes for a bucketload of Android security vulnerabilities, including a FreeType flaw (CVE-2025-27363) that “may be under limited, targeted exploitation.” About CVE-2025-27363 CVE- … Read more Published Date: May 07, 2025 (2 hours, 4 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-3248 CVE-2025-27363 CVE-2024-7399

CVE-2025-39361 – WProyal Royal Elementor Addons Cross-site Scripting (XSS)

The following table lists the changes that have been made to the CVE-2025-39361 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 07, 2025 Action […]

CVE-2025-20980 – Android libsavscmn Out-of-Bounds Write

The following table lists the changes that have been made to the CVE-2025-20980 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 07, 2025 Action […]