CVE-2025-47940 – TYPO3 Privileged Access Escalation Vulnerability

TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, administrator-level backend users without system maintainer privileges can escalate their privileges and gain system maintainer access. Exploiting this vulnerability requires a valid administrator account. Users should update […]

CVE-2025-47939 – TYPO3 File Upload Vulnerability (Unrestricted File Type Upload)

TYPO3 is an open source, PHP based web content management system. By design, the file management module in TYPO3’s backend user interface has historically allowed the upload of any file type, with the exception of those that are directly executable in a web server context. This lack of restriction means it is possible to upload […]

CVE-2025-47938 – TYPO3 Password Change Without Verification

TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, the backend user management interface allows password changes without requiring the current password. When an administrator updates their own account or modifies other user accounts […]

CVE-2025-47937 – TYPO3 Table Query Privilege Escalation Vulnerability

TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, when performing a database query involving multiple tables through the database abstraction layer (DBAL), frontend user permissions are only applied via `FrontendGroupRestriction` to the first […]

CVE-2025-45862 – TOTOLINK A3002R Buffer Overflow Vulnerability

The following table lists the changes that have been made to the CVE-2025-45862 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 20, 2025 Action […]

CVE-2024-53359 – Zalo Information Disclosure Vulnerability

The following table lists the changes that have been made to the CVE-2024-53359 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 20, 2025 Action […]

CVE-2025-4978 – Netgear DGND3700 Basic Authentication Remote Authentication Bypass Vulnerability

The following table lists the changes that have been made to the CVE-2025-4978 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 20, 2025 Action […]

CVE-2025-4977 – Netgear DGND3700 Cross-Site Scripting Vulnerability

The following table lists the changes that have been made to the CVE-2025-4977 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 20, 2025 Action […]

CVE-2025-41231 – VMware Cloud Foundation Missing Authorization Vulnerability

The following table lists the changes that have been made to the CVE-2025-41231 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 20, 2025 Action […]

CVE-2025-41229 – VMware Cloud Foundation Directory Traversal Vulnerability

The following table lists the changes that have been made to the CVE-2025-41229 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 20, 2025 Action […]