CVE-2023-26226 – Yandex Browser for Desktop Use-After-Free Memory Corruption Vulnerability

The following table lists the changes that have been made to the CVE-2023-26226 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 30, 2025 Action […]

CVE-2025-5357 – FreeFloat FTP Server PWD Command Handler Buffer Overflow

The following table lists the changes that have been made to the CVE-2025-5357 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 30, 2025 Action […]

CVE-2025-5356 – FreeFloat FTP Server BYE Command Handler Buffer Overflow Vulnerability

The following table lists the changes that have been made to the CVE-2025-5356 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 30, 2025 Action […]

May 2025 Patch Tuesday: Five Zero-Days and Five Critical Vulnerabilities Among 72 CVEs

May 2025 Patch Tuesday: Five Zero-Days and Five Critical Vulnerabilities Among 72 CVEs Microsoft has addressed 72 vulnerabilities in its May 2025 security update release. This month’s patches include fixes for five actively exploited zero-day vulnerabilities, including a zero-day vulner … Read more Published Date: May 30, 2025 (43 minutes ago) Vulnerabilities has been mentioned in […]

CVE-2024-42191 – HCL Traveler for Microsoft Outlook COM Hijacking Vulnerability

The following table lists the changes that have been made to the CVE-2024-42191 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 30, 2025 Action […]

CVE-2024-42190 – HCL Traveler for Microsoft Outlook DLL Hijacking Vulnerability

The following table lists the changes that have been made to the CVE-2024-42190 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 30, 2025 Action […]

CVE-2024-23589 – HCL Glovius Cloud Hash Algorithm Weakness

The following table lists the changes that have been made to the CVE-2024-23589 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 30, 2025 Action […]

CVE-2024-13917 – Kruger&Matz Applock System Privilege Escalation Vulnerability

An application “com.pri.applock”, which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data. Exposed ”com.pri.applock.LockUI“ activity allows any other malicious application, with no granted Android system permissions, to inject an arbitrary intent with system-level privileges to a protected application. One must know the protecting PIN […]

CVE-2024-13916 – Kruger&Matz com.pri.applock Fingerprint PIN Code Exfiltration

An application “com.pri.applock”, which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data. Exposed ”com.android.providers.settings.fingerprint.PriFpShareProvider“ content provider’s public method query() allows any other malicious application, without any granted Android system permissions, to exfiltrate the PIN code. Vendor did not provide information about vulnerable versions. Only […]

CVE-2024-13915 – Ulefone and Krüger&Matz Android Smartphones Factory Reset Service Remote Code Execution Vulnerability

The following table lists the changes that have been made to the CVE-2024-13915 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 30, 2025 Action […]