Alert: Malicious RubyGems Impersonate Fastlane Plugins, Steal CI/CD Data

Alert: Malicious RubyGems Impersonate Fastlane Plugins, Steal CI/CD Data Socket’s Threat Research Team has uncovered a targeted supply chain attack leveraging malicious RubyGems impersonating Fastlane plugins. The attackers exploited heightened demand for Telegram workarou … Read more Published Date: Jun 04, 2025 (1 hour, 15 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2023-22794 CVE-2021-33621

CVE-2025-5547 – FreeFloat FTP Server CDUP Command Handler Buffer Overflow Vulnerability

The following table lists the changes that have been made to the CVE-2025-5547 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jun. 04, 2025 Action […]

CVE-2025-5546 – PHPGurukul Daily Expense Tracker System SQL Injection Vulnerability

The following table lists the changes that have been made to the CVE-2025-5546 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jun. 04, 2025 Action […]

CVE-2025-5545 – Aluoxiang OA System Path Traversal Vulnerability

The following table lists the changes that have been made to the CVE-2025-5545 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jun. 04, 2025 Action […]

CVE-2025-5544 – Aluoxiang OA System Path Traversal Vulnerability

The following table lists the changes that have been made to the CVE-2025-5544 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jun. 03, 2025 Action […]

CVE-2025-24015 – Deno AES-GCM Authentication Tag Validation Bypass

Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Versions 1.46.0 through 2.1.6 have an issue that affects AES-256-GCM and AES-128-GCM in Deno in which the authentication tag is not being validated. This means tampered ciphertexts or incorrect keys might not be detected, which breaks the guarantees expected from AES-GCM. Older versions of […]

CVE-2025-5543 – TOTOLINK X2000R Cross-Site Scripting Vulnerability in Parent Controls Page

The following table lists the changes that have been made to the CVE-2025-5543 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jun. 03, 2025 Action […]