CVE-2025-45582 – Apache GNU Tar Directory Traversal Overwrite Vulnerability

GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with […]

CVE-2025-43856 – Immich OAuth2 CSRF Account Hijacking Vulnerability

immich is a high performance self-hosted photo and video management solution. Prior to 1.132.0, immich is vulnerable to account hijacking through oauth2, because the state parameter is not being checked. The oauth2 state parameter is similar to a csrf token, so when the user starts the login flow this unpredictable token is generated and somehow […]

CVE-2024-47065 – Meshtastic Traceroute Rate Limiting Vulnerability

The following table lists the changes that have been made to the CVE-2024-47065 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 11, 2025 Action […]

CVE-2025-7029 – Intel Software SMI Handler Buffer Overflow Vulnerability

The following table lists the changes that have been made to the CVE-2025-7029 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 11, 2025 Action […]

CVE-2025-7028 – Apache Software SMI Handler Pointer Dereference Vulnerability

A vulnerability in the Software SMI handler (SwSmiInputValue 0x20) allows a local attacker to supply a crafted pointer (FuncBlock) through RBX and RCX register values. This pointer is passed unchecked into multiple flash management functions (ReadFlash, WriteFlash, EraseFlash, and GetFlashInfo) that dereference both the structure and its nested members, such as BufAddr. This enables arbitrary […]

CVE-2025-7027 – ASUS Firmware SMM Privilege Escalation Vulnerability

The following table lists the changes that have been made to the CVE-2025-7027 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 11, 2025 Action […]

CVE-2025-7026 – Intel Software SMI Handler Local Privilege Escalation Vulnerability

The following table lists the changes that have been made to the CVE-2025-7026 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 11, 2025 Action […]

CVE-2025-52989 – Juniper Networks Junos OS and Junos OS Evolved Delimiter Injection Vulnerability

An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to modify the system configuration. A user with limited configuration and commit permissions, using a specifically crafted annotate configuration command, can change any part of the device configuration. This issue […]