CVE-2025-40919 – Apache::Authen::DigestMD5 Insecure cnonce Generation Vulnerability
Authen::DigestMD5 versions 0.01 through 0.02 for Perl generate the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from […]
CVE-2025-40918 – Apache::Authen::SASL::Perl DIGEST_MD5 CNonce Weak Randomness Vulnerability
Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from […]
CVE-2025-40913 – Net::Dropbear Integer Overflow in libtommath Library
The following table lists the changes that have been made to the CVE-2025-40913 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 9b29abf9-4ab0-4765-b253-1875cd9b441e Jul. 16, 2025 Action […]
CVE-2025-40776 – BIND Named Cache-Poisoning Vulnerability
The following table lists the changes that have been made to the CVE-2025-40776 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 16, 2025 Action […]
CVE-2025-3871 – Fortra GoAnywhere MFT Authentication Bypass Denial of Service
The following table lists the changes that have been made to the CVE-2025-3871 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by df4dee71-de3a-4139-9588-11b62fe6c0ff Jul. 16, 2025 Action […]
UNC6148 Backdoors Fully-Patched SonicWall SMA 100 Series Devices with OVERSTEP Rootkit
UNC6148 Backdoors Fully-Patched SonicWall SMA 100 Series Devices with OVERSTEP Rootkit A threat activity cluster has been observed targeting fully-patched end-of-life SonicWall Secure Mobile Access (SMA) 100 series appliances as part of a campaign designed to drop a backdoor called OVER … Read more Published Date: Jul 16, 2025 (1 hour, 10 minutes ago) Vulnerabilities has been […]
Update Google Chrome to fix actively exploited zero-day (CVE-2025-6558)
Update Google Chrome to fix actively exploited zero-day (CVE-2025-6558) For the fifth time this year, Google has patched a Chrome zero-day vulnerability (CVE-2025-6558) exploited by attackers in the wild. About CVE-2025-6558 CVE-2025-6558 is a high-severity vulnerability … Read more Published Date: Jul 16, 2025 (1 hour, 39 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-7657 […]
Google’s AI Tool Big Sleep Uncovered Critical SQLite 0-Day Vulnerability and Blocks Active Exploitation
Google’s AI Tool Big Sleep Uncovered Critical SQLite 0-Day Vulnerability and Blocks Active Exploitation Google’s revolutionary AI-powered security tool, Big Sleep, has achieved a groundbreaking milestone by discovering and preventing the exploitation of a critical SQLite 0-day vulnerability, marking the … Read more Published Date: Jul 16, 2025 (1 hour, 40 minutes ago) Vulnerabilities has been mentioned […]
CVE-2025-40923 – Apache Plack-Middleware-Session Insecure Session ID Generation
The following table lists the changes that have been made to the CVE-2025-40923 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 9b29abf9-4ab0-4765-b253-1875cd9b441e Jul. 16, 2025 Action […]
CVE-2025-34300 – Sawtooth Software Lighthouse Studio Template Injection
The following table lists the changes that have been made to the CVE-2025-34300 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0 Jul. 16, 2025 Action Type […]