CVE-2025-54076 – WeGIA Reflected Cross-Site Scripting (XSS)

The following table lists the changes that have been made to the CVE-2025-54076 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 18, 2025 Action […]

CVE-2025-54073 – Microsoft MCP Package Docs Command Injection Vulnerability

mcp-package-docs is an MCP (Model Context Protocol) server that provides LLMs with efficient access to package documentation across multiple programming languages and language server protocol (LSP) capabilities. A command injection vulnerability exists in the `mcp-package-docs` MCP Server prior to the fix in commit cb4ad49615275379fd6f2f1cf1ec4731eec56eb9. The vulnerability is caused by the unsanitized use of input parameters […]

CVE-2025-54059 – Melange SBOM Generation Permissions Vulnerability

The following table lists the changes that have been made to the CVE-2025-54059 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 18, 2025 Action […]

CVE-2025-53945 – Apko File Permission Vulnerability (Root Escalation)

The following table lists the changes that have been made to the CVE-2025-53945 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 18, 2025 Action […]

CVE-2025-53888 – RIOT-OS L2FILTER Add Buffer Overflow

RIOT-OS, an operating system that supports Internet of Things devices, has an ineffective size check implemented with `assert()` can lead to buffer overflow in versions up to and including 2025.04. Assertions are usually compiled out in production builds. If assertions are the only defense against untrusted inputs, the software may be exposed to attacks that […]

CVE-2025-7787 – Xuxueli xxl-job Server-Side Request Forgery (SSRF) Vulnerability

The following table lists the changes that have been made to the CVE-2025-7787 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 18, 2025 Action […]

CVE-2025-7788 – Xuxueli xxl-job OS Command Injection

The following table lists the changes that have been made to the CVE-2025-7788 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 18, 2025 Action […]

CVE-2025-46732 – OpenCTI IDOR Notification Manipulation

The following table lists the changes that have been made to the CVE-2025-46732 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 18, 2025 Action […]

CVE-2025-46000 – Apache Filemanager SVG File Upload RCE

The following table lists the changes that have been made to the CVE-2025-46000 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 18, 2025 Action […]

Hackers scanning for TeleMessage Signal clone flaw exposing passwords

Hackers scanning for TeleMessage Signal clone flaw exposing passwords Researchers are seeing exploitation attempts for the CVE-2025-48927 vulnerability in the TeleMessage SGNL app, which allows retrieving usernames, passwords, and other sensitive data. TeleMessage SGNL … Read more Published Date: Jul 18, 2025 (3 hours, 5 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-48928 CVE-2025-48927