US nuclear weapons agency hacked in Microsoft SharePoint attacks

US nuclear weapons agency hacked in Microsoft SharePoint attacks Unknown threat actors have breached the National Nuclear Security Administration’s network in attacks exploiting a recently patched Microsoft SharePoint zero-day vulnerability chain. NNSA is a semi-au … Read more Published Date: Jul 23, 2025 (3 hours, 27 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-53770

US nuclear weapons agency reportedly hacked in SharePoint attacks

US nuclear weapons agency reportedly hacked in SharePoint attacks Unknown threat actors have reportedly breached the National Nuclear Security Administration’s network in attacks exploiting a recently patched Microsoft SharePoint zero-day vulnerability chain. NNSA i … Read more Published Date: Jul 23, 2025 (1 hour, 25 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-53770

CVE-2025-54090 – Apache HTTP Server Rewrite Condition Evaluation Vulnerability

The following table lists the changes that have been made to the CVE-2025-54090 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 23, 2025 Action […]

CVE-2025-40599 – SonicWall SMA Arbitrary File Upload Vulnerability

The following table lists the changes that have been made to the CVE-2025-40599 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 23, 2025 Action […]

CVE-2025-46099 – Pluck CMS Remote Code Execution Vulnerability

The following table lists the changes that have been made to the CVE-2025-46099 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 23, 2025 Action […]

CVE-2022-4978 – Steppschuh Remote Control Server UDP Keystroke Injection RCE

The following table lists the changes that have been made to the CVE-2022-4978 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 23, 2025 Action […]

CVE-2018-25114 – Apache osCommerce Remote Code Execution Vulnerability

A remote code execution vulnerability exists within osCommerce Online Merchant version 2.3.4.1 due to insecure default configuration and missing authentication in the installer workflow. By default, the /install/ directory remains accessible after installation. An unauthenticated attacker can invoke install_4.php, submit crafted POST data, and inject arbitrary PHP code into the configure.php file. When the application […]

CVE-2018-25113 – Dicoogle PACS Web Server Path Traversal Vulnerability

The following table lists the changes that have been made to the CVE-2018-25113 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 23, 2025 Action […]

CVE-2017-20198 – Apache DC/OS Docker Container Escalation

The following table lists the changes that have been made to the CVE-2017-20198 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 23, 2025 Action […]

CVE-2016-15045 – Deepin lastore-daemon D-Bus Privilege Escalation Vulnerability

A local privilege escalation vulnerability exists in lastore-daemon, the system package manager daemon used in Deepin Linux (developed by Wuhan Deepin Technology Co., Ltd.). In versions 0.9.53-1 (Deepin 15.5) and 0.9.66-1 (Deepin 15.7), the D-Bus configuration permits any user in the sudo group to invoke the InstallPackage method without password authentication. By default, the first […]