CVE-2025-53113 – GLPI External Links Information Disclosure

GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 0.65 through 10.0.18, a technician can use the external links feature to fetch information on items they do not have the right to see. […]

CVE-2025-53112 – GLPI Unauthorized Resource Deletion Vulnerability

The following table lists the changes that have been made to the CVE-2025-53112 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 30, 2025 Action […]

CVE-2025-53111 – GLPI Unauthenticated Access Vulnerability

The following table lists the changes that have been made to the CVE-2025-53111 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 30, 2025 Action […]

CVE-2025-46811 – SUSE Manager WebSocket Root RCE

The following table lists the changes that have been made to the CVE-2025-46811 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 30, 2025 Action […]

CVE-2025-43018 – HP LaserJet Pro Printer Information Disclosure Vulnerability

The following table lists the changes that have been made to the CVE-2025-43018 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 30, 2025 Action […]

CVE-2024-45515 – Zimbra Collaboration Cross-Site Scripting (XSS)

The following table lists the changes that have been made to the CVE-2024-45515 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 30, 2025 Action […]

New Lenovo UEFI firmware updates fix Secure Boot bypass flaws

New Lenovo UEFI firmware updates fix Secure Boot bypass flaws Lenovo is warning of high-severity BIOS flaws that could let attackers bypass Secure Boot on all-in-one desktops using customized Insyde UEFI firmware. Devices confirmed to be impacted are IdeaCentre … Read more Published Date: Jul 30, 2025 (2 hours, 19 minutes ago) Vulnerabilities has been mentioned in […]

CVE-2025-54425 – Umbraco Content Delivery API Cache Bypass Vulnerability

Umbraco is an ASP.NET CMS. In versions 13.0.0 through 13.9.2, 15.0.0 through 15.4.1 and 16.0.0 through 16.1.0, the content delivery API can be restricted from public access where an API key must be provided in a header to authorize the request. It’s also possible to configure output caching, such that the delivery API outputs will […]

CVE-2025-54572 – Apache Ruby SAML Denial-of-Service Vulnerability

The following table lists the changes that have been made to the CVE-2025-54572 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 30, 2025 Action […]

CVE-2025-54430 – Apache Dedupe GitHub Token Exfiltration

dedupe is a python library that uses machine learning to perform fuzzy matching, deduplication and entity resolution quickly on structured data. Before commit 3f61e79, a critical severity vulnerability has been identified within the .github/workflows/benchmark-bot.yml workflow, where a issue_comment can be triggered using the @benchmark body. This workflow is susceptible to exploitation as it checkout the […]