CVE-2025-8528 – Exrick xboot Exposed Sensitive Information Cookie Storage

The following table lists the changes that have been made to the CVE-2025-8528 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 04, 2025 Action […]

CVE-2025-8527 – Exrick xboot Swagger Server-Side Request Forgery (SSRF) Vulnerability

The following table lists the changes that have been made to the CVE-2025-8527 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 04, 2025 Action […]

CVE-2025-7844 – TPM 2.0 Stack Buffer Overflow

The following table lists the changes that have been made to the CVE-2025-7844 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 04, 2025 Action […]

CVE-2025-54554 – Tera Insights tiCrypt Information Disclosure

The following table lists the changes that have been made to the CVE-2025-54554 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 04, 2025 Action […]

CVE-2025-4604 – Liferay Portal/Captcha Bypass Remote Code Execution

The vulnerable code can bypass the Captcha check in Liferay Portal 7.4.3.80 through 7.4.3.132, and Liferay DXP 2024.Q1.1 through 2024.Q1.19, 2024.Q2.0 through 2024.Q2.13, 2024.Q3.0 through 2024.Q3.13, 2024.Q4.0 through 2024.Q4.7, 2025.Q1.0 through 2025.Q1.15 and 7.4 update 80 through update 92 and then attackers can run scripts in the Gogo shell

CVE-2025-4599 – Liferay Portal Liferay DXP Cross-Site Scripting (XSS)

The following table lists the changes that have been made to the CVE-2025-4599 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 04, 2025 Action […]

CVE-2025-8526 – Exrick xBoot Unrestricted File Upload Vulnerability

The following table lists the changes that have been made to the CVE-2025-8526 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 04, 2025 Action […]

CVE-2025-8525 – Exrick xboot Information Disclosure Vulnerability

The following table lists the changes that have been made to the CVE-2025-8525 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 04, 2025 Action […]

CVE-2025-51726 – CyberGhost VPN Weak SHA-1 Signing and Predictable ASLR Vulnerability

CyberGhostVPNSetup.exe (Windows installer) is signed using the weak cryptographic hash algorithm SHA-1, which is vulnerable to collision attacks. This allows a malicious actor to craft a fake installer with a forged SHA-1 certificate that may still be accepted by Windows signature verification mechanisms, particularly on systems without strict SmartScreen or trust policy enforcement. Additionally, the […]

CVE-2025-51387 – GitKraken Desktop Node.js Code Injection Vulnerability

The following table lists the changes that have been made to the CVE-2025-51387 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 04, 2025 Action […]