CVE-2025-54879 – Mastodon LDAP Rate Limiting Email Confirmation Path Bypass Vulnerability

Mastodon is a free, open-source social network server based on ActivityPub Mastodon which facilitates LDAP configuration for authentication. In versions 3.1.5 through 4.2.24, 4.3.0 through 4.3.11 and 4.4.0 through 4.4.3, Mastodon’s rate-limiting system has a critical configuration error where the email-based throttle for confirmation emails incorrectly checks the password reset path instead of the confirmation […]

CVE-2025-54876 – Janssen Project PlainText Password Storage Vulnerability

The following table lists the changes that have been made to the CVE-2025-54876 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 06, 2025 Action […]

CVE-2025-54873 – RISC Zero RISC-V Arithmetic Overflow/Underflow

The following table lists the changes that have been made to the CVE-2025-54873 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 06, 2025 Action […]

CVE-2025-54872 – “Onion-Site-Template Tor Image Exposure Vulnerability”

The following table lists the changes that have been made to the CVE-2025-54872 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 06, 2025 Action […]

CVE-2025-54869 – FPDI PDF DoS Vulnerability

The following table lists the changes that have been made to the CVE-2025-54869 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 06, 2025 Action […]

CVE-2025-54801 – Fiber Ctx.BodyParser Slice Index Overflow/Exhaustion Vulnerability

Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and below, when using Fiber’s Ctx.BodyParser to parse form data containing a large numeric key that represents a slice index (e.g., test.18446744073704), the application crashes due to an out-of-bounds slice allocation in the underlying schema decoder. The root cause is that the […]

CVE-2025-54594 – React Native Bottom Tabs GitHub Actions Code Execution

react-native-bottom-tabs is a library of Native Bottom Tabs for React Native. In versions 0.9.2 and below, the github/workflows/release-canary.yml GitHub Actions repository workflow improperly used the pull_request_target event trigger, which allowed for untrusted code from a forked pull request to be executed in a privileged context. An attacker could create a pull request containing a malicious […]

CVE-2025-54125 – XWiki Platform XML Export Information Disclosure Vulnerability

The following table lists the changes that have been made to the CVE-2025-54125 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 06, 2025 Action […]

CVE-2025-54124 – XWiki Platform Password Hash Disclosure Vulnerability

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform Old Core versions 9.8-rc-1 through 16.4.6, 16.5.0-rc-1 through 16.10.4, and 17.0.0-rc-1 through 17.1.0, any user with editing rights can create an XClass with a database list property that references a […]