CVE-2025-55000 – OpenBao TOTP Secrets Engine Code Replay Vulnerability
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, OpenBao’s TOTP secrets engine could accept valid codes multiple times rather than strictly-once. This was caused by unexpected normalization in the underlying TOTP library. To work around, ensure that all codes […]
CVE-2025-54999 – OpenBao User Enumeration Vulnerability
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, when using OpenBao’s userpass auth method, user enumeration was possible due to timing difference between non-existent users and users with stored credentials. This is independent of whether the supplied credentials were […]
CVE-2025-54998 – OpenBao Authentication Bypass Vulnerability
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, attackers could bypass the automatic user lockout mechanisms in the OpenBao Userpass or LDAP auth systems. This was caused by different aliasing between pre-flight and full login request user entity alias […]
CVE-2025-54997 – OpenBao Audit Subsystem Privilege Escalation
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, some OpenBao deployments intentionally limit privileged API operators from executing system code or making network connections. However, these operators can bypass both restrictions through the audit subsystem by manipulating log prefixes. […]
28,000+ Microsoft Exchange Servers Vulnerable to CVE-2025-53786 Exposed Online
28,000+ Microsoft Exchange Servers Vulnerable to CVE-2025-53786 Exposed Online Over 28,000 unpatched Microsoft Exchange servers are exposed on the public internet and remain vulnerable to a critical security flaw designated CVE-2025-53786, according to new scanning data released … Read more Published Date: Aug 09, 2025 (1 hour, 4 minutes ago) Vulnerabilities has been mentioned in this article. […]
CVE-2025-55152 – Oak Denial of Service (DoS) Vulnerability
The following table lists the changes that have been made to the CVE-2025-55152 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 09, 2025 Action […]
CVE-2025-54996 – OpenBao Identity Escalation Privilege Vulnerability
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, accounts with access to highly-privileged identity entity systems in root namespaces were able to increase their scope directly to the root policy. While the identity system allowed adding arbitrary policies, which […]
CVE-2025-54888 – Fedify ActivityPub Actor Impersonation Bypass
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. In versions below 1.3.20, 1.4.0-dev.585 through 1.4.12, 1.5.0-dev.636 through 1.5.4, 1.6.0-dev.754 through 1.6.7, 1.7.0-pr.251.885 through 1.7.8 and 1.8.0-dev.909 through 1.8.4, an authentication bypass vulnerability allows any unauthenticated attacker to impersonate any ActivityPub actor by sending forged activities signed with their own keys. […]
CVE-2025-54417 – Craft CMS Remote Code Execution Bypass
The following table lists the changes that have been made to the CVE-2025-54417 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 09, 2025 Action […]
CVE-2025-8744 – CesiumLab Web SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-8744 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 09, 2025 Action […]