Apple fixes zero-day vulnerability exploited in “extremely sophisticated attack” (CVE-2025-43300)

Apple fixes zero-day vulnerability exploited in “extremely sophisticated attack” (CVE-2025-43300) Apple has fixed yet another vulnerability (CVE-2025-43300) that has apparently been exploited as a zero-day “in an extremely sophisticated attack against specific targeted individuals.” About CVE-2025 … Read more Published Date: Aug 20, 2025 (1 hour, 4 minutes ago) Vulnerabilities has been mentioned in this article.

CVE-2025-9240 – Elunez Eladmin Information Disclosure Vulnerability

The following table lists the changes that have been made to the CVE-2025-9240 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 20, 2025 Action […]

CVE-2024-57152 – My-Site Unauthenticated Access Control Vulnerability

The following table lists the changes that have been made to the CVE-2024-57152 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 20, 2025 Action […]

CVE-2025-43746 – Liferay Portal Liferay DXP Reflected Cross-Site Scripting (XSS)

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.2, 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 allows a remote authenticated attacker to inject JavaScript code via _com_liferay_dynamic_data_mapping_web_portlet_DDMPortlet_portletNamespace and _com_liferay_dynamic_data_mapping_web_portlet_DDMPortlet_namespace parameter.

Apple fixes new zero-day flaw exploited in targeted attacks

Apple fixes new zero-day flaw exploited in targeted attacks Apple has released emergency updates to patch another zero-day vulnerability that was exploited in an “extremely sophisticated attack.” Tracked as CVE-2025-43300, this security flaw is caused by an ou … Read more Published Date: Aug 20, 2025 (1 hour, 43 minutes ago) Vulnerabilities has been mentioned in this […]

CVE-2025-9239 – Elunez Eladmin DES Key Handler Weak Encryption Strength Vulnerability

The following table lists the changes that have been made to the CVE-2025-9239 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 20, 2025 Action […]

CVE-2025-9238 – Swatadru Exam-Seating-Arrangement SQL Injection Vulnerability

The following table lists the changes that have been made to the CVE-2025-9238 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 20, 2025 Action […]

CVE-2025-9237 – CodeAstro Ecommerce Website Cross Site Scripting

The following table lists the changes that have been made to the CVE-2025-9237 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 20, 2025 Action […]

CVE-2025-9236 – Portabilis i-Diario SQL Injection Vulnerability

The following table lists the changes that have been made to the CVE-2025-9236 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 20, 2025 Action […]

CVE-2025-55746 – Directus Unauthenticated File Upload and Modification Vulnerability

The following table lists the changes that have been made to the CVE-2025-55746 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 20, 2025 Action […]