CVE-2025-52287 – OperaMasks SDK ELite Script Engine RCE via Deserialization

The following table lists the changes that have been made to the CVE-2025-52287 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0 Aug. 22, 2025 Action Type […]

CVE-2025-55581 – D-Link DCS-825L Persistent Root Code Execution Vulnerability

The following table lists the changes that have been made to the CVE-2025-55581 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0 Aug. 22, 2025 Action Type […]

CVE-2025-52085 – Yoosee SQL Injection Vulnerability

An SQL injection vulnerability in Yoosee application v6.32.4 allows authenticated users to inject arbitrary SQL queries via a request to a backend API endpoint. Successful exploitation enables extraction of sensitive database information, including but not limited to, the database server banner and version, current database user and schema, the current DBMS user privileges, and arbitrary […]

CVE-2025-43760 – Liferay Portal Reflected Cross-Site Scripting (XSS)

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.6, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.20 and 7.4 GA through update 92 allows an remote authenticated attacker to inject JavaScript into the PortalUtil.escapeRedirect

CVE-2024-53499 – Jeewms SQL Injection

The following table lists the changes that have been made to the CVE-2024-53499 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 22, 2025 Action […]

CVE-2024-53496 – Apache My-site Unauthenticated Access Control Bypass

The following table lists the changes that have been made to the CVE-2024-53496 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 22, 2025 Action […]

CVE-2024-52786 – Anji-Plus AJ-Report Authentication Bypass Remote Code Execution

The following table lists the changes that have been made to the CVE-2024-52786 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 22, 2025 Action […]

CVE-2024-50645 – MallChat Authentication Bypass

The following table lists the changes that have been made to the CVE-2024-50645 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 22, 2025 Action […]

CVE-2025-57771 – Roo Code Command Injection Vulnerability

The following table lists the changes that have been made to the CVE-2025-57771 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 22, 2025 Action […]

CVE-2025-57800 – Audiobookshelf OpenID Connect Callback URL Redirect Vulnerability

Audiobookshelf is an open-source self-hosted audiobook server. In versions 2.6.0 through 2.26.3, the application does not properly restrict redirect callback URLs during OIDC authentication. An attacker can craft a login link that causes Audiobookshelf to store an arbitrary callback in a cookie, which is later used to redirect the user after authentication. The server then […]