CVE-2025-57819 – FreePBX Unauthenticated Remote Code Execution Vulnerability
The following table lists the changes that have been made to the CVE-2025-57819 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 28, 2025 Action […]
CVE-2025-58334 – JetBrains IDE Services Privilege Escalation Vulnerability
The following table lists the changes that have been made to the CVE-2025-58334 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 28, 2025 Action […]
CVE-2025-57759 – Contao Unauthenticated Permission Bypass Vulnerability
The following table lists the changes that have been made to the CVE-2025-57759 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 28, 2025 Action […]
CVE-2025-57758 – Contao Table Access Voter Privilege Escalation Vulnerability
The following table lists the changes that have been made to the CVE-2025-57758 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 28, 2025 Action […]
CVE-2025-57757 – Contao RSS Feed Information Disclosure Vulnerability
The following table lists the changes that have been made to the CVE-2025-57757 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 28, 2025 Action […]
CVE-2025-57756 – Contao Information Disclosure Vulnerability
Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected content elements that are rendered as fragments are indexed and become publicly available in the front end search. This issue has been patched in versions 4.13.56, 5.3.38, and 5.6.1. A workaround involves disabling the front end […]
CVE-2025-31979 – HCL BigFix SM File Upload Validation Bypass
A File Upload Validation Bypass vulnerability has been identified in the HCL BigFix SM, where the application fails to properly enforce file type restrictions during the upload process. An attacker may exploit this flaw to upload malicious or unauthorized files, such as scripts, executables, or web shells, by bypassing client-side or server-side validation mechanisms.
CVE-2025-31977 – HCL BigFix SM Cryptographic Weakness
The following table lists the changes that have been made to the CVE-2025-31977 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 28, 2025 Action […]
CVE-2025-31972 – HCL BigFix SM Sensitive Information Exposure
The following table lists the changes that have been made to the CVE-2025-31972 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 28, 2025 Action […]
BadSuccessor Post-Patch: Leveraging dMSAs for Credential Acquisition and Lateral Movement in Active Directory
BadSuccessor Post-Patch: Leveraging dMSAs for Credential Acquisition and Lateral Movement in Active Directory Microsoft’s recent patch for the BadSuccessor vulnerability (CVE-2025-53779) has successfully closed the direct privilege escalation path, but security researchers warn that the underlying technique r … Read more Published Date: Aug 28, 2025 (2 hours, 16 minutes ago) Vulnerabilities has been mentioned in this […]