CVE-2025-58067 – Basecamp Google Sign-In Open Redirect Vulnerability

Basecamp’s Google Sign-In adds Google sign-in to Rails applications. Prior to version 1.3.1, it is possible to redirect a user to another origin if the “proceed_to” value in the session store is set to a protocol-relative URL. Normally the value of this URL is only written and read by the library or the calling application. […]

CVE-2025-58066 – Ntpd-rs NTS Protocol Denial of Service Vulnerability

nptd-rs is a tool for synchronizing your computer’s clock, implementing the NTP and NTS protocols. In versions between 1.2.0 and 1.6.1 inclusive servers which allow non-NTS traffic are affected by a denial of service vulnerability, where an attacker can induce a message storm between two NTP servers running ntpd-rs. Client-only configurations are not affected. Affected […]

CVE-2025-56577 – Evope Core Cryptographic Key Disclosure

Affected Products The following products are affected by CVE-2025-56577 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below. No affected product recoded yet

CVE-2024-46484 – TRENDnet TV-IP410 OS Command Injection

Affected Products The following products are affected by CVE-2024-46484 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below. No affected product recoded yet