CVE-2025-55209 – FreePBX UCP is Vulnerable to Stored XSS Through its User Control Panel

contactmanager is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versions 15.0.14 and below, 16.0.0 through 16.0.26.4 and 17.0.0 through 17.0.5, a stored cross-site scripting (XSS) vulnerability in FreePBX allows a low-privileged User Control Panel (UCP) user to inject malicious JavaScript into the system. The malicious […]

CVE-2025-55190 – Argo CD: Project API Token Exposes Repository Credentials

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 through 2.14.15, 3.0.0 through 3.0.12 and 3.1.0-rc1 through 3.1.1, API tokens with project-level permissions are able to retrieve sensitive repository credentials (usernames, passwords) through the project details API endpoint, even when the token only has standard application management […]

CVE-2025-58361 – Promptcraft Forge Studio’s incomplete URL check is vulnerable to XSS via SVG

Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All versions contain an non-exhaustive URL scheme check that does not protect against XSS. User-controlled URLs pass through src/utils/validation.ts, but the check only strips `javascript:` and a few patterns. `data:` URLs (for example data:image/svg+xml,…) still pass. If a sanitized value is used […]

CVE-2025-58353 – Promptcraft Forge Studio: Complete Sanitizer Bypass Enables XSS via Overlapping Patterns

The following table lists the changes that have been made to the CVE-2025-58353 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 04, 2025 Action […]

CVE-2025-32322 – Android MediaProjection Permission Activity Token Grant Vulnerability

The following table lists the changes that have been made to the CVE-2025-32322 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 04, 2025 Action […]

CVE-2025-26439 – Google Talkback Local Privilege Escalation

The following table lists the changes that have been made to the CVE-2025-26439 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 04, 2025 Action […]

CVE-2025-26431 – Android Accessibility Services Local Privilege Escalation

The following table lists the changes that have been made to the CVE-2025-26431 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 04, 2025 Action […]

CVE-2025-26419 – Samsung Android FRP Bypass Vulnerability

The following table lists the changes that have been made to the CVE-2025-26419 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 04, 2025 Action […]

CVE-2025-22415 – Android RCE: Android System Activity Launcher

The following table lists the changes that have been made to the CVE-2025-22415 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 04, 2025 Action […]

CVE-2025-22414 – FrpBypassAlertActivity Local Privilege Escalation

The following table lists the changes that have been made to the CVE-2025-22414 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 04, 2025 Action […]