CVE-2025-36904 – Apache Tomcat Remote Code Execution

Affected Products The following products are affected by CVE-2025-36904 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below. No affected product recoded yet

CVE-2025-43772 – Liferay Portal Liferay DXP DoS Memory Consumption Vulnerability

Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older unsupported versions does not restrict the saving of request parameters in the portlet session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP request.

Chinese APT Hackers Exploit Router Vulnerabilities to Infiltrate Enterprise Environments

Chinese APT Hackers Exploit Router Vulnerabilities to Infiltrate Enterprise Environments Over the past several years, a concerted campaign by Chinese state-sponsored Advanced Persistent Threat (APT) groups has exploited critical vulnerabilities in enterprise-grade routers to establish lon … Read more Published Date: Sep 04, 2025 (2 hours, 51 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2024-3400 […]

Cato Networks acquires Aim Security to bring AI protection into SASE Cloud

Cato Networks acquires Aim Security to bring AI protection into SASE Cloud Cato Networks acquired Aim Security to further enhance the Cato SASE Cloud Platform, supporting secure enterprise adoption of AI agents and both public and private AI applications. Cato has now exceed … Read more Published Date: Sep 04, 2025 (2 hours, 18 minutes ago) Vulnerabilities […]

CVE-2025-58357 – 5ire Cross-Platform Desktop AI Assistant Content Injection Vulnerability

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Version 0.13.2 contains a vulnerability in the chat page’s script gadgets that enables content injection attacks through multiple vectors: malicious prompt injection pages, compromised MCP servers, and exploited tool integrations. This is fixed in version 0.14.0.