CVE-2025-58358 – Markdownify Command Injection Vulnerability

Markdownify is a Model Context Protocol server for converting almost anything to Markdown. Versions below 0.0.2 contain a command injection vulnerability, caused by the unsanitized use of input parameters within a call to child_process.exec, enabling an attacker to inject arbitrary system commands. Successful exploitation can lead to remote code execution under the server process’s privileges. […]

CVE-2025-58057 – Netty BrotliDecoder Denial of Service Vulnerability

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In netty-codec-compression versions 4.1.124.Final and below, and netty-codec versions 4.2.4.Final and below, when supplied with specially crafted input, BrotliDecoder and certain other decompression decoders will allocate a large number of reachable byte buffers, which can lead […]

CVE-2025-57833: A New SQL Injection Flaw Puts Django Web Applications at Risk

CVE-2025-57833: A New SQL Injection Flaw Puts Django Web Applications at Risk The Django Software Foundation has released important security updates for multiple supported versions of the popular Python web framework. The patches address a high-severity vulnerability tracked as … Read more Published Date: Sep 04, 2025 (3 hours, 58 minutes ago) Vulnerabilities has been mentioned in […]

CVE-2025-9931 – Jinher OA Cross-Site Scripting Vulnerability

Affected Products The following products are affected by CVE-2025-9931 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below. No affected product recoded yet