CISA Warns of Linux Kernel Race Condition Vulnerability Exploited in Attacks

CISA Warns of Linux Kernel Race Condition Vulnerability Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a new high-severity vulnerability in the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, signaling that it … Read more Published Date: Sep 05, 2025 (1 hour, 58 minutes ago) Vulnerabilities has been mentioned in […]

CVE-2025-48395 – Eaton NMC G2 File Traversal Vulnerability

The following table lists the changes that have been made to the CVE-2025-48395 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 05, 2025 Action […]

September 2025 Patch Tuesday forecast: The CVE matrix

September 2025 Patch Tuesday forecast: The CVE matrix We work in an industry driven by Common Vulnerabilities and Exposures (CVE). Each security update released by myriad vendors addresses some flaw in software that could be exploited and those flaws tha … Read more Published Date: Sep 05, 2025 (2 hours, 39 minutes ago) Vulnerabilities has been mentioned […]

CVE-2025-8944 – OceanWP < 4.1.2 – Subscriber+ Limited Option Update

CVE ID : CVE-2025-8944 Published : Sept. 5, 2025, 6:15 a.m. | 1 hour, 26 minutes ago Description : The OceanWP WordPress theme before 4.1.2 is vulnerable to an option update due to a missing capability check on one of its AJAX request handler, allowing any authenticated users, such as subscriber to update the darkMod` setting. Severity: […]

CVE-2025-58400 – RATOC RAID Monitoring Manager for Windows Unquoted Service Path Privilege Escalation

The following table lists the changes that have been made to the CVE-2025-58400 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 05, 2025 Action […]

CVE-2025-55671 – TkEasyGUI Path Injection Vulnerability

The following table lists the changes that have been made to the CVE-2025-55671 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 05, 2025 Action […]

CVE-2025-55037 – TkEasyGUI OS Command Injection

The following table lists the changes that have been made to the CVE-2025-55037 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 05, 2025 Action […]

CVE-2025-41408 – Yahoo! Shopping Android URL Scheme Authorization Bypass

The following table lists the changes that have been made to the CVE-2025-41408 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 05, 2025 Action […]

Windows Heap-based Buffer Overflow Vulnerability Let Attackers Elevate Privileges

Windows Heap-based Buffer Overflow Vulnerability Let Attackers Elevate Privileges A recently patched vulnerability in a core Windows driver could allow a local attacker to execute code with the highest system privileges, effectively taking full control of a target machine. The flaw … Read more Published Date: Sep 05, 2025 (1 hour, 11 minutes ago) Vulnerabilities has been […]

Django Unauthenticated, 0 click, RCE, and SQL Injection using default configuration.

Django Unauthenticated, 0 click, RCE, and SQL Injection using default configuration. 2 min read1 day agoArticle about the critical CVE-2025–57833 I found in Django.Impact:RCE on PostgreSQL and SQL Injection on all of the databases.Vulnerable code:Vulnerability detection:In order for y … Read more Published Date: Sep 05, 2025 (1 hour, 33 minutes ago) Vulnerabilities has been mentioned in […]