CVE-2025-58401 – Obsidian GitHub Copilot Plugin Token Storage Vulnerability
The following table lists the changes that have been made to the CVE-2025-58401 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 05, 2025 Action […]
CVE-2025-8684 – Flatsome <= 3.20.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
CVE ID : CVE-2025-8684 Published : Sept. 5, 2025, 4:15 a.m. | 1 hour, 23 minutes ago Description : The Flatsome Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme’s shortcodes in all versions up to, and including, 3.20.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it […]
Windows Update Is Causing Unexpected UAC Prompts and App Installation Issues
Windows Update Is Causing Unexpected UAC Prompts and App Installation Issues According to a notice published on the Windows Health Dashboard, Microsoft has confirmed that the routine security updates released in August are causing unexpected UAC (User Account Control) prompts … Read more Published Date: Sep 05, 2025 (3 hours, 16 minutes ago) Vulnerabilities has been mentioned […]
CVE-2025-9990 – WordPress Helpdesk Integration <= 5.8.10 – Unauthenticated Local File Inclusion
CVE ID : CVE-2025-9990 Published : Sept. 5, 2025, 3:15 a.m. | 22 minutes ago Description : The WordPress Helpdesk Integration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.8.10 via the portal_type parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files […]
Hackers Scanning Cisco ASA Devices to Exploit Vulnerabilities from 25,000 IPs
Hackers Scanning Cisco ASA Devices to Exploit Vulnerabilities from 25,000 IPs An unprecedented surge in malicious scanning activity targeting Cisco Adaptive Security Appliances (ASAs) occurred in late August 2025, with over 25,000 unique IP addresses participating in coordinate … Read more Published Date: Sep 05, 2025 (1 hour, 56 minutes ago) Vulnerabilities has been mentioned in this […]
Argo CD Patches Critical CVSS 10 Vulnerability Exposing Repository Credentials (CVE-2025-55190)
Argo CD Patches Critical CVSS 10 Vulnerability Exposing Repository Credentials (CVE-2025-55190) The Argo CD project has disclosed and patched a critical vulnerability (CVE-2025-55190, CVSS 10) affecting its popular GitOps continuous delivery platform for Kubernetes. The flaw, found in the Projec … Read more Published Date: Sep 05, 2025 (4 hours, 16 minutes ago) Vulnerabilities has been mentioned […]
September 2025 Android Security Patch
September 2025 Android Security Patch September 5, 2025The September 2025 Google Android security patch release is one of the most impactful updates this year, addressing more than a hundred vulnerabilities with particular urgency due to … Read more Published Date: Sep 05, 2025 (2 hours, 16 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-48543 CVE-2025-48539 […]
CISA Adds Three New Vulnerabilities to Catalog, Urges Immediate Patching
CISA Adds Three New Vulnerabilities to Catalog, Urges Immediate Patching The Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation in the wild … Read more Published Date: Sep 05, 2025 (4 hours, 41 minutes ago) Vulnerabilities has been mentioned in this article. […]
CVE-2025-7445 – Kubernetes secrets-store-sync-controller discloses service account tokens in logs
The following table lists the changes that have been made to the CVE-2025-7445 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 05, 2025 Action […]
CVE-2025-56752: Remote Attackers Can Gain Full Administrative Access to Affected Ruijie Networks Devices Without Authentication
CVE-2025-56752: Remote Attackers Can Gain Full Administrative Access to Affected Ruijie Networks Devices Without Authentication Ruijie Networks has released a security advisory addressing a critical vulnerability in its Reyee RG-ES series switches that could allow attackers to modify device login credentials without authorizat … Read more Published Date: Sep 05, 2025 (5 hours, 6 minutes ago) Vulnerabilities […]