CVE-2025-53187: Critical RCE in ABB ASPECT BMS with CVSS 9.8, No Prior Authentication

CVE-2025-53187: Critical RCE in ABB ASPECT BMS with CVSS 9.8, No Prior Authentication ABB has issued a cybersecurity advisory disclosing multiple vulnerabilities affecting its ASPECT Building Management System (BMS), including an authentication bypass rated CVSS 9.8. While patches exis … Read more Published Date: Sep 05, 2025 (5 hours, 41 minutes ago) Vulnerabilities has been mentioned in […]

CVE-2025-58362 – Hono contains a flaw in URL path parsing, potentially leading to path confusion

The following table lists the changes that have been made to the CVE-2025-58362 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 05, 2025 Action […]

CVE-2025-58359 – frost-core: refresh shares with smaller min_signers will reduce group security

ZF FROST is a Rust implementation of FROST (Flexible Round-Optimised Schnorr Threshold signatures). In versions 2.0.0 through 2.1.0, refresh shares with smaller min_signers will reduce security of group. The inability to change min_signers (i.e. the threshold) with the refresh share functionality (frost_core::keys::refresh module) was not made clear to users. Using a smaller value would not […]

CVE-2025-58179 – Astro Cloudflare adapter is vulnerable to Server-Side Request Forgery via /_image endpoint

The following table lists the changes that have been made to the CVE-2025-58179 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 05, 2025 Action […]

CVE-2025-58352 – Weblate has long session expiry times during second factor verification

The following table lists the changes that have been made to the CVE-2025-58352 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 05, 2025 Action […]

CVE-2025-55739 – api: Shared OAuth Signing Key Between Different Instances

api is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versions lower than 15.0.13, 16.0.2 through 16.0.14, 17.0.1 and 17.0.2, there is an identical OAuth private key used across multiple systems that installed the same FreePBX RPM or DEB package. An attacker with access to the […]

CVE-2025-55241 – Azure Entra Elevation of Privilege Vulnerability

The following table lists the changes that have been made to the CVE-2025-55241 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 04, 2025 Action […]

CVE-2025-55238 – Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability

The following table lists the changes that have been made to the CVE-2025-55238 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 04, 2025 Action […]

CVE-2025-54914 – Azure Networking Elevation of Privilege Vulnerability

The following table lists the changes that have been made to the CVE-2025-54914 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 04, 2025 Action […]

CVE-2025-55242 – Xbox Certification Bug Copilot Djando Information Disclosure Vulnerability

The following table lists the changes that have been made to the CVE-2025-55242 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 04, 2025 Action […]