CVE-2025-57816 – Fides Webserver API Rate Limiting Vulnerability in Proxied Environments

Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Webserver API’s built-in IP-based rate limiting is ineffective in environments with CDNs, proxies or load balancers. The system incorrectly applies rate limits based on directly connected infrastructure IPs rather than client IPs, and stores counters in-memory rather than in a shared store. […]

CVE-2025-57766 – Fides’s Admin UI User Password Change Does Not Invalidate Current Session

The following table lists the changes that have been made to the CVE-2025-57766 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 08, 2025 Action […]

CVE-2025-10106 – yanyutao0402 ChanCMS search sql injection

The following table lists the changes that have been made to the CVE-2025-10106 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 08, 2025 Action […]

CVE-2025-1761 – IBM Concert Software information disclosure

Affected Products The following products are affected by CVE-2025-1761 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below. No affected product recoded yet

CVE-2025-52288 – Open5GS AMF Denial of Service DoS

The following table lists the changes that have been made to the CVE-2025-52288 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 08, 2025 Action […]

CVE-2025-10105 – yanyutao0402 ChanCMS search sql injection

Affected Products The following products are affected by CVE-2025-10105 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below. No affected product recoded yet

CVE-2025-54994 – @akoskm/create-mcp-server-stdio has Command Injection in MCP Server due to unsafe `exec` API

The following table lists the changes that have been made to the CVE-2025-54994 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 08, 2025 Action […]

CVE-2025-53838 – LinkAce has a Stored One Click XSS vulnerability

The following table lists the changes that have been made to the CVE-2025-53838 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 08, 2025 Action […]

CVE-2025-52389 – Envasadora H2O Eireli Soda Cristal IDOR Vulnerability

The following table lists the changes that have been made to the CVE-2025-52389 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 08, 2025 Action […]

CVE-2025-10104 – code-projects Online Event Judging System review_search.php sql injection

The following table lists the changes that have been made to the CVE-2025-10104 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 08, 2025 Action […]