CVE-2025-59044 – Himmelblau vulnerable to GID collision via group name-derived mapping (privilege escalation)

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Himmelblau 0.9.x derives numeric GIDs for Entra ID groups from the group display name when himmelblau.conf `id_attr_map = name` (the default configuration). Because Microsoft Entra ID allows multiple groups with the same `displayName` (including end-user–created personal/O365 groups, depending on tenant policy), distinct directory […]

CVE-2025-59042 – PyInstaller has local privilege escalation vulnerability

PyInstaller bundles a Python application and all its dependencies into a single package. Due to a special entry being appended to `sys.path` during the bootstrap process of a PyInstaller-frozen application, and due to the bootstrap script attempting to load an optional module for bytecode decryption while this entry is still present in `sys.path`, an application […]

CVE-2025-59038 – Prebid.js NPM package briefly compromised

Affected Products The following products are affected by CVE-2025-59038 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below. No affected product recoded yet

CVE-2025-9997 – BLMon OS Command Injection Vulnerability

The following table lists the changes that have been made to the CVE-2025-9997 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 09, 2025 Action […]

CVE-2025-59036 – Infrahub allows authentication with deleted and expired API tokens

The following table lists the changes that have been made to the CVE-2025-59036 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 09, 2025 Action […]

CVE-2025-58135 – Zoom Workplace Clients for Windows – Improper Action Enforcement

The following table lists the changes that have been made to the CVE-2025-58135 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 09, 2025 Action […]

CVE-2025-54258 – Substance3D – Modeler | Use After Free (CWE-416)

The following table lists the changes that have been made to the CVE-2025-54258 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Sep. 09, 2025 Action […]