CISA Warns of OpenPLC ScadaBR cross-site scripting vulnerability Exploited in Attacks
CISA Warns of OpenPLC ScadaBR cross-site scripting vulnerability Exploited in Attacks The Cybersecurity and Infrastructure Security Agency (CISA) has officially updated its Known Exploited Vulnerabilities (KEV) catalog to include a critical flaw in OpenPLC ScadaBR, confirming that thre … Read more Published Date: Nov 29, 2025 (1 hour, 37 minutes ago) Vulnerabilities has been mentioned in this […]
CVE-2025-6666 – motogadget mo.lock Ignition Lock NFC hard-coded key
The following table lists the changes that have been made to the CVE-2025-6666 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 29, 2025 Action […]
CVE-2025-66290 – OrangeHRM is Vulnerable to Improper Authorization Allowing Unauthorized Access to Candidate Attachments
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application’s recruitment attachment retrieval endpoint does not enforce the required authorization checks before serving candidate files. Even users restricted to ESS-level access, who have no permission to view the Recruitment module, can directly access candidate attachment URLs. When an authenticated […]
CVE-2025-66291 – OrangeHRM is Vulnerable to Improper Authorization Allowing Unauthorized Access to Interview Attachments
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the interview attachment retrieval endpoint in the Recruitment module serves files based solely on an authenticated session and user-supplied identifiers, without verifying whether the requester has permission to access the associated interview record. Because the server does not perform any recruitment-level […]
CVE-2025-66289 – OrangeHRM is Vulnerable to Persistent Session Access Due to Missing Invalidation After User Disable and Password Change
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application does not invalidate existing sessions when a user is disabled or when a password change occurs, allowing active session cookies to remain valid indefinitely. As a result, a disabled user, or an attacker using a compromised account, can continue […]
CVE-2025-66225 – OrangeHRM is Vulnerable to Account Takeover Through Unvalidated Username in Password Reset Workflow
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflow does not enforce that the username submitted in the final reset request matches the account for which the reset process was originally initiated. After obtaining a valid reset link for any account they can receive email for, […]
CVE-2025-66224 – OrangeHRM is Vulnerable to Code Execution Through Arbitrary File Write from Sendmail Parameter Injection
The following table lists the changes that have been made to the CVE-2025-66224 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 29, 2025 Action […]
CVE-2025-65892 – Krpano Reflected Cross-Site Scripting (rXSS)
The following table lists the changes that have been made to the CVE-2025-65892 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 29, 2025 Action […]
CVE-2025-65540 – Xmall XSS
The following table lists the changes that have been made to the CVE-2025-65540 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 29, 2025 Action […]
CVE-2025-66221 – Werkzeug safe_join() allows Windows special device names
Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug’s safe_join function allows path segments with Windows device names. On Windows, there are special device names such as CON, AUX, etc that are implicitly present and readable in every directory. send_from_directory uses safe_join to safely serve files at user-specified paths under a […]