CISA Warns of OpenPLC ScadaBR cross-site scripting vulnerability Exploited in Attacks

CISA Warns of OpenPLC ScadaBR cross-site scripting vulnerability Exploited in Attacks The Cybersecurity and Infrastructure Security Agency (CISA) has officially updated its Known Exploited Vulnerabilities (KEV) catalog to include a critical flaw in OpenPLC ScadaBR, confirming that thre … Read more Published Date: Nov 29, 2025 (1 hour, 37 minutes ago) Vulnerabilities has been mentioned in this […]

CVE-2025-6666 – motogadget mo.lock Ignition Lock NFC hard-coded key

The following table lists the changes that have been made to the CVE-2025-6666 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 29, 2025 Action […]

CVE-2025-66290 – OrangeHRM is Vulnerable to Improper Authorization Allowing Unauthorized Access to Candidate Attachments

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application’s recruitment attachment retrieval endpoint does not enforce the required authorization checks before serving candidate files. Even users restricted to ESS-level access, who have no permission to view the Recruitment module, can directly access candidate attachment URLs. When an authenticated […]

CVE-2025-66291 – OrangeHRM is Vulnerable to Improper Authorization Allowing Unauthorized Access to Interview Attachments

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the interview attachment retrieval endpoint in the Recruitment module serves files based solely on an authenticated session and user-supplied identifiers, without verifying whether the requester has permission to access the associated interview record. Because the server does not perform any recruitment-level […]

CVE-2025-66224 – OrangeHRM is Vulnerable to Code Execution Through Arbitrary File Write from Sendmail Parameter Injection

The following table lists the changes that have been made to the CVE-2025-66224 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 29, 2025 Action […]

CVE-2025-65892 – Krpano Reflected Cross-Site Scripting (rXSS)

The following table lists the changes that have been made to the CVE-2025-65892 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 29, 2025 Action […]

CVE-2025-65540 – Xmall XSS

The following table lists the changes that have been made to the CVE-2025-65540 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 29, 2025 Action […]

CVE-2025-66221 – Werkzeug safe_join() allows Windows special device names

Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug’s safe_join function allows path segments with Windows device names. On Windows, there are special device names such as CON, AUX, etc that are implicitly present and readable in every directory. send_from_directory uses safe_join to safely serve files at user-specified paths under a […]