ch
Feedback
🛡 Cybersecurity & Privacy 🛡 - CVEs

🛡 Cybersecurity & Privacy 🛡 - CVEs

前往频道在 Telegram

🔐 Explore the latest CVEs in cybersecurity and privacy. 🔔 Daily updates. 💻 Ensuring your online security. 📩 lalilolalo.dev@gmail.com

显示更多
Buy Ad
431
订阅者
无数据24 小时
无数据7 天
-330 天
帖子存档
‼️ CVE-2025-6079 ‼️ The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the homework.php file in all versions up to, and including, 93.2.0. This makes it possible for authenticated attackers, with Studentlevel access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-3671 ‼️ The WPGYM Wordpress Gym Management System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 67.7.0 via the 'page' parameter. This makes it possible for authenticated attackers, with Subscriberlevel access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other safe file types can be uploaded and included. The Local File Inclusion exploit can be chained to include various dashboard view files in the plugin. One in particular reported by the researcher can be leveraged to update the password of Super Administrator accounts in Multisite environments making ... 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2024-8393 ‼️ The Woocommerce Blocks Woolook plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7.0 via the via the 'tab' parameter. This makes it possible for authenticated attackers, with Administratorlevel access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other safe file types can be uploaded and included. Please note that this can also be exploited via CSRF techniques. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2024-12612 ‼️ The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via several parameters across multiple AJAX action in all versions up to, and including, 93.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-49895 ‼️ CrossSite Request Forgery CSRF vulnerability in iThemes ServerBuddy by PluginBuddy.Com allows Object Injection.This issue affects ServerBuddy by PluginBuddy.Com from na through 1.0.5. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2024-12575 ‼️ The Poll Maker Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 5.8.9 via the 'aysfinishpoll' AJAX action. This makes it possible for unauthenticated attackers to retrieve admin email information which is exposed in the poll response. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-55284 ‼️ Claude Code is an agentic coding tool. Prior to version 1.0.4, it's possible to bypass the Claude Code confirmation prompts to read a file and then send file contents over the network without user confirmation due to an overly broad allowlist of safe commands. Reliably exploiting this requires the ability to add untrusted content into a Claude Code context window. Users on standard Claude Code autoupdate received this fix automatically after release. Current users of Claude Code are unaffected, as versions prior to 1.0.24 are deprecated and have been forced to update. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-55286 ‼️ z2d is a pure Zig 2D graphics library. z2d v0.7.0 released with a new multisample antialiasing MSAA method, which uses a new buffering mechanism for storing coverage data. This differs from the standard alpha mask surface used for the previous supersample antialiasing SSAA method. Under certain circumstances where the path being drawn existed in whole or partly outside of the rendering surface, incorrect bounding could cause outofbounds access within the coverage buffer. This affects the higherlevel drawing operations, such as Context.fill, Context.stroke, painter.fill, and painter.stroke, when either the .default or .multisample4x antialiasing modes were used. .supersample4x was not affected, nor was drawing without antialiasing. In nonsafe optimization modes consumers compiling with R... 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2017-20199 ‼️ A vulnerability was found in Buttercup buttercupbrowserextension up to 0.14.2. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper access controls. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.1 is able to address this issue. The identifier of the patch is 89. It is recommended to upgrade the affected component. This vulnerability only affects products that are no longer supported by the maintainer. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-52621 ‼️ HCL BigFix SaaS Authentication Service is vulnerable to cache poisoning.  The BigFix SaaS's HTTP responses were observed to include the Origin header. Its presence alongside an unvalidated reflection of the Origin header value introduces a potential for cache poisoning. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-52620 ‼️ HCL BigFix SaaS Authentication Service is affected by a CrossSite Scripting XSS vulnerability. The image upload functionality inadequately validated the submitted image format. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-52619 ‼️ HCL BigFix SaaS Authentication Service is affected by a sensitive information disclosure. Under certain conditions, error messages disclose sensitive version information about the underlying platform. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-52618 ‼️ HCL BigFix SaaS Authentication Service is affected by a SQL injection vulnerability. The vulnerability allows potential attackers to manipulate SQL queries. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-43201 ‼️ This issue was addressed with improved checks. This issue is fixed in Apple Music Classical 2.3 for Android. An app may be able to unexpectedly leak a user's credentials. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-8959 ‼️ HashiCorp's gogetter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designated directory boundaries. This vulnerability, identified as CVE20258959, is fixed in gogetter 1.7.9. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-36088 ‼️ IBM TS4500 1.11.0.0D00, 1.11.0.1C00, 1.11.0.2C00, and 1.10.00F00 web GUI is vulnerable to crosssite scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-43490 ‼️ A potential security vulnerability has been identified in the HPAudioAnalytics service included in the HP Hotkey Support software, which might allow escalation of privilege. HP is releasing software updates to mitigate the potential vulnerability. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-55285 ‼️ backstagepluginscaffolderbackend is the backend for the default Backstage software templates. Prior to version 2.1.1, duplicate logging of the input values in the fetchtemplate action in the Scaffolder meant that some of the secrets were not properly redacted. If secrets.x is not passed through to fetchtemplate there is no impact. This issue has been resolved in 2.1.1 of the scaffolderbackend plugin. A workaround for this issue involves Template Authors removing the use of secrets being used as an argument to fetchtemplate. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-9060 ‼️ A vulnerability has been found in the  MSoft MFlash application that allows execution of arbitrary code on the server. The issue occurs in the integration configuration functionality that is only available to MFlash administrators. The vulnerability is related to insufficient validation of parameters when setting up security components. This issue affects MFlash v. 8.0 and possibly others. To mitigate apply 8.2653 hotfix 11.06.2025 and above. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-8996 ‼️ Missing Authorization vulnerability in Drupal Layout Builder Advanced Permissions allows Forceful Browsing.This issue affects Layout Builder Advanced Permissions from 0.0.0 before 2.2.0. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs