en
Feedback
🛡 Cybersecurity & Privacy 🛡 - CVEs

🛡 Cybersecurity & Privacy 🛡 - CVEs

Open in Telegram

🔐 Explore the latest CVEs in cybersecurity and privacy. 🔔 Daily updates. 💻 Ensuring your online security. 📩 lalilolalo.dev@gmail.com

Show more
Buy Ad
431
Subscribers
No data24 hours
No data7 days
-330 days
Posts Archive
‼️ CVE-2025-8995 ‼️ Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login from 0.0.0 before 2.1.4. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-8675 ‼️ ServerSide Request Forgery SSRF vulnerability in Drupal AI SEO Link Advisor allows Server Side Request Forgery.This issue affects AI SEO Link Advisor from 0.0.0 before 1.0.6. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-8362 ‼️ Improper Neutralization of Input During Web Page Generation 'Crosssite Scripting' vulnerability in Drupal GoogleTag Manager allows CrossSite Scripting XSS.This issue affects GoogleTag Manager from 0.0.0 before 1.10.0. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-8361 ‼️ Missing Authorization vulnerability in Drupal Config Pages allows Forceful Browsing.This issue affects Config Pages from 0.0.0 before 2.18.0. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-8092 ‼️ Improper Neutralization of Input During Web Page Generation 'Crosssite Scripting' vulnerability in Drupal COOKiES Consent Management allows CrossSite Scripting XSS.This issue affects COOKiES Consent Management from 0.0.0 before 1.2.16. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-7961 ‼️ Improper Control of Generation of Code 'Code Injection' vulnerability in Wulkano KAP on MacOS allows TCC Bypass.This issue affects KAP 3.6.0. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-8066 ‼️ URL Redirection to Untrusted Site 'Open Redirect' vulnerability in Bunkerity Bunker Web on Linux allows Phishing.This issue affects Bunker Web 1.6.2. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-55207 ‼️ Astro is a web framework for contentdriven websites. Following CVE202554793 there's still an Open Redirect vulnerability in a subset of Astro deployment scenarios prior to version 9.4.1. Astro 5.12.8 addressed CVE202554793 where httpsexample.comastro.buildpress would redirect to the external origin astro.buildpress. However, with the Node deployment adapter in standalone mode and trailingSlash set to "always" in the Astro configuration, httpsexample.comastro.buildpress still redirects to astro.buildpress. This affects any user who clicks on a specially crafted link pointing to the affected domain. Since the domain appears legitimate, victims may be tricked into trusting the redirected page, leading to possible credential theft, malware distribution, or other phishingrelated attacks. Thi... 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-49898 ‼️ Improper Neutralization of Input During Web Page Generation 'Crosssite Scripting' vulnerability in Xolluteon Dropshix allows DOMBased XSS.This issue affects Dropshix from na through 4.0.14. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-49897 ‼️ Improper Neutralization of Special Elements used in an SQL Command 'SQL Injection' vulnerability in gopiplus Vertical scroll slideshow gallery v2 allows Blind SQL Injection. This issue affects Vertical scroll slideshow gallery v2 from na through 9.1. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-49432 ‼️ Missing Authorization vulnerability in FWDesign Ultimate Video Player allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate Video Player from na through 10.1. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-5048 ‼️ A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-5047 ‼️ A maliciously crafted DGN file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-5046 ‼️ A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force an OutofBounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-55203 ‼️ Plane is opensource project management software. Prior to version 0.28.0, a stored crosssite scripting XSS vulnerability exists in the descriptionhtml field of Plane. This flaw allows an attacker to inject malicious JavaScript code that is stored and later executed in other users browsers. The descriptionhtml field is not properly sanitized or escaped. An attacker can submit crafted JavaScript payloads that are saved in the applications database. When another user views the affected content, the injected code executes in their browser, running in the applications context and bypassing standard security protections. Successful exploitation can lead to session hijacking, theft of sensitive information, or forced redirection to malicious sites. The vulnerability can also be chained with CS... 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-54989 ‼️ Firebird is a relational database. Prior to versions 3.0.13, 4.0.6, and 5.0.3, there is an XDR message parsing NULL pointer dereference denialofservice vulnerability in Firebird. This specific flaw exists within the parsing of xdr message from client. It leads to NULL pointer dereference and DoS. This issue has been patched in versions 3.0.13, 4.0.6, and 5.0.3. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-54466 ‼️ Improper Control of Generation of Code 'Code Injection' vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Apache OFBiz before 24.09.02 only when the scrum plugin is used. Even unauthenticated attackers can exploit this vulnerability. Users are recommended to upgrade to version 24.09.02, which fixes the issue. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-24975 ‼️ Firebird is a relational database. Prior to snapshot versions 4.0.6.3183, 5.0.2.1610, and 6.0.0.609, Firebird is vulnerable if ExtConnPoolSize is not set equal to 0. If connections stored in ExtConnPool are not verified for presence and suitability of the CryptCallback interface is used when created versus what is available could result in a segfault in the server process. Encrypted databases, accessed by execute statement on external, may be accessed later by an attachment missing a key to that database. In a case when execute statement are chained, segfault may happen. Additionally, the segfault may affect unencrypted databases. This issue has been patched in snapshot versions 4.0.6.3183, 5.0.2.1610, and 6.0.0.609 and point releases 4.0.6 and 5.0.2. A workaround for this issue involve... 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-9053 ‼️ A vulnerability has been found in projectworlds Travel Management System 1.0. This vulnerability affects unknown code of the file updatesubcategory.php. The manipulation of the argument t1s1 leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

‼️ CVE-2025-9052 ‼️ A vulnerability was identified in projectworlds Travel Management System 1.0. This affects an unknown part of the file updatepackage.php. The manipulation of the argument s1 leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs