THREAT OPS › Threat News
Threat Intelligence News
12303 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- YARA-X 1.0.0: The Stable Release and Its Advantagesvirustotal_blog · 2025-06-04
- What 17,845 GitHub Repos Taught Us About Malicious MCP Serversvirustotal_blog · 2025-06-04
- [NVD] CVE-2025-4517 (CRITICAL 9.4) — Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= paramnvd · 2025-06-03
- [NVD] CVE-2025-4435 (HIGH 7.5) — When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and notnvd · 2025-06-03
- [NVD] CVE-2025-4330 (HIGH 7.5) — Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extracnvd · 2025-06-03
- [NVD] CVE-2025-4138 (HIGH 7.5) — Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extracnvd · 2025-06-03
- [NVD] CVE-2024-12718 (MEDIUM 5.3) — Allows modifying some file metadata (e.g. last modified) with filter="data" or file permissions (chmod) with filter="tar" of files outside the extraction directory. You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.nvd · 2025-06-03
- [NVD] CVE-2025-5455 — An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a vnvd · 2025-06-02
- [NVD] CVE-2025-48938 (CRITICAL 9.8) — go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could result in executing arbitrary commands on a user's machine by rnvd · 2025-05-30
- [NVD] CVE-2025-4598 (MEDIUM 4.7) — A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loadnvd · 2025-05-30
- [NVD] CVE-2025-36572 (MEDIUM 6.5) — Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to gain unauthnvd · 2025-05-28
- [NVD] CVE-2025-5278 (MEDIUM 4.4) — A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a cranvd · 2025-05-27
- [NVD] CVE-2025-5222 (HIGH 7.0) — A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution.nvd · 2025-05-27
- AI ClickFix: Hijacking Computer-Use Agents Using ClickFixembracethered · 2025-05-24
- [NVD] CVE-2025-34025 — The Versa Concerto SD-WAN orchestration platform is vulnerable to an privileges escalation and container escape vulnerability caused by unsafe default mounting of host binary paths that allow the container to modify host paths. The escape can be used to trigger remote code executnvd · 2025-05-21
- [NVD] CVE-2025-34027 — The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The Spack upload endpoint can be leveraged for a Time-of-Check to Time-of-Use (TOCTOU) wnvd · 2025-05-21
- [NVD] CVE-2025-4805 — A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Access Portal configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScrinvd · 2025-05-16
- [NVD] CVE-2025-4804 — Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the spamBlocker module. This vulnerability requires an authenticated administrator session to a locally managed Firebox.nvd · 2025-05-16
- [NVD] CVE-2025-4211 — Improper Link Resolution Before File Access ('Link Following') vulnerability in QFileSystemEngine in the Qt corelib module on Windows which potentially allows Symlink Attacks and the use of Malicious Files. Issue originates from CVE-2024-38081. The vulnerability arises from the unvd · 2025-05-16
- [NVD] CVE-2025-47809 (HIGH 8.2) — Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivileged installation with UAC, and the CodeMeter Control Center component must be installed, and the CodeMenvd · 2025-05-16
- [NVD] CVE-2025-4516 — There is an issue in CPython when using `bytes.decode("unicode_escape", error="ignore|replace")`. If you are not using the "unicode_escape" encoding or an error handler your usage is not affected. To work-around this issue you may stop using the error= handler and instead wrap thnvd · 2025-05-15
- [NVD] CVE-2025-40583 (MEDIUM 4.4) — A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices do transmit sensitive information in cleartext. This could allow a privileged local attacker to retrieve thisnvd · 2025-05-13
- [NVD] CVE-2025-40582 (HIGH 7.8) — A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices do not properly sanitize configuration parameters. This could allow a non-privileged local attacker to executnvd · 2025-05-13
- [NVD] CVE-2025-40581 (HIGH 7.1) — A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices are vulnerable to an authentication bypass. This could allow a non-privileged local attacker to bypass the aunvd · 2025-05-13
- [NVD] CVE-2025-42999 (CRITICAL 9.1) — SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.nvd · 2025-05-13
- [NVD] CVE-2025-4528 (MEDIUM 4.3) — A weakness has been identified in Dígitro NGC Explorer up to 3.48.21. This affects an unknown function. Executing a manipulation can lead to session expiration. The attack can be launched remotely. Upgrading to version 3.48.22 mitigates this issue. It is recommended to upgrade thnvd · 2025-05-11
- [NVD] CVE-2025-4527 (LOW 3.7) — A security flaw has been discovered in Dígitro NGC Explorer up to 3.48.21. The impacted element is an unknown function of the component Password Transmission Handler. Performing a manipulation results in client-side enforcement of server-side security. The attack can be initiatednvd · 2025-05-11
- [NVD] CVE-2025-4526 (MEDIUM 4.3) — A vulnerability was identified in Dígitro NGC Explorer up to 3.48.21. The affected element is an unknown function of the component Configuration Page. Such manipulation leads to missing password field masking. It is possible to launch the attack remotely. Upgrading to version 3.4nvd · 2025-05-11
- [NVD] CVE-2025-4382 (MEDIUM 5.9) — A flaw was found in systems utilizing LUKS-encrypted disks with GRUB configured for TPM-based auto-decryption. When GRUB is set to automatically decrypt disks using keys stored in the TPM, it reads the decryption key into system memory. If an attacker with physical access can cornvd · 2025-05-09
- [NVD] CVE-2025-1254 (HIGH 7.4) — Out-of-bounds Read, Out-of-bounds Write vulnerability in RTI Connext Professional (Recording Service) allows Overflow Buffers, Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before 7.3.0.7, from 6.1.0 before 6.1.2.23, from 6.0.0 befnvd · 2025-05-08
- [NVD] CVE-2025-1253 (HIGH 7.8) — Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags. This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before 7nvd · 2025-05-08
- [NVD] CVE-2025-1252 (HIGH 7.1) — Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags. This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before 7.3.0.7, from 6.1.0 before 6.1.2.23, from 6.0.0 before 6.0.1.42, from 5.3.nvd · 2025-05-08
- [NVD] CVE-2025-37833 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: net/niu: Niu requires MSIX ENTRY_DATA fields touch before entry reads Fix niu_try_msix() to not cause a fatal trap on sparc systems. Set PCI_DEV_FLAGS_MSIX_TOUCH_ENTRY_DATA_FIRST on the struct pci_dev to work nvd · 2025-05-08
- [NVD] CVE-2025-37802 (HIGH 7.5) — In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix WARNING "do not call blocking ops when !TASK_RUNNING" wait_event_timeout() will set the state of the current task to TASK_UNINTERRUPTIBLE, before doing the condition check. This means that ksmbd_duranvd · 2025-05-08
- [NVD] CVE-2023-7303 (LOW 3.5) — A vulnerability, which was classified as problematic, was found in q2apro q2apro-on-site-notifications up to 1.4.6. This affects the function process_request of the file q2apro-onsitenotifications-page.php. The manipulation leads to cross site scripting. It is possible to initiatnvd · 2025-05-07
- Mainframes Are the New AI Infrastructure. Protect it with Secure AIaqua_nautilus · 2025-05-06
- [NVD] CVE-2025-4318 — The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could potentially allow an authenticated user who has access to create or modify components to run arbitrary JavaScript code during the component rennvd · 2025-05-05
- How ChatGPT Remembers You: A Deep Dive into Its Memory and Chat History Featuresembracethered · 2025-05-05
- [NVD] CVE-2022-49833 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: clone zoned device info when cloning a device When cloning a btrfs_device, we're not cloning the associated btrfs_zoned_device_info structure of the device in case of a zoned filesystem. Later onnvd · 2025-05-01
- [NVD] CVE-2022-49770 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: ceph: avoid putting the realm twice when decoding snaps fails When decoding the snaps fails it maybe leaving the 'first_realm' and 'realm' pointing to the same snaprealm memory. And then it'll put it twice and nvd · 2025-05-01
- [NVD] CVE-2025-23160 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix a resource leak related to the scp device in FW initialization On Mediatek devices with a system companion processor (SCP) the mtk_scp structure has to be removed explicitly to avoinvd · 2025-05-01
- Shadow Roles: AWS Defaults Can Open the Door to Service Takeoveraqua_nautilus · 2025-04-29
- [NVD] CVE-2025-3511 (HIGH 7.5) — Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module, CC-Link IE TSN Analog-Digital Converter module, CC-Link IE TSN Digital-Analog Converter module, CC-Link IE TSN FPGA module, CC-Link IE TSN Remote nvd · 2025-04-25
- [NVD] CVE-2025-31324 (CRITICAL 10.0) — SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integritnvd · 2025-04-24
- What’s Really Happening in Your Containers? Aqua’s Risk Assessment Has the Answeraqua_nautilus · 2025-04-23
- Binarly Transparency Platform v3.0: Actionable Threat Intelligence Meets Exploitation-Aware Prioritizationbinarly · 2025-04-23
- Phishing for Codes: Russian Threat Actors Target Microsoft 365 OAuth Workflowsvolexity · 2025-04-22
- [NVD] CVE-2025-46252 (HIGH 7.6) — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kofi Mokome Message Filter for Contact Form 7 allows SQL Injection. This issue affects Message Filter for Contact Form 7: from n/a through 1.6.3.2.nvd · 2025-04-22
- [NVD] CVE-2025-43955 (LOW 2.2) — TwsCachedXPathAPI in Convertigo versions before 8.3.11 did not restrict commons-jxpath functions, which could allow expression injection in contexts where an attacker can influence an evaluated XPath expression. Convertigo 8.3.11 fixes the issue by assigning an empty FunctionLibrnvd · 2025-04-20
- [NVD] CVE-2025-23129 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: Clear affinity hint before calling ath11k_pcic_free_irq() in error path If a shared IRQ is used by the driver due to platform limitation, then the IRQ affinity hint is set right after the allocatinvd · 2025-04-16
- [NVD] CVE-2025-22127 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: f2fs: fix potential deadloop in prepare_compress_overwrite() Jan Prusakowski reported a kernel hang issue as below: When running xfstests on linux-next kernel (6.14.0-rc3, 6.12) I encountered a problem in genenvd · 2025-04-16
- [NVD] CVE-2025-22124 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: md/md-bitmap: fix wrong bitmap_limit for clustermd when write sb In clustermd, separate write-intent-bitmaps are used for each cluster node: 0 4k 8k 12nvd · 2025-04-16
- [NVD] CVE-2025-22108 (HIGH 8.6) — In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Mask the bd_cnt field in the TX BD properly The bd_cnt field in the TX BD specifies the total number of BDs for the TX packet. The bd_cnt field has 5 bits and the maximum number supported is 32 with tnvd · 2025-04-16
- [NVD] CVE-2025-22104 (HIGH 7.1) — In the Linux kernel, the following vulnerability has been resolved: ibmvnic: Use kernel helpers for hex dumps Previously, when the driver was printing hex dumps, the buffer was cast to an 8 byte long and printed using string formatters. If the buffer size was not a multiple of nvd · 2025-04-16
- [NVD] CVE-2025-22103 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: net: fix NULL pointer dereference in l3mdev_l3_rcv When delete l3s ipvlan: ip link del link eth0 ipvlan1 type ipvlan mode l3s This may cause a null pointer dereference: Call trace: ip_rcv_finishnvd · 2025-04-16
- [NVD] CVE-2025-22101 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: net: libwx: fix Tx L4 checksum The hardware only supports L4 checksum offload for TCP/UDP/SCTP protocol. There was a bug to set Tx checksum flag for the other protocol that results in Tx ring hang. Fix to compunvd · 2025-04-16
- [NVD] CVE-2025-22039 (HIGH 8.8) — In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix overflow in dacloffset bounds check The dacloffset field was originally typed as int and used in an unchecked addition, which could overflow and bypass the existing bounds check in both smb_check_pernvd · 2025-04-16
- [NVD] CVE-2024-58097 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix RCU stall while reaping monitor destination ring While processing the monitor destination ring, MSDUs are reaped from the link descriptor based on the corresponding buf_id. However, sometimesnvd · 2025-04-16
- [NVD] CVE-2024-58095 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: jfs: add check read-only before txBeginAnon() call Added a read-only check before calling `txBeginAnon` in `extAlloc` and `extRecord`. This prevents modification attempts on a read-only mounted filesystem, avoinvd · 2025-04-16
- [NVD] CVE-2024-58094 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: jfs: add check read-only before truncation in jfs_truncate_nolock() Added a check for "read-only" mode in the `jfs_truncate_nolock` function to avoid errors related to writing to a read-only filesystem. Call snvd · 2025-04-16
- [NVD] CVE-2025-30714 (MEDIUM 4.8) — Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connvd · 2025-04-15
- [NVD] CVE-2025-30706 (HIGH 7.5) — Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectonvd · 2025-04-15
- [NVD] CVE-2025-3576 (MEDIUM 5.9) — A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrinvd · 2025-04-15
- [NVD] CVE-2025-1782 (CRITICAL 9.9) — In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is not properly sanitized before being used and can be misused to include an arbitrary file in the PHP code allowing an attacker to do anything as the web server user. This flaw requires the attacker tnvd · 2025-04-14
- [NVD] CVE-2025-3512 — There is a Heap-based Buffer Overflow vulnerability in QTextMarkdownImporter. This requires an incorrectly formatted markdown file to be passed to QTextMarkdownImporter to trigger the overflow. This issue affects Qt from 6.8.0 to 6.8.4. Versions up to 6.6.0 are known to be unaffnvd · 2025-04-11
- Aqua Security Achieves FedRAMP® High Authorizationaqua_nautilus · 2025-04-08
- [NVD] CVE-2025-2251 (MEDIUM 6.2) — A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP) within the Enterprise JavaBeans (EJB) remote invocation mechanism. This vulnerability stems from untrusted data deserialization handled by JBoss Marshalling. This flaw allows an attacker to send a snvd · 2025-04-07
- [NVD] CVE-2025-22457 (CRITICAL 9.0) — A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.nvd · 2025-04-03
- [NVD] CVE-2025-31098 (HIGH 7.5) — Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in debounce DeBounce Email Validator debounce-io-email-validator allows PHP Local File Inclusion. This issue affects DeBounce Email Validator: from n/a through <nvd · 2025-04-03
- [NVD] CVE-2025-2842 (MEDIUM 4.3) — A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to grant the cluster-monitoring-view ClusterRnvd · 2025-04-02
- Tomcat in the Crosshairs: New Research Reveals Ongoing Attacksaqua_nautilus · 2025-04-02
- [NVD] CVE-2025-2786 (MEDIUM 4.3) — A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extract the ServiceAccount token and use it to snvd · 2025-04-02
- GoResolver: Using Control-flow Graph Similarity to Deobfuscate Golang Binaries, Automaticallyvolexity · 2025-04-01
- [NVD] CVE-2025-0416 — Local privilege escalation through insecure DCOM configuration in Valmet DNA versions prior to C2023. The DCOM object Valmet DNA Engineering has permissions that allow it to run commands as a user with the SeImpersonatePrivilege privilege. The SeImpersonatePrivilege privilege is nvd · 2025-04-01
- [NVD] CVE-2025-2782 — The WatchGuard Terminal Services Agent on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnerable system.nvd · 2025-03-28
- [NVD] CVE-2025-2781 — The WatchGuard Mobile VPN with SSL Client on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnerable system.nvd · 2025-03-28
- [NVD] CVE-2022-49742 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: f2fs: initialize locks earlier in f2fs_fill_super() syzbot is reporting lockdep warning at f2fs_handle_error() [1], for spin_lock(&sbi->error_lock) is called before spin_lock_init() is called. For safe locking nvd · 2025-03-27
- [NVD] CVE-2022-49738 (HIGH 7.1) — In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on i_extra_isize in is_alive() syzbot found a f2fs bug: BUG: KASAN: slab-out-of-bounds in data_blkaddr fs/f2fs/f2fs.h:2891 [inline] BUG: KASAN: slab-out-of-bounds in is_alive fs/f2nvd · 2025-03-27
- Cut Through Alert Noise and Fix Toxic Combinations Firstaqua_nautilus · 2025-03-27
- [NVD] CVE-2025-21870 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-topology: Harden loops for looking up ALH copiers Other, non DAI copier widgets could have the same stream name (sname) as the ALH copier and in that case the copier->data is NULL, no alh_data nvd · 2025-03-27
- [NVD] CVE-2025-21868 (HIGH 7.5) — In the Linux kernel, the following vulnerability has been resolved: net: allow small head cache usage with large MAX_SKB_FRAGS values Sabrina reported the following splat: WARNING: CPU: 0 PID: 1 at net/core/dev.c:6935 netif_napi_add_weight_locked+0x8f2/0xba0 Modules linvd · 2025-03-27
- IngressNightmare Vulnerabilities: All You Need to Knowaqua_nautilus · 2025-03-26
- [NVD] CVE-2025-2559 (MEDIUM 4.9) — A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache can grow indefinitely, leading to an OutOfnvd · 2025-03-25
- How the Google-Wiz acquisition redefines cloud securityaqua_nautilus · 2025-03-24
- [NVD] CVE-2025-2610 (HIGH 7.6) — Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting. This vulnerability is associated with program files protected/components/MagnusLog.Php. This issue anvd · 2025-03-21
- [NVD] CVE-2025-2609 (HIGH 8.2) — Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/logUsers/read" cross-site scripting This vulnnvd · 2025-03-21
- [Breach] Cuties AI — 144,250 accounts exposedhibp_breaches · 2025-03-21
- [NVD] CVE-2025-29923 (LOW 3.7) — go-redis is the official Redis client library for the Go programming language. Prior to 9.5.5, 9.6.3, and 9.7.2, go-redis potentially responds out of order when `CLIENT SETINFO` times out during connection establishment. This can happen when the client is configured to transmit invd · 2025-03-20
- Clevo Boot Guard Keys Leaked in Update Packagebinarly · 2025-03-20
- [NVD] CVE-2024-7631 (MEDIUM 4.3) — A flaw was found in the OpenShift Console, an endpoint for plugins to serve resources in multiple languages: /locales/resources.json. This endpoint's lng and ns parameters are used to construct a filepath in pkg/plugins/handlers unsafely.go#L112 Because of this unsafe filepath convd · 2025-03-19
- [NVD] CVE-2025-25040 (LOW 3.3) — A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and affects: - AOS-CX 10.14.xxxx : All patches - AOS-CX 10.15.xxxx : 10.15.1000 and below The vulnerability is specificnvd · 2025-03-18
- [NVD] CVE-2025-2241 (HIGH 8.2) — A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision obnvd · 2025-03-17
- Supply Chain Security Risk: GitHub Action tj-actions/changed-files Compromisedaqua_nautilus · 2025-03-16
- [NVD] CVE-2024-54448 (HIGH 7.2) — The Automation Scripting functionality can be exploited by attackers to run arbitrary system commands on the underlying operating system. An account with administrator privileges or that has been explicitly granted access to use Automation Scripting is needed to carry out the attnvd · 2025-03-14
- [NVD] CVE-2024-8176 (HIGH 7.5) — A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space and cnvd · 2025-03-14
- UEFI Bootkit Hunting: In-Depth Search for Unique Code Behaviorbinarly · 2025-03-13
- [NVD] CVE-2025-2240 (HIGH 7.5) — A flaw was found in Smallrye, where smallrye-fault-tolerance is vulnerable to an out-of-memory (OOM) issue. This vulnerability is externally triggered when calling the metrics URI. Every call creates a new object within meterMap and may lead to a denial of service (DoS) issue.nvd · 2025-03-12
- [NVD] CVE-2025-21864 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: tcp: drop secpath at the same time as we currently drop dst Xiumei reported hitting the WARN in xfrm6_tunnel_net_exit while running tests that boil down to: - create a pair of netns - run a basic TCP test ovenvd · 2025-03-12
- [NVD] CVE-2025-21855 (HIGH 8.6) — In the Linux kernel, the following vulnerability has been resolved: ibmvnic: Don't reference skb after sending to VIOS Previously, after successfully flushing the xmit buffer to VIOS, the tx_bytes stat was incremented by the length of the skb. It is invalid to access the skb mnvd · 2025-03-12
- [NVD] CVE-2025-21851 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: bpf: Fix softlockup in arena_map_free on 64k page kernel On an aarch64 kernel with CONFIG_PAGE_SIZE_64KB=y, arena_htab tests cause a segmentation fault and soft lockup. The same failure is not observed with 4k nvd · 2025-03-12