Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
ILIAS 10.0, 10.1, 10.2 – Unauthenticated RCE write-up published:
https://srlabs.de/blog/breaking-ilias-part-2-three-to-rce
Why is this being published only now?
The vulnerability discussed here is tracked as CVE-2025-11344 and was assigned a CVSS base score of 5.3 (MEDIUM). Anyone wondering why this was not classified as CRITICAL should be aware that the CNA relied on the base score and severity assessment provided by ILIAS in its security advisory, which included neither a scoring matrix nor any justification for the rating.
Overview
- Gitea
- Gitea Open Source Git Server
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
🔴 CVE-2026-20897 - Critical (9.1)
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20897/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- InternationalColorConsortium
- iccDEV
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
🟠CVE-2026-24412 - High (8.8)
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have aHeap Buffer Overflow vulnerability in the CIccTagXmlSegmentedCurve::ToXml() function. This occurs ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-24412/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- Gitea
- Gitea Open Source Git Server
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
🟠CVE-2026-20736 - High (7.5)
Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachment to a repository may be able to delete it after losing access to that repository by making the request through a different rep...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20736/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
Description
Statistics
- 1 Post
Fediverse
🟠CVE-2025-15059 - High (7.8)
GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerabilit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-15059/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- Framelink
- Figma MCP Server
Description
Statistics
- 1 Post
Fediverse
🔴 CVE-2025-15061 - Critical (9.8)
Framelink Figma MCP Server fetchWithRetry Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Framelink Figma MCP Server. Authentication is not re...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-15061/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- Anritsu
- VectorStar
Description
Statistics
- 1 Post
Fediverse
🟠CVE-2025-15350 - High (7.8)
Anritsu VectorStar CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Anritsu VectorStar. User interaction is re...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-15350/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- Gitea
- Gitea Open Source Git Server
Description
Statistics
- 1 Post
Fediverse
🔴 CVE-2026-20750 - Critical (9.1)
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20750/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
Description
Statistics
- 1 Post
Fediverse
🔴 CVE-2025-67229 - Critical (9.8)
An improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unauthenticated, on-path attacker to spoof backend responses by exploiting insufficient certificate validation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-67229/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- InternationalColorConsortium
- iccDEV
Description
Statistics
- 1 Post
Fediverse
🟠CVE-2026-24405 - High (8.8)
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have a Heap Buffer Overflow vulnerability in CIccMpeCalculator::Read(). This occurs when user-controllab...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-24405/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack