Overview
- wolfSSL
- wolfSSH
Description
Statistics
- 1 Post
- 11 Interactions
Fediverse
Oops.
wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to send a bogus signature, or trick the client into skipping user authentication. This affects client applications with wolfSSH version 1.4.21 and earlier. Users of wolfSSH must update or apply the fix patch and it’s recommended to update credentials used. This fix is also recommended for wolfSSH server applications. While there aren’t any specific attacks on server applications, the same defect is present. Thanks to Aina Toky Rasoamanana of Valeo and Olivier Levillain of Telecom SudParis for the report.
sev:CRIT 9.4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/U:Red
Overview
- Sneeit
- Sneeit Framework
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
🚨 CVE-2025-6389: WordPress Sneeit Framework plugin vulnerability currently under active exploitation
PoC: https://github.com/Ashwesker/Ashwesker-CVE-2025-6389
▪️Vulnerability Type: Remote Code Execution (RCE)
▪️CVSS: 9.8
▪️Published: 11/24/2025
Impact:
▪️Full site compromise
▪️Create admin accounts
▪️Install backdoors/malicious files
▪️Redirect visitors or inject malware
Credit: youtube.com/@Nxploited
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
⚠️ Samsung warnt vor gefährlicher Sicherheitslücke in SSD-Tool Magician: Lokale Angreifer können privilegierte Daten ausnutzen (CVE-2024-23769, CVSS 7.3). Update auf Version 8.0.1 jetzt installieren! https://www.golem.de/news/samsung-warnt-gefaehrliche-sicherheitsluecke-in-ssd-tool-magician-2601-203858.html #Cybersecurity #SamsungSSD #ITsicherheit
Tja Opensource ist euer freund, freunde der IT-Sicherheit… 🤷
Overview
- Sfwebservice
- InWave Jobs
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
🔴 CVE-2025-39477 - Critical (9.8)
Missing Authorization vulnerability in Sfwebservice InWave Jobs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InWave Jobs: from n/a through 3.5.8.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-39477/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda
Overview
- aio-libs
- aiohttp
Description
Statistics
- 1 Post
- 2 Interactions
Bluesky
Overview
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
TOTOLINK
https://www.cve.org/CVERecord?id=CVE-2025-65606 ( not yet published )
Overview
- TOTOLINK
- WA300
Description
Statistics
- 1 Post
- 1 Interaction
Overview
- TRENDnet
- TEW-811DRU
Description
Statistics
- 1 Post
- 1 Interaction
Overview
- MediaTek, Inc.
- MT6739, MT6761, MT6765, MT6768, MT6781, MT6789, MT6833, MT6835, MT6853, MT6855, MT6877, MT6878, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6897, MT6899, MT6983, MT6985, MT6989, MT6991, MT8186, MT8188, MT8196, MT8667, MT8673, MT8676, MT8678, MT8765, MT8766, MT8768, MT8771, MT8781, MT8791T, MT8792, MT8793, MT8795T, MT8796, MT8798, MT8873, MT8883
Description
Statistics
- 1 Post
Fediverse
🟠 CVE-2025-20781 - High (7.8)
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AL...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-20781/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda
Overview
Description
Statistics
- 1 Post
Fediverse
🔴 CVE-2025-60534 - Critical (9.8)
Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectively proxy requests in order to operate functionality on the web application without the need to authenticate with legitimate cr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-60534/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda