Overview
Description
Statistics
- 1 Post
Fediverse
Oh that could be fun.
https://www.cve.org/CVERecord?id=CVE-2025-67809
An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present in the publicly accessible Flickr Zimlet used by Zimbra Collaboration. Because these credentials are embedded directly in the Zimlet, any unauthorized party could retrieve them and misuse the Flickr integration. An attacker with access to the exposed credentials could impersonate the legitimate application and initiate valid Flickr OAuth flows. If a user is tricked into approving such a request, the attacker could gain access to the user s Flickr data. The hardcoded credentials have since been removed from the Zimlet code, and the associated key has been revoked.
Overview
- SourceCodester
- Warehouse Management System
Description
Statistics
- 1 Post
Overview
- NXLog
- NXLog Agent
Description
Statistics
- 1 Post
Fediverse
⚠️ HIGH severity: CVE-2025-67900 in NXLog Agent <6.11 lets local attackers alter OpenSSL configs via OPENSSL_CONF, risking confidentiality & integrity. Patch to 6.11+ & restrict local access! https://radar.offseq.com/threat/cve-2025-67900-cwe-829-inclusion-of-functionality--155a752c #OffSeq #Vulnerability #InfoSec
Overview
- Shiguangwu
- sgwbox N3
Description
Statistics
- 1 Post
Fediverse
🚨 CVE-2025-14706 (CRITICAL, CVSS 9.3): Shiguangwu sgwbox N3 v2.0.25 has an unpatched remote command injection in /usr/sbin/http_eshell_server. Public exploit, no vendor fix. Isolate, restrict, & monitor now! https://radar.offseq.com/threat/cve-2025-14706-command-injection-in-shiguangwu-sgw-4786a150 #OffSeq #CVE202514706 #Infosec #NetworkSecurity
Overview
- Microsoft
- Windows 11 Version 25H2
Description
Statistics
- 1 Post
Overview
- pgadmin.org
- pgAdmin 4
Description
Statistics
- 1 Post
Fediverse
We discovered a critical pgAdmin vulnerability (CVE-2025-13780): whitespace bypassed a regex meant to block dangerous psql meta-commands.
A great example of why regex is fragile for input validation.
Deep dive:
https://www.endorlabs.com/learn/when-regex-isnt-enough-how-we-discovered-cve-2025-13780-in-pgadmin
Overview
Description
Statistics
- 1 Post
Overview
- argoproj
- argo-workflows
Description
Statistics
- 1 Post
Fediverse
A patch in Argo Workflows was supposed to fix a ZipSlip issue… but it didn’t.
Our research uncovered CVE-2025-66626 — a validation bug that let malicious tarballs escape the working directory and reach RCE.
Full write-up:
https://www.endorlabs.com/learn/when-a-broken-fix-leads-to-rce-how-we-found-cve-2025-66626-in-argo
Overview
Description
Statistics
- 1 Post
Overview
- Microsoft
- Windows 11 Version 25H2
Description
Statistics
- 1 Post