24h | 7d | 30d

Overview

  • Monsta Limited of New Zealand
  • Monsta FTP

07 Nov 2025
Published
19 Nov 2025
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
10.77%

KEV

Description

Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server.

Statistics

  • 1 Post

Last activity: 14 hours ago

Fediverse

Profile picture

🚨 Alleged Leak of Unauthorized Monsta FTP Access; CVE-2025-34299

darkwebinformer.com/alleged-le

  • 0
  • 0
  • 0
  • 14h ago

Overview

  • djangoproject
  • Django
  • django

05 Nov 2025
Published
08 Nov 2025
Updated

CVSS
Pending
EPSS
0.07%

KEV

Description

An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank cyberstan for reporting this issue.

Statistics

  • 1 Post

Last activity: 20 hours ago

Bluesky

Profile picture
GitHub - omarkurt/django-connector-CVE-2025-64459-testbed: A self-contained testbed for Django CVE-2025-64459. Demonstrates QuerySet.filter() parameter injection via dictionary expansion using Docker.
  • 0
  • 0
  • 0
  • 20h ago

Overview

  • vim
  • vim

02 Dec 2025
Published
05 Dec 2025
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.01%

KEV

Description

Vim is an open source, command line text editor. Prior to version 9.1.1947, an uncontrolled search path vulnerability on Windows allows Vim to execute malicious executables placed in the current working directory for the current edited file. On Windows, when using cmd.exe as a shell, Vim resolves external commands by searching the current working directory before system paths. When Vim invokes tools such as findstr for :grep, external commands or filters via :!, or compiler/:make commands, it may inadvertently run a malicious executable present in the same directory as the file being edited. The issue affects Vim for Windows prior to version 9.1.1947.

Statistics

  • 1 Post

Last activity: 8 hours ago

Bluesky

Profile picture
Vim for Windowsに高深刻度の脆弱性 CVE-2025-66476 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #セキュリティ #Security
  • 0
  • 0
  • 0
  • 8h ago

Overview

  • Go standard library
  • crypto/x509
  • crypto/x509

03 Dec 2025
Published
03 Dec 2025
Updated

CVSS
Pending
EPSS
0.02%

KEV

Description

An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com.

Statistics

  • 1 Post

Last activity: 20 hours ago

Bluesky

Profile picture
🚨 New UNKNOWN CVE detected in AWS Lambda 🚨 CVE-2025-61727 impacts stdlib in 27 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/357 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless
  • 0
  • 0
  • 0
  • 20h ago

Overview

  • Pending

11 Jun 2021
Published
04 Dec 2025
Updated

CVSS
Pending
EPSS
84.32%

Description

OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.

Statistics

  • 1 Post

Last activity: 14 hours ago

Fediverse

Profile picture

🚨CVE-2021-26828: OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability has been added to the CISA KEV Catalog

Vendor: OpenPLC
Product: ScadaBR
CVSS: 8.8

darkwebinformer.com/cisa-kev-c

  • 0
  • 0
  • 0
  • 14h ago

Overview

  • pickplugins
  • User Verification by PickPlugins

05 Dec 2025
Published
05 Dec 2025
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
Pending

KEV

Description

The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.39. This is due to the plugin not properly validating that an OTP was generated before comparing it to user input in the "user_verification_form_wrap_process_otpLogin" function. This makes it possible for unauthenticated attackers to log in as any user with a verified email address, such as an administrator, by submitting an empty OTP value.

Statistics

  • 1 Post

Last activity: 1 hour ago

Fediverse

Profile picture

🔥 CRITICAL: CVE-2025-12374 in 'User Verification by PickPlugins' (WP, ≤2.0.39) allows auth bypass via empty OTP—admin takeover possible. Disable plugin or implement WAF rules until patched! radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Linux
  • Linux

17 Apr 2024
Published
04 May 2025
Updated

CVSS
Pending
EPSS
0.01%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: Revert "scsi: fcoe: Fix potential deadlock on &fip->ctlr_lock" This reverts commit 1a1975551943f681772720f639ff42fbaa746212. This commit causes interrupts to be lost for FCoE devices, since it changed sping locks from "bh" to "irqsave". Instead, a work queue should be used, and will be addressed in a separate commit.

Statistics

  • 1 Post

Last activity: 11 hours ago

Bluesky

Profile picture
URGENT for #Ubuntu users: Critical kernel vulnerability CVE-2024-26917 patched. Can cause system crashes (DoS) Read more: 👉 tinyurl.com/pj7k9bm3 #Security
  • 0
  • 0
  • 0
  • 11h ago

Overview

  • Unknown
  • UNA CMS

04 Dec 2025
Published
04 Dec 2025
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
Pending

KEV

Description

UNA CMS versions 9.0.0-RC1 - 14.0.0-RC4 contain a PHP object injection vulnerability in BxBaseMenuSetAclLevel.php where the profile_id POST parameter is passed to PHP unserialize() without proper handling, allowing remote, unauthenticated attackers to inject arbitrary PHP objects and potentially write and execute arbitrary PHP code.

Statistics

  • 1 Post

Last activity: 8 hours ago

Fediverse

Profile picture

🚨 CVE-2025-66571: CRITICAL PHP object injection in UNA CMS 9.0.0-RC1–14.0.0-RC4. Remote, unauthenticated code execution via unsafe unserialize(). Restrict endpoints, monitor logs, & apply mitigations. Patch ASAP. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 8h ago

Overview

  • NetScaler
  • ADC

26 Aug 2025
Published
21 Oct 2025
Updated

CVSS v4.0
CRITICAL (9.2)
EPSS
15.24%

Description

Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with IPv6 services or servicegroups bound with IPv6 servers (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with DBS IPv6 services or servicegroups bound with IPv6 DBS servers (OR) CR virtual server with type HDX

Statistics

  • 1 Post

Last activity: 2 hours ago

Bluesky

Profile picture
Citrix发布关键NetScaler漏洞补丁,确认CVE-2025-7775漏洞已被主动利用 https://qian.cx/posts/0B404317-F9DD-40AC-8FC8-FA262C228420
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Pending

19 Aug 2025
Published
19 Aug 2025
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

EzGED3 3.5.0 contains an unauthenticated arbitrary file read vulnerability due to improper access control and insufficient input validation in a script exposed via the web interface. A remote attacker can supply a crafted path parameter to a PHP script to read arbitrary files from the filesystem. The script lacks both authentication checks and secure path handling, allowing directory traversal attacks (e.g., ../../../) to access sensitive files such as configuration files, database dumps, source code, and password reset tokens. If phpMyAdmin is exposed, extracted credentials can be used for direct administrative access. In environments without such tools, attacker-controlled file reads still allow full database extraction by targeting raw MySQL data files. The vendor states that the issue is fixed in 3.5.72.27183.

Statistics

  • 2 Posts

Last activity: Last hour

Fediverse

Profile picture

🚨 New plugin: EzGED3Plugin (CVE-2025-51539).

EzGED3 pre-authentication arbitrary file read vulnerability detection - may lead to admin takeover.

Results: leakix.net/search?q=%2Bplugin%

  • 0
  • 0
  • 1
  • Last hour
Showing 21 to 30 of 62 CVEs