24h | 7d | 30d

Overview

  • Pending

24 Nov 2025
Published
24 Nov 2025
Updated

CVSS
Pending
EPSS
0.14%

KEV

Description

NULL pointer dereference in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS/TLS connection that triggers BIO_get_data() to return NULL.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 20 hours ago

Bluesky

Profile picture
Important security news for the #openSUSE Tumbleweed community. The libcoap library has received a significant security update, addressing nine documented vulnerabilities (CVE-2025-65493 to CVE-2025-65501). Read more: 👉 tinyurl.com/32r6hmnd #Security
  • 0
  • 1
  • 0
  • 20h ago

Overview

  • SPIP
  • SPIP

23 Aug 2024
Published
22 Nov 2025
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
93.78%

KEV

Description

The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.

Statistics

  • 1 Post

Last activity: 1 hour ago

Bluesky

Profile picture
~Sekoia~ Sekoia details a method to automate C2 configuration extraction from the Kaiji IoT botnet malware. - IOCs: CVE-2024-7954, CVE-2023-1389 - #Botnet #Kaiji #Malware #ThreatIntel
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • TP-Link Archer AX21 (AX1800)

15 Mar 2023
Published
21 Oct 2025
Updated

CVSS
Pending
EPSS
93.75%

Description

TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.

Statistics

  • 1 Post

Last activity: 1 hour ago

Bluesky

Profile picture
~Sekoia~ Sekoia details a method to automate C2 configuration extraction from the Kaiji IoT botnet malware. - IOCs: CVE-2024-7954, CVE-2023-1389 - #Botnet #Kaiji #Malware #ThreatIntel
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • xwiki
  • xwiki-platform

03 Sep 2025
Published
03 Sep 2025
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
2.05%

KEV

Description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-2 through 16.10.6, configuration files are accessible through jsx and sx endpoints. It's possible to access and read configuration files by using URLs such as `http://localhost:8080/bin/ssx/Main/WebHome?resource=../../WEB-INF/xwiki.cfg&minify=false`. This is fixed in version 16.10.7.

Statistics

  • 2 Posts

Last activity: 5 hours ago

Fediverse

Profile picture

🚨 New plugin: XWikiPlugin (CVE-2025-24893, CVE-2025-32429, CVE-2025-52472, CVE-2025-55748).

XWiki multiple critical vulnerabilities detection - RCE, SQL/HQL injection, and path traversal.

Results: leakix.net/search?q=%2Bplugin%

  • 0
  • 0
  • 1
  • 5h ago

Overview

  • xwiki
  • xwiki-platform

20 Feb 2025
Published
30 Oct 2025
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
94.18%

Description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity and availability of the whole XWiki installation. To reproduce on an instance, without being logged in, go to `<host>/xwiki/bin/get/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7Dprintln%28"Hello%20from"%20%2B%20"%20search%20text%3A"%20%2B%20%2823%20%2B%2019%29%29%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D%20`. If there is an output, and the title of the RSS feed contains `Hello from search text:42`, then the instance is vulnerable. This vulnerability has been patched in XWiki 15.10.11, 16.4.1 and 16.5.0RC1. Users are advised to upgrade. Users unable to upgrade may edit `Main.SolrSearchMacros` in `SolrSearchMacros.xml` on line 955 to match the `rawResponse` macro in `macros.vm#L2824` with a content type of `application/xml`, instead of simply outputting the content of the feed.

Statistics

  • 2 Posts

Last activity: 5 hours ago

Fediverse

Profile picture

🚨 New plugin: XWikiPlugin (CVE-2025-24893, CVE-2025-32429, CVE-2025-52472, CVE-2025-55748).

XWiki multiple critical vulnerabilities detection - RCE, SQL/HQL injection, and path traversal.

Results: leakix.net/search?q=%2Bplugin%

  • 0
  • 0
  • 1
  • 5h ago

Overview

  • xwiki
  • xwiki-platform

06 Oct 2025
Published
06 Oct 2025
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
1.40%

KEV

Description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 4.3-milestone-1 and prior to versions 16.10.9, 17.4.2, and 17.5.0, the REST search URL is vulnerable to HQL injection via the `orderField` parameter. The specified value is added twice in the query, though, once in the field list for the select and once in the order clause, so it's not that easy to exploit. The part of the query between the two fields can be enclosed in single quotes to effectively remove them, but the query still needs to remain valid with the query two times in it. This has been patched in versions 17.5.0, 17.4.2, and 16.10.9. No known workarounds are available.

Statistics

  • 2 Posts

Last activity: 5 hours ago

Fediverse

Profile picture

🚨 New plugin: XWikiPlugin (CVE-2025-24893, CVE-2025-32429, CVE-2025-52472, CVE-2025-55748).

XWiki multiple critical vulnerabilities detection - RCE, SQL/HQL injection, and path traversal.

Results: leakix.net/search?q=%2Bplugin%

  • 0
  • 0
  • 1
  • 5h ago

Overview

  • xwiki
  • xwiki-platform

24 Jul 2025
Published
25 Jul 2025
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
23.62%

KEV

Description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, it's possible for anyone to inject SQL using the parameter sort of the getdeleteddocuments.vm. It's injected as is as an ORDER BY value. This is fixed in versions 16.10.6 and 17.3.0-rc-1.

Statistics

  • 2 Posts

Last activity: 5 hours ago

Fediverse

Profile picture

🚨 New plugin: XWikiPlugin (CVE-2025-24893, CVE-2025-32429, CVE-2025-52472, CVE-2025-55748).

XWiki multiple critical vulnerabilities detection - RCE, SQL/HQL injection, and path traversal.

Results: leakix.net/search?q=%2Bplugin%

  • 0
  • 0
  • 1
  • 5h ago
Showing 21 to 27 of 27 CVEs