24h | 7d | 30d

Overview

  • Microsoft
  • Windows

26 Aug 2025
Published
05 Dec 2025
Updated

CVSS v3.0
HIGH (7.0)
EPSS
0.23%

KEV

Description

Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of .LNK files. Crafted data in an .LNK file can cause hazardous content in the file to be invisible to a user who inspects the file via the Windows-provided user interface. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-25373.

Statistics

  • 1 Post

Last activity: Last hour

Bluesky

Profile picture
📢 Microsoft corrige CVE-2025-9491: des commandes cachées dans les fichiers LNK exploitées depuis 2017 📝 Selon Next INpact, Microsof… https://cyberveille.ch/posts/2025-12-06-microsoft-corrige-cve-2025-9491-des-commandes-cachees-dans-les-fichiers-lnk-exploitees-depuis-2017/ #CVE_2025_9491 #Cyberveille
  • 0
  • 0
  • 0
  • Last hour

Overview

  • 10web
  • 10Web Booster – Website speed optimization, Cache & Page Speed optimizer

06 Dec 2025
Published
06 Dec 2025
Updated

CVSS v3.1
CRITICAL (9.6)
EPSS
0.04%

KEV

Description

The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to arbitrary folder deletion due to insufficient file path validation in the get_cache_dir_for_page_from_url() function in all versions up to, and including, 2.32.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary folders on the server, which can easily lead to a loss of data or a denial of service condition.

Statistics

  • 1 Post

Last activity: 12 hours ago

Fediverse

Profile picture

🚨 CRITICAL vuln: 10Web Booster WordPress plugin (all versions ≤2.32.7) allows authenticated users to delete arbitrary folders via path traversal (CVE-2025-13377, CVSS 9.6). Risk: data loss, DoS. Restrict access & monitor systems. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 12h ago

Overview

  • Advantech Co., Ltd.
  • WISE-DeviceOn Server

05 Dec 2025
Published
05 Dec 2025
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
0.19%

KEV

Description

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secret for signing EIRMMToken JWTs across all installations. The server accepts forged JWTs that need only contain a valid email claim, allowing a remote unauthenticated attacker to generate arbitrary tokens and impersonate any DeviceOn account, including the root super admin. Successful exploitation permits full administrative control of the DeviceOn instance and can be leveraged to execute code on managed agents through DeviceOn’s remote management features.

Statistics

  • 1 Post

Last activity: 16 hours ago

Fediverse

Profile picture

🚨 CVE-2025-34256: CRITICAL (CVSS 10) vuln in Advantech WISE-DeviceOn Server <5.4—remote attackers can forge JWTs & gain full admin access via hard-coded key. Patch to v5.4+ or restrict access now! radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 16h ago

Overview

  • ajitdas
  • Flex QR Code Generator

06 Dec 2025
Published
06 Dec 2025
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.14%

KEV

Description

The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_qr_code() function in all versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

Statistics

  • 1 Post

Last activity: 10 hours ago

Fediverse

Profile picture

🚨 CRITICAL: CVE-2025-12673 in Flex QR Code Generator for WordPress (≤1.2.6) allows unauthenticated arbitrary file uploads—possible RCE! Disable plugin, monitor for patches, restrict file exec in uploads. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 10h ago

Overview

  • Linux
  • Linux

07 Mar 2025
Published
04 May 2025
Updated

CVSS
Pending
EPSS
0.03%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: io_uring/kbuf: reallocate buf lists on upgrade IORING_REGISTER_PBUF_RING can reuse an old struct io_buffer_list if it was created for legacy selected buffer and has been emptied. It violates the requirement that most of the field should stay stable after publish. Always reallocate it instead.

Statistics

  • 1 Post

Last activity: 18 hours ago

Bluesky

Profile picture
Déjà Vu in Linux io_uring Talk by Pumpkin about exploiting CVE-2025-21836 — a race condition that leads to a use-after-free in the io_uring subsystem. Video: www.youtube.com/watch?v=Ry4e... Slides: u1f383.github.io/slides/talks...
  • 0
  • 0
  • 0
  • 18h ago

Overview

  • Apache Software Foundation
  • Apache HTTP Server

05 Dec 2025
Published
05 Dec 2025
Updated

CVSS
Pending
EPSS
0.03%

KEV

Description

Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off  allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.66, which fixes the issue.

Statistics

  • 1 Post

Last activity: 16 hours ago

Bluesky

Profile picture
Apache HTTP Server 2.4.66 Fixes SSRF Flaw (CVE-2025-59775) Exposing NTLM Hashes on Windows and suexec Bypass
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • libxslt

14 Oct 2025
Published
21 Nov 2025
Updated

CVSS
Pending
EPSS
0.06%

KEV

Description

A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during stylesheet parsing. Due to improper type handling, the function may treat an XML document node as a regular XML element node, resulting in a type confusion. This can cause unexpected memory reads and potential crashes. While difficult to exploit, the flaw could lead to application instability or denial of service.

Statistics

  • 1 Post

Last activity: 16 hours ago

Bluesky

Profile picture
CVE-2025-11731 Libxslt: type confusion in exsltfuncresultcompfunction of libxslt scq.ms/4rG6IMz #SecQube #MicrosoftSecurity
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • 7-Zip
  • 7-Zip

19 Nov 2025
Published
21 Nov 2025
Updated

CVSS v3.0
HIGH (7.0)
EPSS
0.29%

KEV

Description

7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this product is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the handling of symbolic links in ZIP files. Crafted data in a ZIP file can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of a service account. Was ZDI-CAN-26753.

Statistics

  • 1 Post

Last activity: 19 hours ago

Fediverse

Profile picture

đź“° Critical 7-Zip RCE Vulnerability Now Under Active Exploitation

A critical RCE vulnerability in 7-Zip (CVE-2025-11001) is now being actively exploited. ⚠️ The path traversal flaw allows code execution via malicious archives. Update to version 25.0.0 or later immediately! #7Zip #RCE #CyberSecurity

đź”— cyber.netsecops.io/articles/ac

  • 0
  • 0
  • 0
  • 19h ago

Overview

  • Apache Software Foundation
  • Apache Tika PDF parser module
  • org.apache.tika:tika-parser-pdf-module

20 Aug 2025
Published
04 Nov 2025
Updated

CVSS
Pending
EPSS
0.03%

KEV

Description

Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitive data or trigger malicious requests to internal resources or third-party servers. Note that the tika-parser-pdf-module is used as a dependency in several Tika packages including at least: tika-parsers-standard-modules, tika-parsers-standard-package, tika-app, tika-grpc and tika-server-standard. Users are recommended to upgrade to version 3.2.2, which fixes this issue.

Statistics

  • 1 Post

Last activity: 10 hours ago

Fediverse

Profile picture

VulnerabilitĂ  critica in Apache Tika con Severity 10! rischio di attacco XXE

E’ stata pubblicata una vulnerabilità critica in Apache Tika, che potrebbe consentire un attacco di iniezione di entità esterne XML, noto come XXE. La falla di sicurezza, catalogata come CVE-2025-66516, presenta un punteggio pari a 10,0 secondo la scala CVSS, indice di massima gravità.

Si ritiene che CVE-2025-66516 sia identica al CVE-2025-54988 (punteggio CVSS: 8,4), un’altra falla XXE nel framework di rilevamento e analisi dei contenuti, corretta dai responsabili del progetto nell’agosto 2025. Il nuovo CVE, ha affermato il team di Apache Tika, amplia la portata dei pacchetti interessati in due modi.

La falla critica è presente nei moduli Apache Tika, precisamente in tika-core (dalla versione 1.13 alla 3.2.1), tika-pdf-module (dalle versioni 2.0.0 alla 3.2.1) e tika-parsers (dalla 1.13 alla 1.28.5), su tutte le piattaforme, permette ad un aggressore di effettuare iniezioni di entità esterne XML attraverso un file XFA contraffatto incluso in un PDF.

Riguarda i seguenti pacchetti Maven:

  • org.apache.tika:tika-core >= 1.13,
  • org.apache.tika:tika-parser-pdf-module >= 2.0.0,
  • org.apache.tika:tika-parsers >= 1.13,

“Innanzitutto, sebbene il punto di ingresso della vulnerabilità fosse il modulo tika-parser-pdf, come riportato in CVE-2025-54988, la vulnerabilità e la sua correzione si trovavano in tika-core”, ha affermato il team. “Gli utenti che hanno aggiornato il modulo tika-parser-pdf ma non hanno aggiornato tika-core alla versione >= 3.2.2 sarebbero comunque vulnerabili”.

Alla luce della criticitĂ  della vulnerabilitĂ , si consiglia agli utenti di applicare gli aggiornamenti il prima possibile per mitigare le potenziali minacce.

L'articolo VulnerabilitĂ  critica in Apache Tika con Severity 10! rischio di attacco XXE proviene da Red Hot Cyber.

  • 0
  • 0
  • 0
  • 10h ago

Overview

  • TOZED
  • ZLT M30S

05 Dec 2025
Published
05 Dec 2025
Updated

CVSS v4.0
MEDIUM (5.3)
EPSS
0.02%

KEV

Description

A vulnerability was determined in TOZED ZLT M30S and ZLT M30S PRO 1.47/3.09.06. This impacts an unknown function of the file /reqproc/proc_post of the component Web Interface. Executing manipulation of the argument goformId with the input REBOOT_DEVICE can lead to denial of service. The attack can only be done within the local network. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 21 hours ago
Showing 31 to 40 of 42 CVEs