24h | 7d | 30d

Overview

  • UTT
  • 进取 520W

06 Dec 2025
Published
06 Dec 2025
Updated

CVSS v4.0
HIGH (7.1)
EPSS
0.05%

KEV

Description

A vulnerability was detected in UTT 进取 520W 1.7.7-180627. The affected element is the function strcpy of the file /goform/websHostFilter. Performing manipulation of the argument addHostFilter results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Statistics

  • 1 Post

Last activity: 12 hours ago

Fediverse

Profile picture

🚩 CVE-2025-14140: HIGH-severity buffer overflow in UTT 进取 520W v1.7.7-180627. Public exploit available, no vendor patch. Restrict access, deploy IDS/IPS, and monitor logs. Act fast! radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 12h ago

Overview

  • roselldk
  • WebP Express

04 Dec 2025
Published
04 Dec 2025
Updated

CVSS v3.1
MEDIUM (5.3)
EPSS
0.04%

KEV

Description

The WebP Express plugin for WordPress is vulnerable to information exposure via config files in all versions up to, and including, 0.25.9. This is due to the plugin not properly randomizing the name of the config file to prevent direct access on NGINX. This makes it possible for unauthenticated attackers to extract configuration data.

Statistics

  • 1 Post

Last activity: 2 hours ago

Fediverse

Profile picture

Moved from webp-express to avif-express on my Wordpress site because the former has a security vulnerability (CVE-2025-11379) and looks unmaintained.

#CVE_2025_11379 #webp #avif #wordpress

  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Pending

06 Aug 2024
Published
13 Mar 2025
Updated

CVSS
Pending
EPSS
0.58%

KEV

Description

K7RKScan.sys in K7 Ultimate Security before 17.0.2019 allows local users to cause a denial of service (BSOD) because of a NULL pointer dereference.

Statistics

  • 1 Post

Last activity: 23 hours ago

Bluesky

Profile picture
📢 K7 Antivirus: abus de named pipes et escalade de privilèges jusqu’à SYSTEM (CVE-2024-36424) 📝 Source: billet technique de Lucas Laise. https://cyberveille.ch/posts/2025-12-06-k7-antivirus-abus-de-named-pipes-et-escalade-de-privileges-jusqua-system-cve-2024-36424/ #CVE_2024_36424 #Cyberveille
  • 0
  • 0
  • 0
  • 23h ago

Overview

  • Microsoft
  • Windows

26 Aug 2025
Published
05 Dec 2025
Updated

CVSS v3.0
HIGH (7.0)
EPSS
0.23%

KEV

Description

Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of .LNK files. Crafted data in an .LNK file can cause hazardous content in the file to be invisible to a user who inspects the file via the Windows-provided user interface. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-25373.

Statistics

  • 1 Post

Last activity: 13 hours ago

Bluesky

Profile picture
📌 Microsoft Quietly Patches Critical Windows LNK File Vulnerability (CVE-2025-9491) Exploited by Multiple APT Groups https://www.cyberhub.blog/article/16448-microsoft-quietly-patches-critical-windows-lnk-file-vulnerability-cve-2025-9491-exploited-by-multiple-apt-groups
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • UTT
  • 进取 520W

06 Dec 2025
Published
06 Dec 2025
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.04%

KEV

Description

A flaw has been found in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /goform/formArpBindConfig. Executing manipulation of the argument pools can lead to buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Statistics

  • 1 Post

Last activity: 13 hours ago

Fediverse

Profile picture

🔎 CVE-2025-14141: HIGH severity buffer overflow in UTT 进取 520W (v1.7.7-180627) via /goform/formArpBindConfig. No patch; public exploit available. Isolate devices, restrict access, monitor traffic. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Cacti
  • cacti

02 Dec 2025
Published
02 Dec 2025
Updated

CVSS v4.0
HIGH (7.4)
EPSS
0.07%

KEV

Description

Cacti is an open source performance and fault management framework. Prior to 1.2.29, there is an input-validation flaw in the SNMP device configuration functionality. An authenticated Cacti user can supply crafted SNMP community strings containing control characters (including newlines) that are accepted, stored verbatim in the database, and later embedded into backend SNMP operations. In environments where downstream SNMP tooling or wrappers interpret newline-separated tokens as command boundaries, this can lead to unintended command execution with the privileges of the Cacti process. This vulnerability is fixed in 1.2.29.

Statistics

  • 1 Post

Last activity: 11 hours ago

Bluesky

Profile picture
High-Severity Cacti Flaw (CVE-2025-66399) Risks Remote Code Execution via SNMP Community String Injection
  • 0
  • 0
  • 0
  • 11h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 15 hours ago

Bluesky

Profile picture
How a Grand Finalist Hacked NASA and Netflix: CVE-2023-44957 & CVE-2024-38945 Secrets Introduction: Bug bounty programs have become a critical line of defense for organizations like NASA and Netflix, where ethical hackers uncover vulnerabilities before malicious actors exploit them. This article…
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 15 hours ago

Bluesky

Profile picture
How a Grand Finalist Hacked NASA and Netflix: CVE-2023-44957 & CVE-2024-38945 Secrets Introduction: Bug bounty programs have become a critical line of defense for organizations like NASA and Netflix, where ethical hackers uncover vulnerabilities before malicious actors exploit them. This article…
  • 0
  • 0
  • 0
  • 15h ago
Showing 11 to 18 of 18 CVEs