Aggregator
Rack Ruby Framework Vulnerabilities Let Attackers Inject and Manipulate Log Content
7 months 2 weeks ago
Researchers Thai Do and Minh Pham have exposed multiple critical vulnerabilities in the Rack Ruby framework, a cornerstone of Ruby-based web applications with over a billion global downloads. Identified as CVE-2025-25184, CVE-2025-27111, and CVE-2025-27610, these flaws pose significant risks to applications built on frameworks like Ruby on Rails and Sinatra. Rack, acting as a modular […]
The post Rack Ruby Framework Vulnerabilities Let Attackers Inject and Manipulate Log Content appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Aman Mishra
CVE-2025-4035 | GNOME libsoup Cookie Domain
7 months 2 weeks ago
A vulnerability has been found in GNOME libsoup and classified as problematic. This vulnerability affects unknown code of the component Cookie Domain Handler. The manipulation leads to an unknown weakness.
This vulnerability was named CVE-2025-4035. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-25776 | Codeastro Bus Ticket Booking System 1.0 User Registration Full Name/Address cross site scripting
7 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in Codeastro Bus Ticket Booking System 1.0. This affects an unknown part of the component User Registration Handler. The manipulation of the argument Full Name/Address leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-25776. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2015-2079 | Usermin up to 1.659 uconfig_save.cgi sig_file_free neutralization of directives
7 months 2 weeks ago
A vulnerability, which was classified as very critical, has been found in Usermin up to 1.659. Affected by this issue is the function sig_file_free of the file uconfig_save.cgi. The manipulation leads to improper neutralization of directives in statically saved code ('static code injection').
This vulnerability is handled as CVE-2015-2079. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-23377 | Dell PowerProtect Data Manager up to 19.18.0-23 escape output (dsa-2025-062)
7 months 2 weeks ago
A vulnerability classified as problematic was found in Dell PowerProtect Data Manager up to 19.18.0-23. Affected by this vulnerability is an unknown functionality. The manipulation leads to escaping of output.
This vulnerability is known as CVE-2025-23377. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-23375 | Dell PowerProtect Data Manager up to 19.18.0-23 incorrect privileged apis (dsa-2025-062)
7 months 2 weeks ago
A vulnerability classified as critical has been found in Dell PowerProtect Data Manager up to 19.18.0-23. Affected is an unknown function. The manipulation leads to incorrect use of privileged apis.
This vulnerability is traded as CVE-2025-23375. It is possible to launch the attack on the local host. There is no exploit available.
vuldb.com
CVE-2025-3200 | Wiesemann & Theis Com-Server++ prior 1.60 TLS risky encryption (VDE-2025-031)
7 months 2 weeks ago
A vulnerability was found in Wiesemann & Theis Com-Server++, Com-Server PoE 3x Isolated, Com-Server 20mA, Com-Server OEM and Com-Server UL. It has been rated as problematic. This issue affects some unknown processing of the component TLS. The manipulation leads to risky cryptographic algorithm.
The identification of this vulnerability is CVE-2025-3200. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-32472 | SICK AG SICK multiScan1XX/SICK picoScan1XX Slowloris resource consumption
7 months 2 weeks ago
A vulnerability was found in SICK AG SICK multiScan1XX and SICK picoScan1XX. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to resource consumption.
This vulnerability was named CVE-2025-32472. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-23376 | Dell PowerProtect Data Manager Reporting up to 19.18.0-23 Template Engine special elements used in a template engine (dsa-2025-062)
7 months 2 weeks ago
A vulnerability was found in Dell PowerProtect Data Manager Reporting up to 19.18.0-23. It has been classified as problematic. This affects an unknown part of the component Template Engine. The manipulation leads to improper neutralization of special elements used in a template engine.
This vulnerability is uniquely identified as CVE-2025-23376. An attack has to be approached locally. There is no exploit available.
vuldb.com
CVE-2025-46661 | IPW Metazo up to 8.1.3 smartyValidator.php special elements used in a template engine
7 months 2 weeks ago
A vulnerability was found in IPW Metazo up to 8.1.3 and classified as critical. Affected by this issue is some unknown functionality of the file smartyValidator.php. The manipulation leads to improper neutralization of special elements used in a template engine.
This vulnerability is handled as CVE-2025-46661. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2022-39317 | FreeRDP up to 2.8.x ZGFX Decoder out-of-bounds (GHSA-99cm-4gw7-c8jh / Nessus ID 211437)
7 months 2 weeks ago
A vulnerability was found in FreeRDP up to 2.8.x. It has been rated as problematic. This issue affects some unknown processing of the component ZGFX Decoder. The manipulation leads to out-of-bounds read.
The identification of this vulnerability is CVE-2022-39317. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-45375 | iFeature Slider Plugin up to 1.2 on WordPress cross site scripting
7 months 2 weeks ago
A vulnerability was found in iFeature Slider Plugin up to 1.2 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2022-45375. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2022-41889 | Google TensorFlow up to 2.8.3/2.9.2/2.10.0 tf.compat.v1.extract_volume_patches null pointer dereference (GHSA-xxcj-rhqg-m46g)
7 months 2 weeks ago
A vulnerability has been found in Google TensorFlow up to 2.8.3/2.9.2/2.10.0 and classified as problematic. This vulnerability affects the function tf.compat.v1.extract_volume_patches. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2022-41889. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
[Control systems] CISA ICS security advisories (AV25–238)
7 months 2 weeks ago
Canadian Centre for Cyber Security
Ubuntu security advisory (AV25-237)
7 months 2 weeks ago
Canadian Centre for Cyber Security
CVE-2007-6458 | My123tkshop E-commerce-suite 0.9.1 shop/admin.php admin sql injection (EDB-4733 / BID-26890)
7 months 2 weeks ago
A vulnerability, which was classified as critical, was found in My123tkshop E-commerce-suite 0.9.1. Affected is an unknown function of the file shop/admin.php. The manipulation of the argument admin leads to sql injection.
This vulnerability is traded as CVE-2007-6458. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
IBM security advisory (AV25-236)
7 months 2 weeks ago
Canadian Centre for Cyber Security
RALord
7 months 2 weeks ago
cohenido
Dell security advisory (AV25-235)
7 months 2 weeks ago
Canadian Centre for Cyber Security