Aggregator
HPE security advisory (AV25-809)
1 month 1 week ago
Canadian Centre for Cyber Security
Critical Apache Tika Core Vulnerability Exploited by Uploading Malicious PDF
1 month 1 week ago
A critical security vulnerability in Apache Tika has been discovered that allows attackers to compromise systems by uploading specially crafted PDF files. Organizations worldwide are urged to patch immediately. Apache Tika is a popular open-source toolkit used by thousands of organizations to extract text and metadata from documents, including PDFs, Word files, and images. Apache […]
The post Critical Apache Tika Core Vulnerability Exploited by Uploading Malicious PDF appeared first on Cyber Security News.
Abinaya
DragonForce
1 month 1 week ago
You must login to view this content
cohenido
CVE-2025-64187 | OctoPrint up to 1.11.3 File cross site scripting (GHSA-crvm-xjhm-9h29)
1 month 1 week ago
A vulnerability has been found in OctoPrint up to 1.11.3 and classified as problematic. The impacted element is an unknown function of the component File Handler. The manipulation leads to basic cross site scripting.
This vulnerability is documented as CVE-2025-64187. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2025-64511 | 1Panel-dev MaxKB up to 2.3.0 Tool server-side request forgery (GHSA-9287-g7px-9rp4)
1 month 1 week ago
A vulnerability has been found in 1Panel-dev MaxKB up to 2.3.0 and classified as critical. This impacts an unknown function of the component Tool Module. The manipulation leads to server-side request forgery.
This vulnerability is listed as CVE-2025-64511. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2025-64703 | 1Panel-dev MaxKB up to 2.3.0 Tool information disclosure (GHSA-qwvm-x4xh-g2qq)
1 month 1 week ago
A vulnerability was found in 1Panel-dev MaxKB up to 2.3.0. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component Tool Module. This manipulation causes information disclosure.
This vulnerability is registered as CVE-2025-64703. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-64717 | Zitadel up to 2.71.18/3.4.3/4.6.5 improper authentication (GHSA-j4g7-v4m4-77px)
1 month 1 week ago
A vulnerability labeled as critical has been found in Zitadel up to 2.71.18/3.4.3/4.6.5. Impacted is an unknown function. The manipulation results in improper authentication.
This vulnerability is known as CVE-2025-64717. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2025-59116 | JCD Windu CMS 4.1 observable response discrepancy
1 month 1 week ago
A vulnerability described as problematic has been identified in JCD Windu CMS 4.1. This impacts an unknown function. Such manipulation leads to observable response discrepancy.
This vulnerability is uniquely identified as CVE-2025-59116. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2025-59113 | JCD Windu CMS 4.1 loginError excessive authentication
1 month 1 week ago
A vulnerability marked as problematic has been reported in JCD Windu CMS 4.1. This affects an unknown function. This manipulation of the argument loginError causes improper restriction of excessive authentication attempts.
This vulnerability is handled as CVE-2025-59113. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2025-59111 | JCD Windu CMS 4.1 authorization
1 month 1 week ago
A vulnerability, which was classified as problematic, has been found in JCD Windu CMS 4.1. Affected by this issue is some unknown functionality. The manipulation leads to incorrect authorization.
This vulnerability is referenced as CVE-2025-59111. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2025-59112 | JCD Windu CMS 4.1 POST Request cross-site request forgery
1 month 1 week ago
A vulnerability, which was classified as problematic, was found in JCD Windu CMS 4.1. This affects an unknown part of the component POST Request Handler. The manipulation results in cross-site request forgery.
This vulnerability is identified as CVE-2025-59112. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2025-59110 | JCD Windu CMS 4.1 cross-site request forgery
1 month 1 week ago
A vulnerability was found in JCD Windu CMS 4.1. It has been classified as problematic. Impacted is an unknown function. Performing manipulation results in cross-site request forgery.
This vulnerability is cataloged as CVE-2025-59110. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-59114 | JCD Windu CMS 4.1 cross-site request forgery (EUVD-2025-197998)
1 month 1 week ago
A vulnerability has been found in JCD Windu CMS 4.1 and classified as problematic. This vulnerability affects unknown code. This manipulation causes cross-site request forgery.
This vulnerability is tracked as CVE-2025-59114. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2025-59115 | JCD Windu CMS 4.1 Logon Page cross site scripting (EUVD-2025-197997)
1 month 1 week ago
A vulnerability was found in JCD Windu CMS 4.1. It has been declared as problematic. The affected element is an unknown function of the component Logon Page. Executing manipulation can lead to cross site scripting.
This vulnerability is registered as CVE-2025-59115. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2025-13120 | mruby up to 3.4.0 src/array.c sort_cmp use after free (Issue 6649)
1 month 1 week ago
A vulnerability was found in mruby up to 3.4.0. It has been declared as critical. This vulnerability affects the function sort_cmp of the file src/array.c. Such manipulation leads to use after free.
This vulnerability is traded as CVE-2025-13120. An attack has to be approached locally. Furthermore, there is an exploit available.
It is advisable to implement a patch to correct this issue.
vuldb.com
Interlock
1 month 1 week ago
You must login to view this content
cohenido
Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
1 month 1 week ago
Two hacking groups with ties to China have been observed weaponizing the newly disclosed security flaw in React Server Components (RSC) within hours of it becoming public knowledge.
The vulnerability in question is CVE-2025-55182 (CVSS score: 10.0), aka React2Shell, which allows unauthenticated remote code execution. It has been addressed in React versions 19.0.1, 19.1.2, and 19.2.1.
According
The Hacker News
Akira
1 month 1 week ago
You must login to view this content
cohenido
Akira
1 month 1 week ago
You must login to view this content
cohenido