Aggregator
CVE-2025-66409 | Espressif ESP-IDF up to 5.1.6/5.2.6/5.3.4/5.4.3/5.5.1 out-of-bounds
CVE-2025-60854 | D-Link R15 up to 1.20.01 Password Change model name command injection
CVE-2025-13828 | Mautic up to 4.4.17/5.2.8/6.0.6 authorization (GHSA-3fq7-c5m8-g86x / EUVD-2025-200275)
University of Pennsylvania joins growing pool of Oracle customers impacted by Clop attacks
The Ivy League school said it was one of almost 100 organizations hit by the simultaneous attacks in August.
The post University of Pennsylvania joins growing pool of Oracle customers impacted by Clop attacks appeared first on CyberScoop.
CVE-2025-58386 | Terminalfour up to 8.4.1.1 User Management userLevel improper authorization
CVE-2025-58113 | PDF-XChange Editor 10.7.3.401 EMF File Parser out-of-bounds (TALOS-2025-2280)
CVE-2025-60736 | code-projects Online Medicine Guide 1.0 /login.php upass sql injection
CVE-2025-66399 | Cacti up to 1.2.28 SNMP command injection (GHSA-c7rr-2h93-7gjf / EUVD-2025-200287)
CVE-2025-64750 | sylabs singularity up to 4.1.10/4.3.4 /proc symlink (GHSA-fh74-hm69-rqjw / EUVD-2025-200289)
CVE-2025-13827 | Mautic up to 4.4.17/5.2.8/6.0.6 GrapesJS Builder unrestricted upload (GHSA-5xw2-57jx-pgjp / EUVD-2025-200276)
CVE-2025-65656 | Dcat-Admin up to 2.2.3-beta VersionManager.php file inclusion
CVE-2025-65358 | edoc-doctor-appointment-system 1.0.1 /admin/appointment.php docid sql injection
CVE-2025-12630 | Upload.am Plugin up to 1.0.0 on WordPress AJAX Request authorization
CVE-2025-66416 | modelcontextprotocol python-sdk up to 1.22.x insecure default initialization of resource
CVE-2025-65105 | Apptainer up to 1.4.4 symlink (GHSA-j3rw-fx6g-q46j)
Apache Struts security advisory (AV25-800)
Undetected Firefox WebAssembly Flaw Put 180 Million Users at Risk
Cybersecurity startup Aisle discovered a subtle but dangerous coding error in a Firefox WebAssembly implementation sat undetected for six months despite being shipped with a regression testing capability created by Mozilla to find such a problem.
The post Undetected Firefox WebAssembly Flaw Put 180 Million Users at Risk appeared first on Security Boulevard.
Legislation would designate ‘critical cyber threat actors,’ direct sanctions against them
The bill is a bid at further deterring cyberattacks, a sentiment with growing focus on the Hill and in the Trump administration.
The post Legislation would designate ‘critical cyber threat actors,’ direct sanctions against them appeared first on CyberScoop.