Aggregator
CVE-2025-67643 | Jenkins Redpen up to 1.054.v7b_9517b_6b_202 permission (Nessus ID 278130)
1 month ago
A vulnerability identified as critical has been detected in Jenkins Redpen up to 1.054.v7b_9517b_6b_202. This affects an unknown part. The manipulation leads to permission issues.
This vulnerability is referenced as CVE-2025-67643. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2025-67639 | Jenkins up to 2.540/LTS 2.528.2 cross-site request forgery (Nessus ID 278129)
1 month ago
A vulnerability was found in Jenkins up to 2.540/LTS 2.528.2. It has been classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2025-67639. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-13472 | Perforce BlazeMeter Plugin up to 4.26 on Jenkins authorization (EUVD-2025-200734 / Nessus ID 278130)
1 month ago
A vulnerability categorized as problematic has been discovered in Perforce BlazeMeter Plugin up to 4.26 on Jenkins. This affects an unknown part. Such manipulation leads to missing authorization.
This vulnerability is referenced as CVE-2025-13472. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-67642 | Jenkins HashiCorp Vault Plugin up to 371.v884a_4dd60fb_6 Credentials Lookup permission (Nessus ID 278130)
1 month ago
A vulnerability categorized as critical has been discovered in Jenkins HashiCorp Vault Plugin up to 371.v884a_4dd60fb_6. Affected by this issue is some unknown functionality of the component Credentials Lookup Handler. Executing manipulation can lead to permission issues.
The identification of this vulnerability is CVE-2025-67642. The attack may be launched remotely. There is no exploit available.
vuldb.com
无影v3.1发布—上线小程序反编译等新功能
1 month ago
无影(TscanPlus)v3.1发布,新增微信小程序反编译、全面升级PoC检测引擎、国密网站探测、Nessus扫描、DumpALL、水洞专用等功能。
CVE-2025-11247 | GitLab Enterprise Edition up to 18.4.5/18.5.3/18.6.1 GraphQL authorization (Issue 573766 / EUVD-2025-202647)
1 month ago
A vulnerability, which was classified as problematic, was found in GitLab Enterprise Edition up to 18.4.5/18.5.3/18.6.1. The affected element is an unknown function of the component GraphQL. Such manipulation leads to authorization bypass.
This vulnerability is uniquely identified as CVE-2025-11247. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2025-11984 | GitLab Community Edition/Enterprise Edition up to 18.4.5/18.5.3/18.6.1 WebAuthn Two-Factor Authentication authentication bypass (Issue 577847 / EUVD-2025-202648)
1 month ago
A vulnerability, which was classified as critical, was found in GitLab Community Edition and Enterprise Edition up to 18.4.5/18.5.3/18.6.1. This impacts an unknown function of the component WebAuthn Two-Factor Authentication. Executing manipulation can lead to authentication bypass using alternate channel.
This vulnerability is handled as CVE-2025-11984. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2025-12562 | GitLab Community Edition/Enterprise Edition up to 18.4.5/18.5.3/18.6.1 GraphQL allocation of resources (Issue 579152 / EUVD-2025-202658)
1 month ago
A vulnerability has been found in GitLab Community Edition and Enterprise Edition up to 18.4.5/18.5.3/18.6.1 and classified as critical. The impacted element is an unknown function of the component GraphQL. Performing manipulation results in allocation of resources.
This vulnerability was named CVE-2025-12562. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2025-13978 | GitLab Community Edition/Enterprise Edition up to 18.4.5/18.5.3/18.6.1 Private Project information exposure (ID 566960 / EUVD-2025-202660)
1 month ago
A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 18.4.5/18.5.3/18.6.1 and classified as problematic. This affects an unknown function of the component Private Project Handler. Executing manipulation can lead to information exposure through error message.
The identification of this vulnerability is CVE-2025-13978. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-12716 | GitLab Community Edition/Enterprise Edition up to 18.4.5/18.5.3/18.6.1 cross site scripting (Issue 579548 / EUVD-2025-202659)
1 month ago
A vulnerability labeled as problematic has been found in GitLab Community Edition and Enterprise Edition up to 18.4.5/18.5.3/18.6.1. The affected element is an unknown function. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2025-12716. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2025-14157 | GitLab Community Edition/Enterprise Edition up to 18.4.5/18.5.3/18.6.1 API allocation of resources (Issue 574324 / EUVD-2025-202661)
1 month ago
A vulnerability marked as critical has been reported in GitLab Community Edition and Enterprise Edition up to 18.4.5/18.5.3/18.6.1. The impacted element is an unknown function of the component API Handler. This manipulation causes allocation of resources.
This vulnerability is registered as CVE-2025-14157. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-67738 | Webmin up to 2.599 Squid squid/cachemgr.cgi os command injection (EUVD-2025-202665)
1 month ago
A vulnerability classified as critical was found in Webmin up to 2.599. This affects an unknown function of the file squid/cachemgr.cgi of the component Squid Module. Executing manipulation can lead to os command injection.
This vulnerability is registered as CVE-2025-67738. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-14528 | D-Link DIR-803 up to 1.04 Configuration /getcfg.php AUTHORIZED_GROUP information disclosure
1 month ago
A vulnerability categorized as problematic has been discovered in D-Link DIR-803 up to 1.04. Impacted is an unknown function of the file /getcfg.php of the component Configuration Handler. The manipulation of the argument AUTHORIZED_GROUP results in information disclosure. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability was named CVE-2025-14528. The attack may be performed from remote. In addition, an exploit is available.
Applying restrictive firewalling is recommended.
vuldb.com
F5 strengthens ADSP with enhanced API discovery and threat detection
1 month ago
F5 unveiled enhancements to the F5 Application Delivery and Security Platform (ADSP). The latest updates focus on strengthening API discovery capabilities, improving threat detection, and optimizing network connectivity. These updated capabilities are in the latest 7.0 release of F5 Distributed Cloud Services, marking a major update that strengthens visibility and offers greater control for protecting APIs. “APIs are everywhere, powering every connection across apps, users, and data,” said Kunal Anand, Chief Product Officer at F5. … More →
The post F5 strengthens ADSP with enhanced API discovery and threat detection appeared first on Help Net Security.
Industry News
CVE-2025-64701 | QualitySoft QND Standard/QND Advance/QND Premium up to 11.0.9i privilege chaining (EUVD-2025-202666)
1 month ago
A vulnerability was found in QualitySoft QND Standard, QND Advance and QND Premium up to 11.0.9i. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to privilege chaining.
This vulnerability is uniquely identified as CVE-2025-64701. Local access is required to approach this attack. No exploit exists.
vuldb.com
Submit #703150: D-Link DIR-803 1.04 and earlier Authorization Bypass [Accepted]
1 month ago
Submit #703150 / VDB-335869
Submit #703137: code projects Faculty Management System V2.0.3 SQL injection [Duplicate]
1 month ago
Submit #703137 / VDB-248948
chaste
Доставки не будет, расходимся. Киберпреступники нашли способ устроить логистический коллапс, не выходя из дома
1 month ago
Хакеры научились идеально притворяться теми, кому бизнес привык доверять безоговорочно.
我看 MiniMax 闫俊杰:「心舟」已过万重山
1 month ago
大模型带来的一个变化,就是新时代的中国技术创业者,即便依旧需要商业世界的支持,也终于可以放下技术理想带来的「羞耻感」了。