Aggregator
CVE-2025-29513 | NodeBB up to 4.0.4 Admin API Access Token cross site scripting
9 months 3 weeks ago
A vulnerability has been found in NodeBB up to 4.0.4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Admin API Access Token Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-29513. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-28355 | Volmarg Personal Management System 1.4.65 cross-site request forgery
9 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Volmarg Personal Management System 1.4.65. Affected is an unknown function. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2025-28355. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-24914 | Tenable Nessus up to 10.8.3 default permission
9 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Tenable Nessus up to 10.8.3. This issue affects some unknown processing. The manipulation leads to incorrect default permissions.
The identification of this vulnerability is CVE-2025-24914. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Seeking Post-Mitre Management: What's Next for CVE Program?
9 months 3 weeks ago
Despite Last-Minute Reprieve, Fresh Approach and Ownership Required, and Soon
This week's near-disruption in funding for the Mitre-administered Common Vulnerabilities and Exposures Program shows that the U.S. government no longer wants to be footing the tab. Many experts say this is an opportunity to redesign the CVE Program to be more neutral, sustainable and international.
This week's near-disruption in funding for the Mitre-administered Common Vulnerabilities and Exposures Program shows that the U.S. government no longer wants to be footing the tab. Many experts say this is an opportunity to redesign the CVE Program to be more neutral, sustainable and international.
ISMG Editors: Chris Krebs Resigns as Silent Industry Watches
9 months 3 weeks ago
Also: CVE Program Faces Funding Cliff, Whistleblower Flags DOGE Cybersecurity Gaps
In this week's update, ISMG editors unpacked a whirlwind of cybersecurity drama related to the U.S. government, including Chris Krebs' abrupt exit from SentinelOne to defend against President Trump, the CVE program funding scare and explosive whistleblower claims against Elon Musk's DOGE task force.
In this week's update, ISMG editors unpacked a whirlwind of cybersecurity drama related to the U.S. government, including Chris Krebs' abrupt exit from SentinelOne to defend against President Trump, the CVE program funding scare and explosive whistleblower claims against Elon Musk's DOGE task force.
Minnesota Dental Clinic Notifying 135,000 of 2024 Hack
9 months 3 weeks ago
Community Dental Care Is State's Largest Non-Profit Serving Medicaid Patients
Minnesota's largest nonprofit Medicaid dental practice is notifying nearly 135,000 people of a December 2024 data theft incident that potentially compromised their health and personal information, ranging from medical information to passport numbers.
Minnesota's largest nonprofit Medicaid dental practice is notifying nearly 135,000 people of a December 2024 data theft incident that potentially compromised their health and personal information, ranging from medical information to passport numbers.
Breakthroughs, Concerns in OpenAI's Latest Lineup
9 months 3 weeks ago
Safety Concerns Emerge Amid o3, o4-mini and GPT-4.1 Launches
OpenAI's mid-April announcements include its most advanced reasoning models o3 and o4-mini, with a biorisk monitor, the quietly released GPT-4.1 coding family and the upcoming retirement of its costliest model, GPT-4.5. OpenAI's partners warn that the company's rushed evaluations have left gaps.
OpenAI's mid-April announcements include its most advanced reasoning models o3 and o4-mini, with a biorisk monitor, the quietly released GPT-4.1 coding family and the upcoming retirement of its costliest model, GPT-4.5. OpenAI's partners warn that the company's rushed evaluations have left gaps.
Microsoft's New Model Aims to Do More With Less
9 months 3 weeks ago
BitNet b1.58 2B4T Focuses on Speed, Efficiency, Open Access
Microsoft released what it describes as the most expansive 1-bit AI model to date, BitNet b1.58 2B4T. Unlike traditional large language models that depend on GPUs and massive infrastructure, the model is built to operate efficiently on CPUs including Apple's M2 chip.
Microsoft released what it describes as the most expansive 1-bit AI model to date, BitNet b1.58 2B4T. Unlike traditional large language models that depend on GPUs and massive infrastructure, the model is built to operate efficiently on CPUs including Apple's M2 chip.
BSidesLV24 – Common Ground – One Port to Serve Them All – Google GCP Cloud Shell Abuse
9 months 3 weeks ago
Author/Presenter: Hubert Lin
Our sincere appreciation to BSidesLV, and the Presenters/Authors for publishing their erudite Security BSidesLV24 content. Originating from the conference’s events located at the Tuscany Suites & Casino; and via the organizations YouTube channel.
The post BSidesLV24 – Common Ground – One Port to Serve Them All – Google GCP Cloud Shell Abuse appeared first on Security Boulevard.
Marc Handelman
CVE-2007-1369 | Zend Platform php.ini privileges management (EDB-29712 / XFDB-32820)
9 months 3 weeks ago
A vulnerability has been found in Zend Platform and classified as critical. This vulnerability affects unknown code of the file php.ini. The manipulation leads to improper privilege management.
This vulnerability was named CVE-2007-1369. The attack needs to be approached locally. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-28242 | DAEnetIP4 METO 1.25 /login_ok.htm user session
9 months 3 weeks ago
A vulnerability classified as problematic was found in DAEnetIP4 METO 1.25. This vulnerability affects unknown code of the file /login_ok.htm. The manipulation leads to manage user sessions.
This vulnerability was named CVE-2025-28242. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2025-28238 | Elber REBLE310 5.5.1.R user session
9 months 3 weeks ago
A vulnerability classified as problematic has been found in Elber REBLE310 5.5.1.R. This affects an unknown part. The manipulation leads to manage user sessions.
This vulnerability is uniquely identified as CVE-2025-28238. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2025-28231 | Itel IP Stream 1.7.0.6 access control
9 months 3 weeks ago
A vulnerability was found in Itel IP Stream 1.7.0.6. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2025-28231. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2025-28237 | WorldCast Systems ECRESO FM DAB TV Transmitter 1.10.1 JSON privilege escalation
9 months 3 weeks ago
A vulnerability was found in WorldCast Systems ECRESO FM DAB TV Transmitter 1.10.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component JSON Handler. The manipulation leads to privilege escalation.
This vulnerability is known as CVE-2025-28237. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2025-29512 | NodeBB up to 4.0.4 Blacklist IP cross site scripting
9 months 3 weeks ago
A vulnerability was found in NodeBB up to 4.0.4. It has been classified as problematic. Affected is an unknown function of the component Blacklist IP Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-29512. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-28233 | BW Broadcast TX50 1.7 access control
9 months 3 weeks ago
A vulnerability was found in BW Broadcast TX600 14980, TX300 32990 31448, TX150, TX1000, TX30 and TX50 1.7 and classified as critical. This issue affects some unknown processing. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2025-28233. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2025-1697 | HP Touchpoint Analytics Service prior 4.2.2439 link following
9 months 3 weeks ago
A vulnerability has been found in HP Touchpoint Analytics Service and classified as critical. This vulnerability affects unknown code. The manipulation leads to link following.
This vulnerability was named CVE-2025-1697. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-28235 | Soundcraft Ui12/Ui16 1.0.5x/1.0.7x /socket.io/1/websocket/ information disclosure
9 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Soundcraft Ui12 and Ui16 1.0.5x/1.0.7x. This affects an unknown part of the file /socket.io/1/websocket/. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2025-28235. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2025-28236 | Nautel VX up to 6.4.0 Update /#/software/upgrades privilege escalation
9 months 3 weeks ago
A vulnerability, which was classified as very critical, has been found in Nautel VX up to 6.4.0. Affected by this issue is some unknown functionality of the file /#/software/upgrades of the component Update Handler. The manipulation leads to privilege escalation.
This vulnerability is handled as CVE-2025-28236. The attack may be launched remotely. There is no exploit available.
vuldb.com