Aggregator
CVE-2025-55069 | AutomationDirect CLICK PLUS C0-0x CPU up to 3.70 prng seed (icsa-25-266-01)
CVE-2025-57639 | Tenda AC9 1.0 formSetSambaConf usb.samba.guest.user os command injection
CVE-2025-58354 | kata-containers Kata Containers up to 3.20.x unusual condition (GHSA-989w-4xr2-ww9m)
CVE-2025-57882 | AutomationDirect CLICK PLUS C0-0x CPU up to 3.70 denial of service (icsa-25-266-01)
CVE-2025-55038 | AutomationDirect CLICK PLUS C0-0x CPU up to 3.70 KOPR Protocol authorization (icsa-25-266-01)
PhaseLoom: A Software Defined Radio Powered by the Chip used in the Commodore 64, NES and other Early Home Computers
CVE-2025-59825 | astral-sh tokio-tar up to 0.5.3 Entry::unpack_in_raw path traversal (ID 12163)
CVE-2025-45326 | PocketVJ CP PocketVJ-CP-v3 pvj 3.9.1 submit_size.php privilege escalation
CVE-2025-59546 | dnnsoftware Dnn.Platform up to 10.0.x module title cross site scripting (GHSA-gj8m-5492-q98h)
CVE-2025-59545 | dnnsoftware Dnn.Platform up to 10.0.x Prompt cross site scripting (GHSA-2qxc-mf4x-wr29)
CVE-2025-59547 | dnnsoftware Dnn.Platform up to 10.0.x CKEditor File Upload Endpoint unicode encoding (GHSA-cgqj-mw4m-v7hp)
CVE-2025-59548 | dnnsoftware Dnn.Platform up to 10.0.x FileBrowser cross site scripting (GHSA-5fj9-542v-w4rq)
CVE-2025-59821 | dnnsoftware Dnn.Platform up to 10.0.x cross site scripting (GHSA-jc4g-c8ww-5738)
CVE-2025-59539 | dnnsoftware Dnn.Platform up to 10.0.x Biography cross site scripting (GHSA-7rcc-q6rq-jpcm)
CVE-2025-58069 | AutomationDirect CLICK PLUS C0-0x CPU up to 3.70 Initial Message hard-coded key (icsa-25-266-01)
APIs and hardware are under attack, and the numbers don’t look good
Attackers have a new favorite playground, and it’s not where many security teams are looking. According to fresh data from Bugcrowd, vulnerabilities in hardware and APIs are climbing fast, even as website flaws hold steady. The shift shows how attackers are adapting to infrastructure, going after the hidden systems that keep businesses running. This graph shows the number of vulnerabilities over the past three years (Source: Bugcrowd) “We are in a high-stakes innovation race, but … More →
The post APIs and hardware are under attack, and the numbers don’t look good appeared first on Help Net Security.
Google’s $425 Million Fine a Win for Privacy, But Will it Stick?
Google must pay $425M for violating California privacy laws by tracking 98M users despite opt-outs. A major win for data privacy, though appeals loom.
The post Google’s $425 Million Fine a Win for Privacy, But Will it Stick? appeared first on Security Boulevard.