A vulnerability described as problematic has been identified in Google Go. Affected by this vulnerability is the function p256NegCond of the component crypto-elliptic. Executing manipulation can lead to information exposure through discrepancy.
This vulnerability is tracked as CVE-2025-22866. The attack can be launched remotely. No exploit exists.
Applying a patch is advised to resolve this issue.
With legit sounding names, EvilAI's "productivity" apps are reviving classic threats like Trojans while adding new evasion capabilities against modern antivirus defenses.
A vulnerability categorized as critical has been discovered in linlinjava litemall up to 1.8.0. This affects the function WxAftersaleController of the file /wx/aftersale/cancel. Executing manipulation of the argument ID can lead to improper authorization.
This vulnerability is handled as CVE-2025-10291. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in dpgaspar Flask-AppBuilder up to 4.8.0. It has been rated as critical. The impacted element is an unknown function. Performing manipulation results in improper authentication.
This vulnerability is known as CVE-2025-58065. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
A vulnerability was found in Liferay Portal and DXP. It has been declared as critical. The affected element is an unknown function. Such manipulation leads to authorization bypass.
This vulnerability is traded as CVE-2025-43790. The attack may be launched remotely. There is no exploit available.
A vulnerability labeled as problematic has been found in Portabilis i-Diario 1.5.0. This affects an unknown function of the file /justificativas-de-falta. Executing manipulation of the argument Justificativa can lead to cross site scripting.
The identification of this vulnerability is CVE-2025-7872. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability has been found in Google Android and classified as problematic. This issue affects some unknown processing of the file WVDrmPlugin.cpp. Performing manipulation results in use after free.
This vulnerability is known as CVE-2023-21101. Attacking locally is a requirement. No exploit is available.
To fix this issue, it is recommended to deploy a patch.
A vulnerability classified as problematic was found in Google Android 12.0/13.0. This affects the function applySyncTransaction of the file WindowOrganizer.java. The manipulation results in information disclosure.
This vulnerability is known as CVE-2023-21104. Attacking locally is a requirement. No exploit is available.
It is best practice to apply a patch to resolve this issue.
A vulnerability was found in Google Android 11.0/12.0/13.0 and classified as problematic. This impacts the function registerPhoneAccount of the file PhoneAccountRegistrar.java. The manipulation results in denial of service.
This vulnerability was named CVE-2023-21103. The attack needs to be approached locally. There is no available exploit.
Applying a patch is advised to resolve this issue.
This post first appeared on blog.netwrix.com and was written by Dirk Schrader. A Security Posture Assessment (SPA) provides a holistic evaluation of an organization’s cybersecurity readiness. It identifies vulnerabilities, evaluates compliance, and recommends actionable improvements across systems, users, policies, and tools. Netwrix solutions like DSPM help strengthen defenses, maintain compliance, and reduce the risk of data breaches. What Is a Security Posture Assessment? A Security Posture Assessment … Continued
A vulnerability, which was classified as critical, has been found in litemall 0.9.0. The impacted element is an unknown function of the file linlinjava/litemall/wx/web/WxStorageController.java. The manipulation with the input ../ leads to path traversal.
This vulnerability is listed as CVE-2018-18434. The attack may be initiated remotely. There is no available exploit.
A vulnerability was found in EspoCRM up to 9.1.6. It has been rated as problematic. The affected element is an unknown function of the component Router Cache. The manipulation leads to http request smuggling.
This vulnerability is documented as CVE-2025-52892. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability labeled as problematic has been found in Microsoft Windows. The impacted element is an unknown function of the component Imaging. Executing manipulation can lead to uninitialized resource.
This vulnerability is tracked as CVE-2025-53799. The attack is restricted to local execution. No exploit exists.
A patch should be applied to remediate this issue.
A vulnerability marked as critical has been reported in Microsoft Windows. This affects an unknown function of the component Graphics. The manipulation leads to incorrect initialization of resource.
This vulnerability is listed as CVE-2025-53800. The attack must be carried out locally. There is no available exploit.
To fix this issue, it is recommended to deploy a patch.
A vulnerability described as critical has been identified in Microsoft Windows. This impacts an unknown function of the component DWM Core Library. The manipulation results in untrusted pointer dereference.
This vulnerability is cataloged as CVE-2025-53801. The attack must be initiated from a local position. There is no exploit available.
It is advisable to implement a patch to correct this issue.