Aggregator
CVE-2025-52546 | Copeland LP E3 Supervisory Control up to 2.31F00 Floor Plan unrestricted upload
CVE-2025-6519 | Copeland LP E3 Supervisory Control up to 2.31F00 insufficiently protected credentials
CVE-2025-52550 | Copeland LP E3 Supervisory Control up to 2.31F00 Application Service signature verification
CVE-2025-52547 | Copeland LP E3 Supervisory Control up to 2.31F00 Application Service denial of service
Akira
You must login to view this content
CVE-2025-52545 | Copeland LP E3 Supervisory Control up to 2.31F00 RCI Service insufficiently protected credentials
CVE-2025-52544 | Copeland LP E3 Supervisory Control up to 2.31F00 Floor Plan input validation
CVE-2025-52543 | Copeland LP E3 Supervisory Control up to 2.31F00 password hash instead of password for authentication
Akira
You must login to view this content
CVE-2025-52548 | Copeland LP E3 Supervisory Control up to 2.31F00 Application Service inclusion of undocumented features or chicken bits
CVE-2024-58259 | SUSE rancher up to 2.9.10/2.10.8/2.11.4/2.12.0 API Endpoint allocation of resources (EUVD-2024-54940)
CVE-2025-46810 | openSUSE Tumbleweed up to 2.11.28 symlink (EUVD-2025-26380)
CVE-2025-52549 | Copeland LP E3 Supervisory Control up to 2.31F00 insufficiently protected credentials
CVE-2025-5662 | h2oai h2o-3 3.46.0.4 MySQL JDBC Driver /99/ImportSQLTable deserialization
CVE-2025-56254 | PHPGurukul Employee Leave Management System 2.1 leave-details.php leaveid resource injection (EUVD-2025-26376)
7 месяцев создания, 15 лет диктатуры — один человек контролирует код миллионов программистов
CISA Releases Four Industrial Control Systems Advisories
CISA released four Industrial Control Systems (ICS) advisories on September 2, 2025. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.
- ICSA-25-245-01 Delta Electronics EIP Builder
- ICSA-25-245-02 Fuji Electric FRENIC-Loader 4
- ICSA-25-245-03 SunPower PVS6
- ICSA-25-182-06 Hitachi Energy Relion 670/650 and SAM600-IO Series (Update A)
CISA encourages users and administrators to review newly released ICS advisories for technical details and mitigations.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2020-24363 TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability
- CVE-2025-55177 Meta Platforms WhatsApp Incorrect Authorization Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.