A vulnerability identified as problematic has been detected in Netgate pfSense CE 7.0.8_2. Impacted is an unknown function of the file /suricata/suricata_app_parsers.php. The manipulation of the argument policy_name leads to cross site scripting.
This vulnerability is traded as CVE-2025-34178. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability labeled as problematic has been found in Netgate pfSense CE 7.0.8_2. The affected element is an unknown function of the file /suricata/suricata_flow_stream.php. The manipulation of the argument policy_name results in cross site scripting.
This vulnerability is known as CVE-2025-34177. It is possible to launch the attack remotely. No exploit is available.
A vulnerability, which was classified as problematic, has been found in Netgate pfSense CE 0.63_10. Affected by this vulnerability is an unknown functionality of the file /usr/local/www/haproxy/haproxy_stats.php of the component HTTP GET Request Handler. The manipulation of the argument showsticktablecontent leads to cross site scripting.
This vulnerability is referenced as CVE-2025-34172. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to install a patch to address this issue.
A vulnerability was found in Netgate pfSense CE 2.3.2_7 and classified as problematic. This vulnerability affects unknown code of the file /usr/local/www/status_traffic_totals.php of the component Status Traffic Totals Page. Such manipulation of the argument start-day leads to cross site scripting.
This vulnerability is listed as CVE-2025-34174. The attack may be performed from remote. There is no available exploit.
It is advisable to implement a patch to correct this issue.
A vulnerability was found in Netgate pfSense CE 7.0.8_2. It has been classified as problematic. This issue affects some unknown processing of the file /usr/local/www/suricata/suricata_filecheck.php. Performing manipulation of the argument filehash results in cross site scripting.
This vulnerability is cataloged as CVE-2025-34175. It is possible to initiate the attack remotely. There is no exploit available.
Applying a patch is the recommended action to fix this issue.
A vulnerability has been found in knadh listmonk up to 1.1.0 and classified as problematic. The affected element is an unknown function. The manipulation leads to basic cross site scripting.
This vulnerability is uniquely identified as CVE-2025-58430. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability has been found in huggingface transformers up to 4.52.x and classified as problematic. The impacted element is the function _do_use_weight_decay. Performing manipulation results in resource consumption.
This vulnerability is cataloged as CVE-2025-6921. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
A vulnerability, which was classified as critical, was found in Datart 1.0.0-rc.3. Impacted is an unknown function. Executing manipulation of the argument INIT can lead to os command injection.
This vulnerability is handled as CVE-2025-56819. The attack can be executed remotely. There is not any exploit available.
A vulnerability classified as critical was found in mirweiye wenkucms up to 3.4. This impacts the function createPathOne of the file app/common/common.php. The manipulation results in os command injection.
This vulnerability is cataloged as CVE-2025-11138. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability identified as critical has been detected in SeaCMS 13.3.20250820. Impacted is an unknown function of the file /admin_cron.php of the component Cron Task Management Module. The manipulation of the argument resourcefrom/collectID leads to sql injection.
This vulnerability is documented as CVE-2025-11071. The attack can be initiated remotely. Additionally, an exploit exists.
In Today's Reality, Zero Trust Principles Matter, Verification Is an Imperative This month, a judge made history by throwing out an $8.7 million lawsuit after discovering something that had never before appeared in her courtroom: deepfake testimony. But these new legal lessons are already a reality in business: the need for trust, verification and authentic communication.
US Cyber Defense Agency Slammed by Shutdown, Personnel Cuts and Resource Crisis Facing major turnover, partisan upheaval and a government shutdown, the U.S. cyber defense agency is now operating at a fraction of its strength, leaving states and other entities without federal cyber support or coordination, experts tell Information Security Media Group.
Pete Harteveld Seeks to Strengthen Security Operations With Programmatic Approach New Exabeam CEO Pete Harteveld emphasizes securing AI agents, minimizing tool sprawl and promoting defined security outcomes. His roadmap builds on recent success and aims to deliver programmatic SIEM and UEBA innovations to improve analyst efficiency and benchmarking.
Attackers Read Server Files and Steal Credentials in Gladinet CentreStack, Triofox Hackers are exploiting a flaw allowing them to access without authentication document root folder files in file-sharing and remote-access software, where they obtain access tokens and passwords to unlock remote access to corporate file systems, warn researchers.