Aggregator
CVE-2025-47790 | Nextcloud Server up to 29.0.14/30.0.8/31.0.2 config.php remember_login_cookie_lifetime improper authentication (GHSA-9h3w-f3h4-qqrh)
8 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Nextcloud Server up to 29.0.14/30.0.8/31.0.2. This vulnerability affects unknown code of the file config.php. Such manipulation of the argument remember_login_cookie_lifetime leads to improper authentication.
This vulnerability is referenced as CVE-2025-47790. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2025-47794 | Nextcloud Server up to 29.0.12/30.0.6/31.0.0 Temporary File access control
8 months 3 weeks ago
A vulnerability identified as critical has been detected in Nextcloud Server up to 29.0.12/30.0.6/31.0.0. This affects an unknown part of the component Temporary File Handler. The manipulation leads to improper access controls.
This vulnerability is documented as CVE-2025-47794. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2025-47850 | JetBrains YouTrack up to 2024.3.55417 Attachment missing authentication
8 months 3 weeks ago
A vulnerability identified as critical has been detected in JetBrains YouTrack. Impacted is an unknown function of the component Attachment Handler. This manipulation causes missing authentication.
This vulnerability is tracked as CVE-2025-47850. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2025-48391 | JetBrains YouTrack up to 2025.1.74704 API missing authentication
8 months 3 weeks ago
A vulnerability classified as critical was found in JetBrains YouTrack. Affected is an unknown function of the component API. The manipulation results in missing authentication.
This vulnerability is reported as CVE-2025-48391. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-6276 | Brilliance Golden Link Secondary System up to 20250609 rentTakeInfoPage.htm custTradeName sql injection (EUVD-2025-18934)
8 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Brilliance Golden Link Secondary System up to 20250609. Affected is an unknown function of the file /storagework/rentTakeInfoPage.htm. This manipulation of the argument custTradeName causes sql injection.
The identification of this vulnerability is CVE-2025-6276. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6277 | Brilliance Golden Link Secondary System up to 20250609 custTakeInfoPage.htm custTradeName sql injection (EUVD-2025-18935)
8 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Brilliance Golden Link Secondary System up to 20250609. Affected by this vulnerability is an unknown functionality of the file /storagework/custTakeInfoPage.htm. Such manipulation of the argument custTradeName leads to sql injection.
This vulnerability is referenced as CVE-2025-6277. It is possible to launch the attack remotely. Furthermore, an exploit is available.
vuldb.com
CVE-2025-6365 | HobbesOSR Kitten up to c4f8b7c3158983d1020af432be1b417b28686736 pgtable.h set_pte_at resource consumption (Issue 17 / EUVD-2025-18789)
8 months 3 weeks ago
A vulnerability identified as critical has been detected in HobbesOSR Kitten up to c4f8b7c3158983d1020af432be1b417b28686736. Affected by this vulnerability is the function set_pte_at in the library /include/arch-arm64/pgtable.h. This manipulation causes resource consumption.
This vulnerability is tracked as CVE-2025-6365. The attack is only possible within the local network. No exploit exists.
This product adopts a rolling release strategy to maintain continuous delivery
vuldb.com
CVE-2025-6282 | xlang-ai OpenAgents up to ff2e46440699af1324eb25655b622c4a131265bb backend/api/file.py create_upload_file path traversal (Issue 141 / EUVD-2025-18699)
8 months 3 weeks ago
A vulnerability was found in xlang-ai OpenAgents up to ff2e46440699af1324eb25655b622c4a131265bb. It has been rated as critical. Impacted is the function create_upload_file of the file backend/api/file.py. This manipulation causes path traversal.
This vulnerability is registered as CVE-2025-6282. The attack requires access to the local network. Furthermore, an exploit is available.
This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided.
The reported GitHub issue was closed automatically with the label "not planned" by a bot.
vuldb.com
CVE-2025-6283 | xataio Xata Agent up to 0.3.0 route.ts GET passed path traversal (EUVD-2025-18705)
8 months 3 weeks ago
A vulnerability categorized as critical has been discovered in xataio Xata Agent up to 0.3.0. The affected element is the function GET of the file apps/dbagent/src/app/api/evals/route.ts. Such manipulation of the argument passed leads to path traversal.
This vulnerability is documented as CVE-2025-6283. The attack requires being on the local network. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-32999 | Appleple A-Blog CMS up to 3.0.47/3.1.43 cross site scripting (EUVD-2025-15670)
8 months 3 weeks ago
A vulnerability identified as problematic has been detected in Appleple A-Blog CMS up to 3.0.47/3.1.43. The affected element is an unknown function. This manipulation causes cross site scripting.
This vulnerability is registered as CVE-2025-32999. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2025-27566 | Appleple A-Blog CMS up to 3.0.46/3.1.42 Backup path traversal (EUVD-2025-15666)
8 months 3 weeks ago
A vulnerability was found in Appleple A-Blog CMS up to 3.0.46/3.1.42. It has been declared as critical. This vulnerability affects unknown code of the component Backup. Executing manipulation can lead to path traversal.
This vulnerability is tracked as CVE-2025-27566. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-41429 | Appleple A-Blog CMS neutralization for logs (EUVD-2025-15667)
8 months 3 weeks ago
A vulnerability was found in Appleple A-Blog CMS. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to improper output neutralization for logs.
This vulnerability is listed as CVE-2025-41429. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2025-36560 | Appleple A-Blog CMS server-side request forgery (EUVD-2025-15669)
8 months 3 weeks ago
A vulnerability categorized as critical has been discovered in Appleple A-Blog CMS. Impacted is an unknown function. The manipulation results in server-side request forgery.
This vulnerability is cataloged as CVE-2025-36560. The attack may be launched remotely. There is no exploit available.
vuldb.com
Daily Dose of Dark Web Informer - 30th of September 2025
8 months 3 weeks ago
This daily article is intended to make it easier for those who want to stay updated with my regular Dark Web Informer and X/Twitter posts.
Dark Web Informer
CVE-2025-25968 | DDSN Interactive cm3 Acora CMS 10.1.1 File access control (EUVD-2025-4570)
8 months 3 weeks ago
A vulnerability was found in DDSN Interactive cm3 Acora CMS 10.1.1. It has been classified as critical. This affects an unknown part. The manipulation of the argument File leads to improper access controls.
This vulnerability is documented as CVE-2025-25968. The attack requires being on the local network. There is not any exploit available.
vuldb.com
CVE-2025-26877 | Rustaurius Front End Users Plugin up to 3.2.30 on WordPress cross site scripting
8 months 3 weeks ago
A vulnerability was found in Rustaurius Front End Users Plugin up to 3.2.30 on WordPress. It has been classified as problematic. This affects an unknown part. This manipulation causes cross site scripting.
The identification of this vulnerability is CVE-2025-26877. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-26876 | CodeManas Search with Typesense Plugin up to 2.0.8 on WordPress path traversal
8 months 3 weeks ago
A vulnerability was found in CodeManas Search with Typesense Plugin up to 2.0.8 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. Such manipulation leads to path traversal: '.../...//'.
This vulnerability is referenced as CVE-2025-26876. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2025-29932 | JetBrains GoLand 2019.3.2 Debbugging xml external entity reference
8 months 3 weeks ago
A vulnerability was found in JetBrains GoLand 2019.3.2. It has been classified as problematic. This affects an unknown function of the component Debbugging. This manipulation causes xml external entity reference.
This vulnerability appears as CVE-2025-29932. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2024-52980 | Elasticsearch up to 8.15.0 innerForbidCircularReferences resource consumption
8 months 3 weeks ago
A vulnerability was found in Elasticsearch up to 8.15.0 and classified as problematic. Impacted is the function innerForbidCircularReferences. Such manipulation leads to resource consumption.
This vulnerability is uniquely identified as CVE-2024-52980. The attack can be launched remotely. No exploit exists.
vuldb.com