-
CVE-2025-1072 – GitLab DoS Vulnerability in Fogbugz Importer
CVE ID : CVE-2025-1072 Published : Feb. 7, 2025, 4:15 a.m. | 1 hour, 27 minutes ago Description : A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14.1 prior to 17.3.7, 17.4 prior to 17.4.4, and 17.5 prior to 17.5.2. A denial of service could occur upon importing…
-
CVE-2025-1086 – Safetytest Cloud-Master Server Remote Path Traversal Vulnerability
CVE ID : CVE-2025-1086 Published : Feb. 7, 2025, 2:15 a.m. | 3 hours, 26 minutes ago Description : A vulnerability has been found in Safetytest Cloud-Master Server up to 1.1.1 and classified as critical. This vulnerability affects unknown code of the file /static/. The manipulation leads to path traversal: ‘../filedir’. The attack can be initiated remotely.…
-
CVE-2025-22402 – Dell Update Manager Plugin Basic Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-22402 Published : Feb. 7, 2025, 3:15 a.m. | 2 hours, 27 minutes ago Description : Dell Update Manager Plugin, version(s) 1.5.0 through 1.6.0, contain(s) an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information…
-
CVE-2025-1061 – Nextend Social Login Pro WordPress Authentication Bypass
CVE ID : CVE-2025-1061 Published : Feb. 7, 2025, 2:15 a.m. | 1 hour, 50 minutes ago Description : The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.16. This is due to insufficient verification on the user being supplied during the Apple OAuth authenticate request through…
-
CVE-2025-0674 – Elber Password Management Authentication Bypass
CVE ID : CVE-2025-0674 Published : Feb. 7, 2025, 12:15 a.m. | 3 hours, 50 minutes ago Description : Multiple Elber products are affected by an authentication bypass vulnerability which allows unauthorized access to the password management functionality. Attackers can exploit this issue by manipulating the endpoint to overwrite any user’s password within the system. This grants…
-
CVE-2025-21408 – Microsoft Edge Chromium-based RCE
CVE ID : CVE-2025-21408 Published : Feb. 6, 2025, 11:15 p.m. | 4 hours, 50 minutes ago Description : Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more… Go to Source
-
CVE-2025-21342 – Microsoft Edge Chromium RCE
CVE ID : CVE-2025-21342 Published : Feb. 6, 2025, 11:15 p.m. | 4 hours, 50 minutes ago Description : Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more… Go to Source
-
CVE-2024-47258 – 2N Access Commander TLS Certificate Verification Weakness
CVE ID : CVE-2024-47258 Published : Feb. 6, 2025, 8:15 p.m. | 7 hours, 50 minutes ago Description : 2N Access Commander version 2.1 and prior is vulnerable in default settings to Man In The Middle attack due to not verifying certificates of 2N edge devices. Severity: 8.1 | HIGH Visit the link for more details, such…
-
CVE-2025-21177 – Microsoft Dynamics 365 Sales SSRF
CVE ID : CVE-2025-21177 Published : Feb. 6, 2025, 11:15 p.m. | 4 hours, 50 minutes ago Description : Server-Side Request Forgery (SSRF) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more……
-
CISA KEV Catalog Update Part III- February 2025
CISA KEV Catalog Update Part III- February 2025 The Cybersecurity and Infrastructure Security Agency (CISA) has recently updated its Known Exploited Vulnerabilities (KEV) Catalog, adding five new vulnerabilities that are actively being exploited in … Read more Published Date: Feb 07, 2025 (3 hours, 5 minutes ago) Vulnerabilities has been mentioned in this article. Go to Source