WhatsApp warns users targeted by advanced spyware, sending threat notifications to affected individuals from the past 90 days. A new zero-click exploit used to hack WhatsApp users, reported Donncha Ó Cearbhaill, Head of Security Lab at @AmnestyTech. WhatsApp has just sent out a round of threat notifications to individuals they believe were targeted by an […]
A vulnerability was found in glpi up to 10.0.18. It has been rated as critical. Affected is an unknown function. Performing manipulation results in improper privilege management.
This vulnerability was named CVE-2025-53105. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability categorized as critical has been discovered in readarr 0.4.15.2787. Affected by this vulnerability is an unknown functionality of the file /api/v1/wanted/cutoff of the component API Endpoint. Executing manipulation of the argument sortKey can lead to sql injection.
The identification of this vulnerability is CVE-2025-50983. The attack may be launched remotely. There is no exploit available.
A vulnerability identified as critical has been detected in diskover-web Community Edition 2.3.0. Affected by this issue is some unknown functionality. The manipulation of the argument ES_PASS/ES_MAXSIZE/ES_TRANSLOGSIZE/ES_TIMEOUT/ES_USER/ES_HOST/ES_PORT/ES_SCROLLSIZE/ES_CHUNKSIZE leads to sql injection.
This vulnerability is referenced as CVE-2025-50984. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability classified as problematic has been found in diskover-web Community Edition 2.3.0. Impacted is an unknown function of the component Administrative Settings Interface. Performing manipulation of the argument ES_HOST/ES_INDEXREFRESH/ES_PORT/ES_SCROLLSIZE/ES_TRANSLOGSIZE/ES_TRANSLOGSYNCINT/EXCLUDES_FILES/FILE_TYPES[]/INCLUDES_DIRS/INCLUDES_FILES/TIMEZONE results in cross site scripting.
This vulnerability is cataloged as CVE-2025-50986. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability, which was classified as problematic, has been found in Freeform up to 5.10.15 on CraftCMS. The impacted element is an unknown function. The manipulation leads to improper neutralization of special elements used in a template engine.
This vulnerability is documented as CVE-2025-52122. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability has been found in Gitblit 1.7.1 and classified as problematic. This impacts an unknown function. This manipulation causes cross site scripting.
This vulnerability appears as CVE-2025-50978. The attack may be initiated remotely. There is no available exploit.
A vulnerability was found in Bevy Event Service up to 2025-07-22 and classified as problematic. Affected is an unknown function of the file /notifications/delete/. Such manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2025-54598. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in Cisco NX-OS. It has been declared as problematic. Affected by this issue is some unknown functionality of the component Protocol Independent Multicast Version 6. Executing manipulation can lead to null pointer dereference.
This vulnerability is handled as CVE-2025-20262. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Cisco NX-OS, NX-OS ACI Mode and Unified Computing System. It has been rated as critical. This affects an unknown part of the component CLI. The manipulation leads to os command injection.
This vulnerability is uniquely identified as CVE-2025-20292. Local access is required to approach this attack. No exploit exists.
Upgrading the affected component is advised.
A vulnerability categorized as critical has been discovered in Cisco NX-OS. This vulnerability affects unknown code of the component System-to-Intermediate System. The manipulation results in compiler optimization removal or modification of security-critical code.
This vulnerability was named CVE-2025-20241. The attack needs to be approached within the local network. There is no available exploit.
It is advisable to upgrade the affected component.
A vulnerability identified as problematic has been detected in Cisco NX-OS and Unified Computing System. This issue affects some unknown processing of the component Logging. This manipulation causes information disclosure.
The identification of this vulnerability is CVE-2025-20290. The attack can only be executed locally. There is no exploit available.
You should upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in Cisco Unified Computing System. Affected is an unknown function of the component Web-based Management Interface. This manipulation causes cross site scripting.
This vulnerability is registered as CVE-2025-20296. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability classified as critical was found in Cisco Unified Computing System. This impacts an unknown function of the component CLI. The manipulation results in os command injection.
This vulnerability is cataloged as CVE-2025-20295. The attack must be initiated from a local position. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability, which was classified as problematic, has been found in Consensys gnark 0.12.0. The affected element is an unknown function. Performing manipulation results in resource consumption.
This vulnerability is reported as CVE-2025-58157. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability classified as problematic was found in tokio-rs tracing up to 0.3.19. Impacted is an unknown function of the component ANSI Escape Sequence Handler. Such manipulation leads to improper neutralization of escape, meta, or control sequences.
This vulnerability is documented as CVE-2025-58160. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability classified as problematic has been found in Ocean Extra Plugin up to 2.4.9 on WordPress. This issue affects the function oceanwp_library of the component Shortcode Handler. This manipulation causes cross site scripting.
This vulnerability is registered as CVE-2025-9499. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability described as problematic has been identified in TablePress Plugin up to 3.2 on WordPress. This vulnerability affects unknown code of the component Shortcode Handler. The manipulation of the argument shortcode_debug results in cross site scripting.
This vulnerability is cataloged as CVE-2025-9500. The attack may be launched remotely. There is no exploit available.
A vulnerability marked as critical has been reported in Eventlet up to 0.40.2 on Python. This affects an unknown part of the component WSGI Parser. The manipulation leads to http request smuggling.
This vulnerability is listed as CVE-2025-58068. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.