A vulnerability was found in Microsoft Web Deploy 4.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to deserialization.
This vulnerability is known as CVE-2025-53772. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as problematic has been found in GitLab Community Edition and Enterprise Edition up to 18.0.5/18.1.3/18.2.1. Affected by this issue is some unknown functionality of the component API Endpoint. The manipulation leads to allocation of resources.
This vulnerability is handled as CVE-2025-1477. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability categorized as problematic has been discovered in GitLab Enterprise Edition up to 18.0.5/18.1.3/18.2.1. This issue affects some unknown processing of the component IP Restrictions Handler. The manipulation leads to insufficient granularity of access control.
The identification of this vulnerability is CVE-2025-2498. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Microsoft Visio. Affected by this vulnerability is an unknown functionality. The manipulation leads to use after free.
This vulnerability is known as CVE-2025-53730. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability marked as critical has been reported in Microsoft Excel. Affected is an unknown function. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2025-53741. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability described as critical has been identified in Microsoft Excel. Affected by this vulnerability is an unknown functionality. The manipulation leads to uninitialized resource.
This vulnerability is known as CVE-2025-53759. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as critical has been found in Microsoft SharePoint. Affected by this issue is some unknown functionality. The manipulation leads to server-side request forgery.
This vulnerability is handled as CVE-2025-53760. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
Recent advisories from U.S. federal authorities on vulnerabilities in certain operational technology devices underscore the potential security risks that many healthcare providers frequently underestimate, said Sila Özeren, a security research engineer at Picus Security.
Schellman CEO Avani Desai on Balancing Innovation and Compliance in Uncertain Market The Trump administration’s AI action plan signals a major deregulatory shift, setting up a patchwork of state regulations on AI deployments. Company policies must be “flexible enough to meet the strictest state without rewriting them every few months," said Avani Desai, CEO, Schellman.
Space Policy and Tech Head Paul Liias on Dealing With Satellite Vulnerabilities A major disruption of civil and military satellites could cause chaos on the ground to communications, navigation and other vital services. But the threats don't just come from missiles. They also comes from hackers who could exploit numerous vulnerabilities, said Estonia's Paul Liias.
Cyfinoid's Shrivastava Calls for Greater Visibility Over Software Security Risks Software supply chain security is all too often viewed through a narrow lens, focused mostly on code dependencies and Software Bill of Materials. But the devil remains in the details and risks can emerge from overlooked areas, said Anant Shrivastava, founder and chief researcher at Cyfinoid.