A vulnerability has been found in Ericsson RAN Compute Basebands and Site Controller 6610 and classified as very critical. This vulnerability affects unknown code of the component Configuration Handler. The manipulation leads to improper input validation.
This vulnerability was named CVE-2024-25010. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
Signal has updated its Windows app to protect users' privacy by blocking Microsoft's AI-powered Recall feature from taking screenshots of their conversations. [...]
A vulnerability, which was classified as critical, was found in Poedit up to 3.6.2 on macOS. This affects an unknown part. The manipulation leads to incorrect default permissions.
This vulnerability is uniquely identified as CVE-2025-4280. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in Blog2Social Plugin up to 8.3.x on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-4133. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
Prompt injection risks in GitLab's AI assistant could have allowed attackers to steal source code, or indirectly deliver developers malware, dirty links, and more.