A vulnerability identified as problematic has been detected in Craft CMS up to 4.16.16/5.8.20. This issue affects some unknown processing of the component Control Panel. This manipulation causes use of externally-controlled input to select classes or code.
This vulnerability is tracked as CVE-2025-68455. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability categorized as critical has been discovered in Craft CMS up to 4.16.16/5.8.20. This vulnerability affects unknown code of the component Database Backup Handler. The manipulation results in allocation of resources.
This vulnerability is identified as CVE-2025-68456. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability was found in aio-libs aiohttp up to 3.13.2. It has been rated as critical. This affects an unknown part of the component Python HTTP Parser. The manipulation leads to http request smuggling.
This vulnerability is referenced as CVE-2025-69224. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
A vulnerability was found in aio-libs aiohttp up to 3.13.2. It has been declared as critical. Affected by this issue is the function web.static. Executing a manipulation can lead to path traversal.
The identification of this vulnerability is CVE-2025-69226. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in aio-libs aiohttp up to 3.13.2. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component Parser. Performing a manipulation results in http request smuggling.
This vulnerability was named CVE-2025-69225. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability was found in aio-libs aiohttp up to 3.13.2 and classified as problematic. Affected is the function Request.post of the component Message Handler. Such manipulation leads to infinite loop.
This vulnerability is uniquely identified as CVE-2025-69227. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability has been found in aio-libs aiohttp up to 3.13.2 and classified as critical. This impacts the function request.read of the component Endpoint. This manipulation causes allocation of resources.
This vulnerability is handled as CVE-2025-69229. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
A vulnerability, which was classified as critical, was found in aio-libs aiohttp up to 3.13.2. This affects the function Request.post. The manipulation results in allocation of resources.
This vulnerability is known as CVE-2025-69228. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
A vulnerability, which was classified as critical, has been found in aio-libs aiohttp up to 3.13.2. The impacted element is an unknown function of the component Cookie Handler. The manipulation leads to logging of excessive data.
This vulnerability is traded as CVE-2025-69230. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability classified as critical was found in aio-libs aiohttp up to 3.13.2. The affected element is an unknown function. Executing a manipulation can lead to highly compressed data.
This vulnerability appears as CVE-2025-69223. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
Currently trending CVE - Hype Score: 3 - A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Networks PAN-OS® software enables execution of malicious JavaScript in the context of an authenticated Captive Portal user's browser when they click on a specially ...
Despite Cisco's Cyber Struggles, the Perks of Offering Asset Management Are Clear Cisco is eyeing what would be its third-largest cybersecurity acquisition ever, Calcalist reported: a $2 billion buy of New York-based asset management vendor Axonius. The Israeli business publication said Sunday the two sides are in advanced negotiations. Axonius denied the Calcalist report.