A vulnerability, which was classified as critical, was found in GHH Google Hack Honeypot File Upload Manager 1.3. This affects an unknown part of the file index.php of the component File Upload. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2008-5283. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as problematic, has been found in modelcontextprotocol python-sdk up to 1.9.3. This issue affects some unknown processing. The manipulation leads to uncaught exception.
The identification of this vulnerability is CVE-2025-53366. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Tunnelblick up to 6.x. It has been declared as critical. This vulnerability affects unknown code of the file Tunnelblick.app of the component Uninstall. The manipulation leads to incomplete cleanup.
This vulnerability was named CVE-2025-43711. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Netmake ScriptCase up to 9.12.006 (23). It has been rated as problematic. This issue affects some unknown processing of the file login.php.is of the component Production Environment Extension. The manipulation leads to incorrect provision of specified functionality.
The identification of this vulnerability is CVE-2025-47227. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Quest KACE Systems Management Appliance up to 14.0.96/14.1.18 and classified as critical. This vulnerability affects unknown code of the component Agent. The manipulation leads to incorrect authorization.
This vulnerability was named CVE-2025-26850. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in pimeys web-push Crate up to 0.10.2 on Rust. It has been classified as problematic. Affected is an unknown function. The manipulation leads to improper handling of length parameter inconsistency.
This vulnerability is traded as CVE-2025-53604. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Dradis up to 4.16.0. It has been classified as critical. This affects an unknown part of the component Image Parser. The manipulation leads to authentication bypass by capture-replay.
This vulnerability is uniquely identified as CVE-2023-50786. The attack needs to be approached within the local network. There is no exploit available.
Threat actors are weaponizing exposed Java Debug Wire Protocol (JDWP) interfaces to obtain code execution capabilities and deploy cryptocurrency miners on compromised hosts.
"The attacker used a modified version of XMRig with a hard-"coded configuration, allowing them to avoid suspicious command-line arguments that are often flagged by defenders," Wiz researchers Yaara Shriki and Gili
A vulnerability was found in pimeys web-push Crate up to 0.10.2 on Rust. It has been classified as problematic. Affected is an unknown function. The manipulation leads to improper handling of length parameter inconsistency.
This vulnerability is traded as CVE-2025-53604. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in stepancheg protobuf up to 3.7.1 and classified as problematic. This issue affects the function protobuf::coded_input_stream. The manipulation leads to uncontrolled recursion.
The identification of this vulnerability is CVE-2025-53605. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Quest KACE Systems Management Appliance up to 14.0.96/14.1.18 and classified as critical. This vulnerability affects unknown code of the component Agent. The manipulation leads to incorrect authorization.
This vulnerability was named CVE-2025-26850. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in Zipkin up to 3.5.1. This affects an unknown part of the file /heapdump of the component Spring Boot Actuator. The manipulation leads to insecure default initialization of resource.
This vulnerability is uniquely identified as CVE-2025-53602. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability, which was classified as problematic, has been found in Alinto SOPE SOGo up to 5.12.2. Affected by this issue is some unknown functionality of the file sope-core/NGExtensions/NGHashMap.m of the component Query String Handler. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2025-53603. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as critical was found in Netmake ScriptCase up to 9.12.006 (23). Affected by this vulnerability is an unknown functionality of the component Production Environment Extension. The manipulation leads to os command injection.
This vulnerability is known as CVE-2025-47228. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in modelcontextprotocol python-sdk up to 1.9.x. Affected is an unknown function. The manipulation leads to uncaught exception.
This vulnerability is traded as CVE-2025-53365. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Netmake ScriptCase up to 9.12.006 (23). It has been rated as problematic. This issue affects some unknown processing of the file login.php.is of the component Production Environment Extension. The manipulation leads to incorrect provision of specified functionality.
The identification of this vulnerability is CVE-2025-47227. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Tunnelblick up to 6.x. It has been declared as critical. This vulnerability affects unknown code of the file Tunnelblick.app of the component Uninstall. The manipulation leads to incomplete cleanup.
This vulnerability was named CVE-2025-43711. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Dradis up to 4.16.0. It has been classified as critical. This affects an unknown part of the component Image Parser. The manipulation leads to authentication bypass by capture-replay.
This vulnerability is uniquely identified as CVE-2023-50786. The attack needs to be approached within the local network. There is no exploit available.