Aggregator
Secure Your Spot at RSAC 2026 Conference
1 week 6 days hence
[Virtual Event] Shields Up: Key Technologies Reshaping Cybersecurity Defenses
1 week 2 days hence
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
3 hours 10 minutes ago
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
SolarWinds security advisory (AV25-613) – Update 1
3 hours 22 minutes ago
Canadian Centre for Cyber Security
Ivanti security advisory (AV26-113) – Update 1
3 hours 39 minutes ago
Canadian Centre for Cyber Security
CVE-2025-70039 | linagora twake 2023.Q1.1223 os command injection
4 hours 43 minutes ago
A vulnerability has been found in linagora twake 2023.Q1.1223 and classified as critical. Impacted is an unknown function. This manipulation causes os command injection.
The identification of this vulnerability is CVE-2025-70039. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-70034 | mscdex ssh2 1.17.0 incorrect regex
4 hours 43 minutes ago
A vulnerability, which was classified as problematic, was found in mscdex ssh2 1.17.0. This issue affects some unknown processing. The manipulation results in incorrect regular expression.
This vulnerability was named CVE-2025-70034. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2025-70037 | linagora Twake 2023.Q1.1223 redirect
4 hours 44 minutes ago
A vulnerability, which was classified as problematic, has been found in linagora Twake 2023.Q1.1223. This vulnerability affects unknown code. The manipulation leads to open redirect.
This vulnerability is uniquely identified as CVE-2025-70037. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2025-70038 | linagora Twake 2023.Q1.1223 neutralization
4 hours 45 minutes ago
A vulnerability classified as critical was found in linagora Twake 2023.Q1.1223. This affects an unknown part. Executing a manipulation can lead to improper neutralization.
This vulnerability is handled as CVE-2025-70038. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2025-15568 | TP-Link Archer AXE75 up to 1.3.2 Build 20250107 Web Module os command injection
4 hours 45 minutes ago
A vulnerability classified as critical has been found in TP-Link Archer AXE75 up to 1.3.2 Build 20250107. Affected by this issue is some unknown functionality of the component Web Module. Performing a manipulation results in os command injection.
This vulnerability is known as CVE-2025-15568. Access to the local network is required for this attack. No exploit is available.
vuldb.com
CVE-2026-3588 | IKEA Dirigera up to 2.866.4 server-side request forgery
5 hours 47 minutes ago
A vulnerability described as critical has been identified in IKEA Dirigera up to 2.866.4. Affected by this vulnerability is an unknown functionality. Such manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2026-3588. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2025-70060 | YMFE yapi 1.12.0 cross site scripting
5 hours 47 minutes ago
A vulnerability marked as problematic has been reported in YMFE yapi 1.12.0. Affected is an unknown function. This manipulation causes cross site scripting.
This vulnerability appears as CVE-2025-70060. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2025-70040 | LupinLin1 jimeng-web-mcp 2.1.2 information disclosure
5 hours 47 minutes ago
A vulnerability labeled as problematic has been found in LupinLin1 jimeng-web-mcp 2.1.2. This impacts an unknown function. The manipulation results in information disclosure.
This vulnerability is reported as CVE-2025-70040. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2024-14027 | Linux Kernel xattr memory allocation
5 hours 48 minutes ago
A vulnerability identified as critical has been detected in Linux Kernel. This affects an unknown function of the component xattr. The manipulation leads to uncontrolled memory allocation.
This vulnerability is documented as CVE-2024-14027. The attack needs to be performed locally. There is not any exploit available.
It is suggested to install a patch to address this issue.
vuldb.com
CVE-2025-70042 | oslabs-beta ThermaKube server-side request forgery
5 hours 53 minutes ago
A vulnerability categorized as critical has been discovered in oslabs-beta ThermaKube. The impacted element is an unknown function. Executing a manipulation can lead to server-side request forgery.
This vulnerability is registered as CVE-2025-70042. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2025-70059 | YMFE yapi 1.12.0 resource consumption (EUVD-2025-208415)
6 hours ago
A vulnerability was found in YMFE yapi 1.12.0. It has been rated as problematic. The affected element is an unknown function. Performing a manipulation results in resource consumption.
This vulnerability is cataloged as CVE-2025-70059. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-70046 | Miazzy oa-front-service inclusion of functionality from untrusted control sphere
6 hours ago
A vulnerability was found in Miazzy oa-front-service. It has been declared as problematic. Impacted is an unknown function. Such manipulation leads to inclusion of functionality from untrusted control sphere.
This vulnerability is listed as CVE-2025-70046. The attack must be carried out from within the local network. There is no available exploit.
vuldb.com
CVE-2025-70238 | D-Link DIR-513 1.10 formSetWAN_Wizard52 curTime stack-based overflow (EUVD-2025-208418)
6 hours ago
A vulnerability was found in D-Link DIR-513 1.10. It has been classified as critical. This issue affects some unknown processing of the file /goform/formSetWAN_Wizard52. This manipulation of the argument curTime causes stack-based buffer overflow.
This vulnerability is tracked as CVE-2025-70238. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2025-70047 | Nexusoft NexusInterface 3.2.0-beta.2 resource consumption
6 hours ago
A vulnerability was found in Nexusoft NexusInterface 3.2.0-beta.2 and classified as problematic. This vulnerability affects unknown code. The manipulation results in resource consumption.
This vulnerability is identified as CVE-2025-70047. The attack can be executed remotely. There is not any exploit available.
vuldb.com