Security

CVE-2024-6235: NetScaler Console Flaw Enables Admin Access, PoC Publishes

A critical vulnerability—CVE-2024-6235—in Citrix NetScaler Console has been dissected by security researcher chutton-r7, revealing a severe unauthenticated session hijack that enables attackers to cre …
Read more

Published Date:
Apr 24, 2025 (3 hours, 7 minutes ago)

Vulnerabilities has been mentioned in this article.

CVE-2024-12284

CVE-2024-6236

CVE-2024-6235

CVE-2025-34028: Critical RCE Flaw in Commvault Command Center Scores CVSS 10

Commvault has disclosed a critical vulnerability affecting its Command Center, identified as CVE-2025-34028, with the maximum CVSS score of 10.0. The flaw allows unauthenticated remote attackers to ex …
Read more

Published Date:
Apr 24, 2025 (2 hours, 57 minutes ago)

Vulnerabilities has been mentioned in this article.

CVE-2025-32965

CVE-2025-34028

CVE-2025-32965: Backdoor in xrpl.js SDK Puts Crypto Wallets at Risk

Aikido Intel has issued an urgent alert after detecting a backdoor in multiple versions of xrpl.js, the official SDK for the XRP Ledger, marking one of the most severe supply chain attacks to hit the …
Read more

Published Date:
Apr 24, 2025 (2 hours, 44 minutes ago)

Vulnerabilities has been mentioned in this article.

CVE-2025-32965

CVE-2025-34028

High-Severity SonicWall SSLVPN Vulnerability Allows Firewall Crashing

SonicWall has disclosed a vulnerability affecting its SonicOS SSLVPN Virtual Office interface, which, if exploited, could allow remote attackers to crash firewall appliances. Tracked as CVE-2025-32818 …
Read more

Published Date:
Apr 24, 2025 (2 hours, 3 minutes ago)

Vulnerabilities has been mentioned in this article.

CVE-2025-32818

CVE-2025-32965

CVE-2024-53704

CVE-2024-40766

CVE-2023-0656

GitLab Releases Security Update to Patch XSS and Account Takeover Flaws

GitLab has issued a security advisory urging users to upgrade their self-managed GitLab installations immediately. The advisory highlights the release of versions 17.11.1, 17.10.5, and 17.9.7 for both …
Read more

Published Date:
Apr 24, 2025 (1 hour, 52 minutes ago)

Vulnerabilities has been mentioned in this article.

Redis Vulnerability Exposes Servers to Denial-of-Service Attacks

A high-severity vulnerability has been discovered in Redis, the popular open-source in-memory data structure store, which could allow unauthenticated users to exhaust server memory and cause a Denial- …
Read more

Published Date:
Apr 24, 2025 (1 hour, 39 minutes ago)

Vulnerabilities has been mentioned in this article.

CVE-2025-21605

CVE-2024-31449

CVE-2023-41056

CVE-2022-35951

CVE ID : CVE-2024-22351

Published : April 23, 2025, 11:15 p.m. | 3 hours, 44 minutes ago

Description : IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

Severity: 6.3 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-25045

Published : April 23, 2025, 11:15 p.m. | 3 hours, 44 minutes ago

Description : IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical error message is returned in a request. This information could be used in further attacks against the system.

Severity: 4.3 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-25046

Published : April 23, 2025, 11:15 p.m. | 3 hours, 44 minutes ago

Description : IBM InfoSphere Information Server 11.7 DataStage Flow Designer 

transmits sensitive information via URL or query parameters that could be exposed to an unauthorized actor using man in the middle techniques.

Severity: 3.7 | LOW

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-27580

Published : April 24, 2025, 12:15 a.m. | 2 hours, 44 minutes ago

Description : NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 generates predictable tokens (that depend on username, time, and the fixed 7Dl9#dj- string) and thus allows unauthenticated users with a Common Access Card (CAC) to escalate privileges and compromise any account, including administrators.

Severity: 7.5 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-27581

Published : April 24, 2025, 12:15 a.m. | 2 hours, 44 minutes ago

Description : NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 allows users who lack the InET role to access the InET module via direct requests to known endpoints.

Severity: 4.3 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-46417

Published : April 24, 2025, 1:15 a.m. | 1 hour, 43 minutes ago

Description : The unsafe globals in Picklescan before 0.0.25 do not include ssl. Consequently, ssl.get_server_certificate can exfiltrate data via DNS after deserialization.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-46419

Published : April 24, 2025, 1:15 a.m. | 1 hour, 43 minutes ago

Description : Westermo WeOS 5 through 5.23.0 allows a reboot via a malformed ESP packet.

Severity: 5.9 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Ripple NPM supply chain attack hunts for private keys

Many versions of the Ripple ledger (XRPL) official NPM package are compromised with malware injected to steal cryptocurrency.
The NPM package, xrpl, is a JavaScript/TypeScript library that devs use to …
Read more

Published Date:
Apr 23, 2025 (5 hours, 4 minutes ago)

Vulnerabilities has been mentioned in this article.

CVE-2025-32965

CVE ID : CVE-2025-3673

Published : April 23, 2025, 7:16 p.m. | 3 hours, 42 minutes ago

Description : Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-3092.. Reason: This candidate is a reservation duplicate of CVE-2023-3092. Notes: All CVE users should reference CVE-2023-3092. instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-28169

Published : April 23, 2025, 8:15 p.m. | 2 hours, 43 minutes ago

Description : BYD QIN PLUS DM-i Dilink OS v3.0_13.1.7.2204050.1 to v3.0_13.1.7.2312290.1_0 was discovered to cend broadcasts to the manufacturer’s cloud server unencrypted, allowing attackers to execute a man-in-the-middle attack.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-32818

Published : April 23, 2025, 8:15 p.m. | 2 hours, 43 minutes ago

Description : A Null Pointer Dereference vulnerability in the SonicOS SSLVPN Virtual office interface allows a remote, unauthenticated attacker to crash the firewall, potentially leading to a Denial-of-Service (DoS) condition.

Severity: 7.5 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-46397

Published : April 23, 2025, 9:15 p.m. | 1 hour, 43 minutes ago

Description : Stack-overflow in fig2dev in version 3.2.9a allows an attacker possible code execution via local input manipulation via bezier_spline function.

Severity: 7.1 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…