Security

CVE ID : CVE-2025-29446

Published : April 21, 2025, 5:15 p.m. | 1 hour, 47 minutes ago

Description : open-webui v0.5.16 is vulnerable to SSRF in routers/ollama.py in function verify_connection.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-27086

Published : April 21, 2025, 6:15 p.m. | 47 minutes ago

Description : Vulnerability in Hewlett Packard Enterprise HPE Performance Cluster Manager (HPCM).This issue affects HPE Performance Cluster Manager (HPCM): through 1.12.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-28103

Published : April 21, 2025, 6:15 p.m. | 47 minutes ago

Description : Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-28104

Published : April 21, 2025, 6:15 p.m. | 47 minutes ago

Description : Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-39596

Published : April 17, 2025, 4:15 p.m. | 3 days, 20 hours ago

Description : Weak Authentication vulnerability in Quentn.com GmbH Quentn WP allows Privilege Escalation. This issue affects Quentn WP: from n/a through 1.2.8.

Severity: 9.8 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-43015

Published : April 17, 2025, 4:16 p.m. | 3 days, 20 hours ago

Description : In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces

Severity: 8.3 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-29662

Published : April 17, 2025, 5:15 p.m. | 3 days, 19 hours ago

Description : A RCE vulnerability in the core application in LandChat 3.25.12.18 allows an unauthenticated attacker to execute system code via remote network access.

Severity: 9.8 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2024-55211

Published : April 17, 2025, 6:15 p.m. | 3 days, 18 hours ago

Description : An issue in Think Router Tk-Rt-Wr135G V3.0.2-X000 allows attackers to bypass authentication via a crafted cookie.

Severity: 8.4 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-32408

Published : April 21, 2025, 1:15 p.m. | 45 minutes ago

Description : In Soffid Console 3.5.38 before 3.5.39, necessary checks were not applied to some Java objects. A malicious agent could possibly execute arbitrary code in the Sync Server and compromise security.

Severity: 8.5 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Broadcom Backtracks: Reinstates Lower VMware Core Licensing After Backlash

In March, Broadcom announced a significant change to the licensing and renewal policy for its VMware virtualization software suite. Effective April 10, 2025, all customers are now required to purchase …
Read more

Published Date:
Apr 21, 2025 (4 hours, 14 minutes ago)

Vulnerabilities has been mentioned in this article.

CVE-2025-22218

CVE-2025-22217

Microsoft Urges TPM 2.0 for Windows 11 Upgrade as Win 10 Support Nears End

Microsoft is eager for more users to migrate from Windows 10 to Windows 11—but only if their hardware meets the stringent system requirements, such as the presence of a TPM 2.0 chip (Trusted Platform …
Read more

Published Date:
Apr 21, 2025 (4 hours, 6 minutes ago)

Vulnerabilities has been mentioned in this article.

CVE-2023-1017

CVE-2023-1018

Kimusky Hackers Exploiting RDP & MS Office Vulnerabilities in Targeted Attacks

A sophisticated Advanced Persistent Threat (APT) operation named Larva-24005, linked to the notorious Kimsuky threat group, has been discovered actively exploiting critical vulnerabilities in Remote D …
Read more

Published Date:
Apr 21, 2025 (3 hours, 13 minutes ago)

Vulnerabilities has been mentioned in this article.

CVE-2019-0708

CVE-2017-11882

Critical ASUS Router Vulnerability Let Attackers Malicious Code Remotely

A critical security vulnerability has been discovered in ASUS routers featuring the AiCloud service, exposing millions of devices to the risk of remote code execution by unauthenticated attackers.
The …
Read more

Published Date:
Apr 21, 2025 (2 hours, 6 minutes ago)

Vulnerabilities has been mentioned in this article.

Critical PyTorch Vulnerability Let Attackers Execute Remote Code

A critical vulnerability in PyTorch that allows attackers to execute malicious code remotely, even when using safeguards previously thought to mitigate such risks.
The vulnerability, identified as CVE …
Read more

Published Date:
Apr 21, 2025 (1 hour, 56 minutes ago)

Vulnerabilities has been mentioned in this article.

Speed­i­fy VPN ma­cOS Vulnerability Let Attackers Escalate Privilege

A significant security vulnerability, tracked as CVE-2025-25364, was discovered in Speedify VPN’s macOS application, exposing users to local privilege escalation and full system compromise.
The flaw, …
Read more

Published Date:
Apr 21, 2025 (1 hour, 32 minutes ago)

Vulnerabilities has been mentioned in this article.

CVE ID : CVE-2025-25228

Published : April 21, 2025, 8:15 a.m. | 2 hours, 41 minutes ago

Description : A SQL injection in VirtueMart component 1.0.0 – 4.4.7 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the product management area in backend.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…