March 2025

CVE-2025-27590 – Oxidized Web Unauthenticated Remote Command Execution

CVE ID : CVE-2025-27590 Published : March 3, 2025, 4:15 a.m. | 30 minutes ago Description : In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user account that is running oxidized-web. Severity: 9.0 | CRITICAL Visit the link for more details, such as […]

CVE-2025-27590 – Oxidized Web Unauthenticated Remote Command Execution Read More »

Amnesty: Cellebrite gebruikte Android usb-lek voor ontgrendelen telefoons

Amnesty: Cellebrite gebruikte Android usb-lek voor ontgrendelen telefoons Ontwikkelaar van forensische software Cellebrite heeft drie kwetsbaarheden in de usb-kerneldrivers van Android gebruikt voor het ontgrendelen van vergrendelde telefoons, zo meldt mensenrechtenorganisa … Read more Published Date: Mar 01, 2025 (3 hours, 32 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2024-53197 CVE-2024-53104 CVE-2024-50302

Amnesty: Cellebrite gebruikte Android usb-lek voor ontgrendelen telefoons Read More »

CVE-2024-41778 – IBM Controller Weak Password Policy Vulnerability

CVE ID : CVE-2024-41778 Published : March 1, 2025, 3:15 p.m. | 3 hours, 30 minutes ago Description : IBM Controller 11.0.0 through 11.0.1 and 11.1.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. Severity: 5.3 | MEDIUM Visit the link for more details,

CVE-2024-41778 – IBM Controller Weak Password Policy Vulnerability Read More »

CVE-2025-1797 – Baiyiyun Asset Management and Operations System SQL Injection Vulnerability

CVE ID : CVE-2025-1797 Published : March 1, 2025, 3:15 p.m. | 3 hours, 30 minutes ago Description : A vulnerability, which was classified as critical, has been found in Hunan Zhonghe Baiyi Information Technology Baiyiyun Asset Management and Operations System up to 20250217. Affected by this issue is some unknown functionality of the file /wuser/anyUserBoundHouse.php. The

CVE-2025-1797 – Baiyiyun Asset Management and Operations System SQL Injection Vulnerability Read More »

CVE-2025-1800 – D-Link DAR-7000 HTTP POST Request Handler Command Injection Vulnerability

CVE ID : CVE-2025-1800 Published : March 1, 2025, 6:15 p.m. | 29 minutes ago Description : A vulnerability has been found in D-Link DAR-7000 3.2 and classified as critical. This vulnerability affects the function get_ip_addr_details of the file /view/vpn/sxh_vpn/sxh_vpnlic.php of the component HTTP POST Request Handler. The manipulation of the argument ethname leads to command

CVE-2025-1800 – D-Link DAR-7000 HTTP POST Request Handler Command Injection Vulnerability Read More »

CVE-2025-1799 – Zorlan SkyCaiji SSRF Vulnerability

CVE ID : CVE-2025-1799 Published : March 1, 2025, 6:15 p.m. | 29 minutes ago Description : A vulnerability, which was classified as critical, was found in Zorlan SkyCaiji 2.9. This affects the function previewAction of the file vendor/skycaiji/app/admin/controller/Tool.php. The manipulation of the argument data leads to server-side request forgery. It is possible to initiate the

CVE-2025-1799 – Zorlan SkyCaiji SSRF Vulnerability Read More »