Medium - CVE-2025-53771 - Improper limitation of a pathname to a...
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
High - CVE-2025-7911 - A vulnerability classified as critical was...
A vulnerability classified as critical was found in D-Link DI-8100 1.0. This vulnerability affects the function sprintf of the file /upnp_ctrl.asp of the component jhttpd. The manipulation of the...
High - CVE-2025-7912 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, has been found in TOTOLINK T6 4.1.5cu.748_B20211015. This issue affects the function recvSlaveUpgstatus of the component MQTT Service. The...
(Nem hivatalos csomag) Firefox / Librewolf supply chain attack
Linux-security Engem nem érint, de hátha valamelyik HUP-os fórumtársat igen: https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.o… A következő AUR csomagokba kártékony kód került. Ha valaki frissítette ezeket júl 16. és júl 18...
NA - CVE-2025-52924 - In One Identity OneLogin before 2025.2.0, the...
In One Identity OneLogin before 2025.2.0, the SQL connection "application name" is set based on the value of an untrusted X-RequestId HTTP request header.
Medium - CVE-2025-7653 - The EPay.bg Payments plugin for WordPress is...
The EPay.bg Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'epay' shortcode in all versions up to, and including, 0.1 due to insufficient...
Medium - CVE-2025-7655 - The Live Stream Badger plugin for WordPress is...
The Live Stream Badger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'livestream' shortcode in all versions up to, and including, 1.4.3 due to...
Medium - CVE-2025-7658 - The Temporarily Hidden Content plugin for...
The Temporarily Hidden Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'temphc-start' shortcode in all versions up to, and including, 1.0.6...
Medium - CVE-2025-7661 - The Partnerský systém Martinus plugin for...
The Partnerský systém Martinus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'martinus' shortcode in all versions up to, and including, 1.7.1 due...
Medium - CVE-2025-7669 - The Avishi WP PayPal Payment Button plugin for...
The Avishi WP PayPal Payment Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0. This is due to missing or incorrect nonce validation...