CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-22143

Description: WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the listar_permissoes.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the msg_e parameter. This vulnerability is fixed in 3.2.8.

CVSS: MEDIUM (6.4)

EPSS Score: 0.04%

Source: CVE
January 9th, 2025 (6 months ago)

CVE-2025-22141

Description: WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /dao/verificar_recursos_cargo.php endpoint, specifically in the cargo parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This vulnerability is fixed in 3.2.8.

CVSS: CRITICAL (9.4)

EPSS Score: 0.04%

Source: CVE
January 9th, 2025 (6 months ago)

CVE-2025-22140

Description: WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /html/funcionario/dependente_listar_um.php endpoint, specifically in the id_dependente parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This vulnerability is fixed in 3.2.8.

CVSS: CRITICAL (9.4)

EPSS Score: 0.04%

Source: CVE
January 9th, 2025 (6 months ago)

CVE-2025-22139

Description: WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the configuracao_geral.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the msg_c parameter. This vulnerability is fixed in 3.2.8.

CVSS: MEDIUM (6.4)

EPSS Score: 0.04%

Source: CVE
January 9th, 2025 (6 months ago)

CVE-2025-22137

Description: Pingvin Share is a self-hosted file sharing platform and an alternative for WeTransfer. This vulnerability allows an authenticated or unauthenticated (if anonymous shares are allowed) user to overwrite arbitrary files on the server, including sensitive system files, via HTTP POST requests. The issue has been patched in version 1.4.0.

CVSS: CRITICAL (9.8)

EPSS Score: 0.05%

Source: CVE
January 9th, 2025 (6 months ago)

CVE-2025-22136

Description: Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.217 , Tabby enables several high-risk Electron Fuses, including RunAsNode, EnableNodeCliInspectArguments, and EnableNodeOptionsEnvironmentVariable. These fuses create potential code injection vectors even though the application is signed with hardened runtime and lacks dangerous entitlements such as com.apple.security.cs.disable-library-validation and com.apple.security.cs.allow-dyld-environment-variables. This vulnerability is fixed in 1.0.217.

CVSS: HIGH (8.6)

EPSS Score: 0.04%

Source: CVE
January 9th, 2025 (6 months ago)

CVE-2025-22130

Description: Soft Serve is a self-hostable Git server for the command line. Prior to 0.8.2 , a path traversal attack allows existing non-admin users to access and take over other user's repositories. A malicious user then can modify, delete, and arbitrarily repositories as if they were an admin user without explicitly giving them permissions. This is patched in v0.8.2.

CVSS: MEDIUM (5.3)

EPSS Score: 0.05%

Source: CVE
January 9th, 2025 (6 months ago)

CVE-2025-21603

Description: Cross-site scripting vulnerability exists in MZK-DP300N firmware versions 1.05 and earlier. If an attacker logs in to the affected product and manipulates the device settings, an arbitrary script may be executed on the logged-in user's web browser when accessing a crafted URL.

CVSS: MEDIUM (4.8)

EPSS Score: 0.04%

Source: CVE
January 9th, 2025 (6 months ago)

CVE-2025-21111

Description: Dell VxRail, versions 8.0.000 through 8.0.311, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.

CVSS: HIGH (7.5)

EPSS Score: 0.04%

Source: CVE
January 9th, 2025 (6 months ago)

CVE-2025-21102

Description: Dell VxRail, versions 7.0.000 through 7.0.532, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.

CVSS: HIGH (7.5)

EPSS Score: 0.04%

Source: CVE
January 9th, 2025 (6 months ago)