Tagged: Cybersecurity Alert

CVE-2025-62697

Improper Neutralization of Special Elements in Output Used by a Downstream Component (‘Injection’) vulnerability in The Wikimedia Foundation Mediawiki – LanguageSelector Extension allows Code Injection.This issue affects Mediawiki – LanguageSelector Extension: from master before...

CVE-2025-5517

Heap-based Buffer Overflow vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wallbox (MID/ CE) -Terra AC MID, ABB Terra AC wallbox (MID/ CE) -Terra AC Juno CE,...

CVE-2025-62509

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to version 1.4.0, a business logic flaw in FileRise’s file/folder handling allows low-privilege users to perform unauthorized operations (view/delete/modify)...

CVE-2025-62510

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In version 1.4.0, a regression allowed folder visibility/ownership to be inferred from folder names. Low-privilege users could see or interact...

CVE-2025-62693

Improper Neutralization of Input During Web Page Generation (XSS or ‘Cross-site Scripting’) vulnerability in The Wikimedia Foundation Mediawiki – LastModified Extension allows Stored XSS.This issue affects Mediawiki – LastModified Extension: from master before 1.39....

CVE-2025-62698

Improper Neutralization of Input During Web Page Generation (XSS or ‘Cross-site Scripting’) vulnerability in The Wikimedia Foundation Mediawiki – ExternalGuidance allows Stored XSS.This issue affects Mediawiki – ExternalGuidance: from master before 1.39. More information...

CVE-2025-62700

Improper Neutralization of Input During Web Page Generation (XSS or ‘Cross-site Scripting’) vulnerability in The Wikimedia Foundation Mediawiki – MultiBoilerplate Extensionmaste allows Stored XSS.This issue affects Mediawiki – MultiBoilerplate Extensionmaste: from master before 1.39....

CVE-2025-55086

In NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there was an unchecked index extracting the server DUID from the server reply. With a crafted packet,...

CVE-2025-11979

An authorized user may crash the MongoDB server by causing buffer over-read. This can be done by issuing a DDL operation while queries are being issued, under some conditions. This issue affects MongoDB Server...