CVE-2025-29627

creation_timestamp| type| source ---|---|--- 2025-06-09 19:37:17+00:00| seen|...Read More ...

Continue Reading
CVE-2024-46452

creation_timestamp| type| source ---|---|--- 2025-06-09 19:31:32+00:00| seen|...Read More ...

Continue Reading
HaxCMS-PHP Command Injection Vulnerability

Summary The 'gitImportSite' functionality obtains a URL string from a POST request and insufficiently validates user input. The ’set_remote’ function later passes this input into ’proc ...

Continue Reading
@haxtheweb/haxcms-nodejs Iframe Phishing vulnerability

Summary In the HAX site editor, users can create a website block to load another site in an iframe. The application allows users to supply a target URL in the website block. When the HAX site is visit ...

Continue Reading
Requests vulnerable to .netrc credentials leak via malicious URLs

Impact Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Workarounds For older versions of Requests, use ...

Continue Reading
CVE-2025-49138 HAX CMS vulnerable to Local File Inclusion via saveOutline API Location Parameter

HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, an authenticated Local File Inclusion (LFI) vulnerability in the HAXCMS saveOutline endpoint al ...

Continue Reading
CVE-2025-49138

HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, an authenticated Local File Inclusion (LFI) vulnerability in the HAXCMS saveOutline endpoint al ...

Continue Reading
CVE-2025-49138

HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, an authenticated Local File Inclusion (LFI) vulnerability in the HAXCMS saveOutline endpoint al ...

Continue Reading

Back to Main

Subscribe for the latest news: