CVE-2025-9273 CData API Server MySQL Misconfiguration Information Disclosure Vulnerability

CData API Server MySQL Misconfiguration Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of CData API Server ...

Continue Reading
GHSA-9GH8-9R95-3FC3 MobSF Vulnerable to Arbitrary File Write (AR-Slip) via Absolute Path in .a Extraction

Summary The vulnerability allows any user to overwrite any files available under the account privileges of the running process. Details As part of static analysis, iOS MobSF supports loading and parsi ...

Continue Reading
Security Bulletin: DataStage on Cloud Pak for Data has several vulnerabilities due to the libxml2 package (CVE-2025-27113, CVE-2025-32414, CVE-2025-32415)

Summary libxml2 is used by DataStage on Cloud Pak for Data as part of XML processing. Vulnerability Details CVEID:CVE-2025-27113 DESCRIPTION: libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL ...

Continue Reading
Security Bulletin: DataStage on Cloud Pak for Data is vulnerable to stack overwrite due to the libcurl package (CVE-2024-6197)

Summary libcurl is used by DataStage on Cloud Pak for Data as part of API communication. Vulnerability Details CVEID:CVE-2024-6197 DESCRIPTION: libcurl's ASN1 parser has this utf8asn1str() functi ...

Continue Reading
ArrayQueue’s push_front is not panic-safe

The safe API array_queue::ArrayQueue::push_front can lead to deallocating uninitialized memory if a panic occurs while invoking the clone method on the passed argument. Specifically, push_front receiv ...

Continue Reading
MobSF Vulnerable to Arbitrary File Write (AR-Slip) via Absolute Path in .a Extraction

Summary The vulnerability allows any user to overwrite any files available under the account privileges of the running process. Details As part of static analysis, iOS MobSF supports loading and parsi ...

Continue Reading
Local Deep Research’s API keys are stored in plain text

Affected Versions: > 0.2.0 and < 1.0.0 Patched Versions: >= 1.0.0 Description: The library stored confidential information, including API keys, in a local SQLite database without ...

Continue Reading
mcp-markdownify-server vulnerable to command injection in pptx-to-markdown tool

Summary A command injection vulnerability exists in the mcp-markdownify-server MCP Server. The vulnerability is caused by the unsanitized use of input parameters within a call to child_process.exec, e ...

Continue Reading

Back to Main

Subscribe for the latest news: