CVE-2025-10318 JeecgBoot WebSocket Message sendWebSocketMsg improper authorization

A vulnerability was identified in JeecgBoot up to 3.8.2. Affected by this vulnerability is an unknown functionality of the file /api/system/sendWebSocketMsg of the component WebSocket Message Handler. ...

Continue Reading
CVE-2025-27238 API hostprototype.get lists data to users with insufficient authorization.

Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to...Read More ...

Continue Reading
CVE-2025-7448

creation_timestamp| type| source ---|---|--- 2025-09-12 11:16:39+00:00| seen|...Read More ...

Continue Reading
CVE-2025-10266

creation_timestamp| type| source ---|---|--- 2025-09-12 10:32:01+00:00| seen| https://bsky.app/profile/offseq.bsky.social/post/3lyn2oyyr3k2t 2025-09-12 11:11:39+00:00| seen|...Read More ...

Continue Reading
CVE-2025-10265

creation_timestamp| type| source ---|---|--- 2025-09-12 11:26:40+00:00| seen|...Read More ...

Continue Reading
CVE-2025-10264

creation_timestamp| type| source ---|---|--- 2025-09-12 11:21:40+00:00| seen|...Read More ...

Continue Reading
PT-2025-37305

Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to...Read More ...

Continue Reading
CVE-2025-27238

Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to...Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: