CVE-2025-8965

A vulnerability has been found in linlinjava litemall up to 1.8.0. This vulnerability affects the function create of the file litemall-admin-api/src/main/java/org/linlinjava/litemall/admin/web/AdminSt ...

Continue Reading
EUVD-2025-24814

A security issue in the runtime event system allows unauthenticated connections to receive a reusable API token. This token is broadcasted over a WebSocket and can be intercepted by any local client l ...

Continue Reading
CVE-2025-8965 linlinjava litemall Endpoint AdminStorageController.java create unrestricted upload

A vulnerability has been found in linlinjava litemall up to 1.8.0. This vulnerability affects the function create of the file litemall-admin-api/src/main/java/org/linlinjava/litemall/admin/web/AdminSt ...

Continue Reading
CVE-2025-8965 linlinjava litemall Endpoint AdminStorageController.java create unrestricted upload

A vulnerability has been found in linlinjava litemall up to 1.8.0. This vulnerability affects the function create of the file litemall-admin-api/src/main/java/org/linlinjava/litemall/admin/web/AdminSt ...

Continue Reading
A Comprehensive Analysis of HijackLoader and its Infection Chain

A Comprehensive Analysis of HijackLoader and Its Infection Chain By Ryan Weil · August 18, 2025 Initial contact Dodi Repacks is a website that distributes pirated games. The site is listed as safe/t ...

Continue Reading
CVE-2025-52785 WordPress SMM API Plugin <= 6.0.30 – Broken Access Control Vulnerability

Missing Authorization vulnerability in softnwords SMM API allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SMM API: from n/a through...Read More ...

Continue Reading
CVE-2025-5998 PPWP < 1.9.11 – Subscriber+ Access Bypass via REST API

The PPWP – Password Protect Pages WordPress plugin before version 1.9.11 allows to put the site content behind a password authorization, however users with subscriber or greater roles can view conte ...

Continue Reading
CVE-2025-27845

In ESPEC North America Web Controller 3 before 3.3.4, /api/v4/auth/ with any invalid authentication request results in exposing a JWT secret. This allows for elevated permissions to the...Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: