CVE-2025-10201

creation_timestamp| type| source ---|---|--- 2025-09-10 21:14:50+00:00| seen|...Read More ...

Continue Reading
CVE-2025-43784

creation_timestamp| type| source ---|---|--- 2025-09-10 20:54:49+00:00| seen|...Read More ...

Continue Reading
CVE-2025-9714

creation_timestamp| type| source ---|---|--- 2025-09-10 20:49:49+00:00| seen|...Read More ...

Continue Reading
CVE-2020-36732

creation_timestamp| type| source ---|---|--- 2025-09-10 20:15:05+00:00| seen| https://bsky.app/profile/knaepp.bsky.social/post/3lyj2dsk7fz2s 2025-09-10 21:10:05+00:00| seen|...Read More ...

Continue Reading
EUVD-2025-27610

Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v2/ws/logs is not protected by the same authentication middleware that guards t ...

Continue Reading
Infrahub: Deleted and expired API tokens can still authenticate

Impact A bug in the authentication logic will cause API tokens that were deleted and/or expired to be considered valid. This means that any API token that is associated with an active user account can ...

Continue Reading
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when –auth is enabled

Summary Hoverfly’s admin WebSocket endpoint /api/v2/ws/logs is not protected by the same authentication middleware that guards the REST admin API. Consequently, an unauthenticated remote attacker ca ...

Continue Reading
Indico may disclose unauthorized user details access via legacy API

Impact A legacy API to retrieve user details could be misused to retrieve profile details of other users without having admin permissions due to a broken access check. Patches You should to update to ...

Continue Reading

Back to Main

Subscribe for the latest news: