CVE-2025-54379 eKuiper API endpoints handling SQL queries with user-controlled table names.

LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability ...

Continue Reading
CVE-2025-53940 Quiet uses insecure, inconsistent verification on local backend token

Quiet is an alternative to team chat apps like Slack, Discord, and Element that does not require trusting a central server or running one's own. In versions 6.1.0-alpha.4 and below, Quiet's ...

Continue Reading
CVE-2025-8155

creation_timestamp| type| source ---|---|--- 2025-07-25 13:30:13+00:00| seen|...Read More ...

Continue Reading
CVE-2025-02515

creation_timestamp| type| source ---|---|--- 2025-07-25 12:04:12+00:00| seen|...Read More ...

Continue Reading
CVE-2025-38407

creation_timestamp| type| source ---|---|--- 2025-07-25 13:50:07+00:00| seen|...Read More ...

Continue Reading
CVE-2025-24000

creation_timestamp| type| source ---|---|--- 2025-07-25 13:42:58+00:00| seen|...Read More ...

Continue Reading
CVE-2025-51396

creation_timestamp| type| source ---|---|--- 2025-07-25 12:18:43+00:00| seen|...Read More ...

Continue Reading
CVE-2025-43712

JHipster before v.8.9.0 allows privilege escalation via a modified authorities parameter. Upon registering in the JHipster portal and logging in as a standard user, the authorities parameter in the re ...

Continue Reading

Back to Main

Subscribe for the latest news: