CVE-2025-53640 Indico vulnerable to user enumeration via API endpoint

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Starting in version 2.2 and prior to version 3.3.7, an endpoint used to display details ...

Continue Reading
CVE-2025-53639

MeterSphere is an open source continuous testing platform. Prior to version 3.6.5-lts, the sortField parameter in certain API endpoints is not properly validated or sanitized. An attacker can supply c ...

Continue Reading
CVE-2025-53623

The Job Iteration API is an an extension for ActiveJob that make jobs interruptible and resumable Versions prior to 1.11.0 have an arbitrary code execution vulnerability in the CsvEnumerator class. Th ...

Continue Reading
CVE-2025-53639

MeterSphere is an open source continuous testing platform. Prior to version 3.6.5-lts, the sortField parameter in certain API endpoints is not properly validated or sanitized. An attacker can supply c ...

Continue Reading
CVE-2025-53640 Indico vulnerable to user enumeration via API endpoint

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Starting in version 2.2 and prior to version 3.3.7, an endpoint used to display details ...

Continue Reading
CVE-2025-53639 Metersphere has SQL Injection Vulnerability in Sorting Field

MeterSphere is an open source continuous testing platform. Prior to version 3.6.5-lts, the sortField parameter in certain API endpoints is not properly validated or sanitized. An attacker can supply c ...

Continue Reading
GHSA-VMHH-8RXQ-FP9G

creation_timestamp| type| source ---|---|--- 2025-07-14 19:49:41+00:00| seen|...Read More ...

Continue Reading
GHSA-HM4X-R5HC-794F

creation_timestamp| type| source ---|---|--- 2025-07-14 19:49:41+00:00| seen|...Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: