CVE Monitor
CVE-2025-50059
N/A
15 Jul 2025
CVE-2025-30762
N/A
15 Jul 2025
CVE-2025-30760
N/A
15 Jul 2025
CVE-2025-30759
N/A
15 Jul 2025
CVE-2025-30758
N/A
15 Jul 2025
CVE-2025-30756
N/A
15 Jul 2025
CVE-2025-30754
N/A
15 Jul 2025
CVE-2025-30753
N/A
15 Jul 2025
CVE-2025-30752
N/A
15 Jul 2025
CVE-2025-30751
N/A
15 Jul 2025
CVE-2025-30750
N/A
15 Jul 2025
CVE-2025-30748
N/A
15 Jul 2025
CVE-2025-30747
N/A
15 Jul 2025
CVE-2025-30746
N/A
15 Jul 2025
CVE-2025-30743
N/A
15 Jul 2025
CVE-2025-30739
N/A
15 Jul 2025
CVE-2025-6558
N/A
15 Jul 2025
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2025-34068
CRITICAL
15 Jul 2025
An unauthenticated remote command execution vulnerability exists in Samsung WLAN AP WEA453e firmware prior to version 5.2.4.T1 via improper input validation in the “Tech Support” diagnostic functionality. The command1 and command2 POST or GET parameters accept arbitrary shell commands that are executed with root privileges on the underlying operating system. An attacker can exploit this by crafting a request that injects shell commands to create output files in writable directories and then access their contents via the download endpoint. This flaw allows complete compromise of the device without authentication.
CVE-2025-34109
HIGH
15 Jul 2025
PSEvents.exe in multiple Panda Security products runs hourly with SYSTEM privileges and loads DLL files from a user-writable directory without proper validation. An attacker with low-privileged access who can write DLL files to the monitored directory can achieve arbitrary code execution with SYSTEM privileges. Affected products include Panda Global Protection 2016, Panda Antivirus Pro 2016, Panda Small Business Protection, and Panda Internet Security 2016 (all versions up to 16.1.2).
CVE-2025-24477
MEDIUM
15 Jul 2025
A heap-based buffer overflow in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.4 through 7.2.12 allows an attacker to escalate its privileges via a specially crafted CLI command
CVE-2025-6265
N/A
15 Jul 2025
A path traversal vulnerability in the file_upload-cgi CGI program of Zyxel NWA50AX PRO firmware version 7.10(ACGE.2) and earlier could allow an authenticated attacker with administrator privileges to access specific directories and delete files, such as the configuration file, on the affected device.
CVE-2025-53640
MEDIUM
14 Jul 2025
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Starting in version 2.2 and prior to version 3.3.7, an endpoint used to display details of users listed in certain fields (such as ACLs) could be misused to dump basic user details (such as name, affiliation and email) in bulk. Version 3.3.7 fixes the issue. Owners of instances that allow everyone to create a user account, who wish to truly restrict access to these user details, should consider restricting user search to managers. As a workaround, it is possible to restrict access to the affected endpoints (e.g. in the webserver config), but doing so would break certain form fields which could no longer show the details of the users listed in those fields, so upgrading instead is highly recommended.
CVE-2024-51768
N/A
14 Jul 2025
An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
CVE-2025-50756
N/A
14 Jul 2025
Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the newpass parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2024-42648
N/A
14 Jul 2025
NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via a crafted CONNECT message.