Post

2025-07-04 Daily Vulns

NEW:

CVEvendor-productdescriptionmetricReferenceurltitleGithubURL 
CVE-2025-52554n8n-io - n8nn8n is a workflow automation platform. Prior to version 1.99.1, an authorization vulnerability was discovered in the /rest/executions/:id/stop endpoint of n8n. An authenticated user can stop workflow executions that they do not own or that have not been shared with them, leading to potential business disruption. This issue has been patched in version 1.99.1. A workaround involves restricting access to the /rest/executions/:id/stop endpoint via reverse proxy or API gateway.CVSS4.0: 4.9 - MEDIUM0 1 2 3Exploitation: noneAutomatable: noTechnical Impact: partialn8n Improper Authorization in Workflow Execution Stop Endpoint Allows Terminating Other Users’ Workflowsgithub
CVE-2025-23968WPCenter - AiBud WPUnrestricted Upload of File with Dangerous Type vulnerability in WPCenter AiBud WP allows Upload a Web Shell to a Web Server.This issue affects AiBud WP: from n/a through 1.8.5.CVSS3.1: 9.1 - CRITICAL0Exploitation: noneAutomatable: noTechnical Impact: totalWordPress AiBud WP plugin <= 1.8.5 - Arbitrary File Upload vulnerabilitygithub
CVE-2025-53489Wikimedia Foundation - Mediawiki - GoogleDocs4MW ExtensionImproper Neutralization of Input During Web Page Generation (XSS or ‘Cross-site Scripting’) vulnerability in Wikimedia Foundation Mediawiki - GoogleDocs4MW Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - GoogleDocs4MW Extension: from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.CNA n/a CVSS3.1: 5.6 - MEDIUM0 1Exploitation: noneAutomatable: noTechnical Impact: partialXSS in GoogleDocs4MWgithub
CVE-2023-30754AdFoxly - AdFoxly – Ad Manager, AdSense Ads & Ads.txtUnauth. Reflected Cross-Site Scripting (XSS) vulnerability in AdFoxly AdFoxly – Ad Manager, AdSense Ads & Ads.Txt plugin <= 1.8.5 versions.CVSS3.1: 7.1 - HIGH0Exploitation: noneAutomatable: noTechnical Impact: partialWordPress AdFoxly – Ad Manager, AdSense Ads & Ads.txt Plugin <= 1.8.5 is vulnerable to Cross Site Scripting (XSS)github
CVE-2023-20217Cisco - Cisco ThousandEyes Recorder ApplicationA vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing certain commands using sudo. A successful exploit could allow the attacker to view arbitrary files as root on the underlying operating system. The attacker must have valid credentials on the affected device.CVSS3.1: 5.5 - MEDIUM0Exploitation: noneAutomatable: noTechnical Impact: partialundefinedgithub
CVE-2025-20307Cisco - Cisco BroadWorksA vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform could allow an authenticated, remote attacker to to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid administrative credentials.CVSS3.1: 4.8 - MEDIUM0Exploitation: noneAutomatable: noTechnical Impact: totalCisco BroadWorks Application Delivery Platform Cross-Site Scripting Vulnerabilitygithub
This post is licensed under CC BY 4.0 by the author.