Post

2025-07-08 Daily Vulns

NEW:

CVEvendor-productdescriptionmetricReferenceurltitleGithubURL 
CVE-2016-10033n/a - n/aThe mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \” (backslash double quote) in a crafted Sender property.CNA n/a CVSS3.1: 9.8 - CRITICAL0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20Exploitation: activeAutomatable: yesTechnical Impact: totalundefinedgithub
CVE-2014-3931n/a - n/afastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corruption.CNA n/a CVSS3.1: 9.8 - CRITICAL0 1 2Exploitation: activeAutomatable: yesTechnical Impact: totalundefinedgithub
CVE-2025-39487ValvePress - RankieImproper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in ValvePress Rankie allows Reflected XSS. This issue affects Rankie: from n/a through 1.8.2.CVSS3.1: 7.1 - HIGH0Exploitation: noneAutomatable: noTechnical Impact: partialWordPress Rankie plugin <= 1.8.2 - Reflected Cross Site Scripting (XSS) vulnerabilitygithub
CVE-2024-58117Huawei - HarmonyOSStack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.CVSS3.1: 4 - MEDIUM0Exploitation: noneAutomatable: noTechnical Impact: partialundefinedgithub
CVE-2025-23970aonetheme - Service Finder BookingIncorrect Privilege Assignment vulnerability in aonetheme Service Finder Booking allows Privilege Escalation. This issue affects Service Finder Booking: from n/a through 6.0.CVSS3.1: 9.8 - CRITICAL0Exploitation: noneAutomatable: yesTechnical Impact: totalWordPress Service Finder Booking <= 6.0 - Privilege Escalation Vulnerabilitygithub
CVE-2025-3467langgenius - langgenius/difyAn XSS vulnerability exists in langgenius/dify versions prior to 1.1.3, specifically affecting Firefox browsers. This vulnerability allows an attacker to obtain the administrator’s token by sending a payload in the published chat. When the administrator views the conversation content through the monitoring/log function using Firefox, the XSS vulnerability is triggered, potentially exposing sensitive token information to the attacker.0 1Exploitation: pocAutomatable: noTechnical Impact: totalXSS Vulnerability in langgenius/difygithub 
This post is licensed under CC BY 4.0 by the author.