Post

2025-07-25 Daily Vulns

NEW:

CVEvendor-productdescriptionmetricReferenceurltitleGithubURL 
CVE-2025-33109IBM - iIBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to a privilege escalation caused by an invalid database authority check. A bad actor could execute a database procedure or function without having all required permissions, in addition to causing denial of service for some database actions.CVSS3.1: 7.5 - HIGH0Exploitation: noneAutomatable: noTechnical Impact: partialIBM i privilege escalationgithub
CVE-2016-15044Kaltura - Video PlatformA remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user-controlled data within the keditorservices module. An unauthenticated remote attacker can exploit this issue by sending a specially crafted serialized PHP object in the kdata GET parameter to the redirectWidgetCmd endpoint. Successful exploitation leads to execution of arbitrary PHP code in the context of the web server process.CVSS4.0: 9.3 - CRITICAL0 1 2 3Exploitation: pocAutomatable: yesTechnical Impact: totalKaltura < 11.1.0-2 PHP Object Injection RCEgithub
CVE-2025-40680Capillary io - CapillaryScopeLack of sensitive data encryption in CapillaryScope v2.5.0 of Capillary io, which stores both the proxy credentials and the JWT session token in plain text within different registry keys on the Windows operating system. Any authenticated local user with read access to the registry can extract these sensitive values.CVSS4.0: 6.9 - MEDIUM0Exploitation: noneAutomatable: noTechnical Impact: partialEncryption of sensitive data in CapillaryScope missinggithub
This post is licensed under CC BY 4.0 by the author.