Post

2025-07-26 Daily Vulns

NEW:

CVEvendor-productdescriptionmetricReferenceurltitleGithubURL 
CVE-2024-48729n/a - n/aAn issue in ETSI Open-Source MANO (OSM) v.14.x, v.15.x allows a remote attacker to escalate privileges via the /osm/admin/v1/users componentCNA n/a CVSS3.1: 7.1 - HIGH0 1 2Exploitation: pocAutomatable: noTechnical Impact: totalundefinedgithub
CVE-2020-36850Sitecore - JSS React Sample ApplicationAn information disclosure vulnerability exits in Sitecore JSS React Sample Application 11.0.0 - 14.0.1 that may cause page content intended for one user to be shown to another user.CVSS4.0: 8.7 - HIGH0 1 2Exploitation: noneAutomatable: yesTechnical Impact: partialSitecore JSS React Sample Application 11.0.0 - 14.0.1 Information Disclosuregithub
CVE-2013-10032GetSimple CMS Project - GetSimple CMSAn authenticated remote code execution vulnerability exists in GetSimpleCMS version 3.2.1. The application’s upload.php endpoint allows authenticated users to upload arbitrary files without proper validation of MIME types or extensions. By uploading a .pht file containing PHP code, an attacker can bypass blacklist-based restrictions and place executable code within the web root. A crafted request using a polyglot or disguised extension allows the attacker to execute the payload by accessing the file directly via the web server. This vulnerability exists due to the use of a blacklist for filtering file types instead of a whitelist.CVSS4.0: 8.7 - HIGH0 1 2 3 4 5Exploitation: pocAutomatable: noTechnical Impact: totalGetSimple CMS 3.2.1 Authenticated RCE via Arbitrary PHP File Uploadgithub
CVE-2019-25224databasebackup - WP Database Backup – Unlimited Database & Files Backup by Backup for WPThe WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system.CVSS3.1: 9.8 - CRITICAL0 1 2 3 4 5Exploitation: noneAutomatable: yesTechnical Impact: totalWP Database Backup < 5.2 - Unauthenticated OS Command Injectiongithub
CVE-2025-0249HCL Software - IEMHCL IEM is affected by an improper invalidation of access or JWT token vulnerability. A token was not invalidated which may allow attackers to access sensitive data without authorization.CVSS3.1: 3.3 - LOW0Exploitation: noneAutomatable: noTechnical Impact: partialHCL IEM is affected by an improper invalidation of access or JWT token vulnerabilitygithub
CVE-2023-7306nmedia - Frontend File Manager PluginThe Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpfm_delete_multiple_files() function in all versions up to, and including, 21.5. This makes it possible for unauthenticated attackers to delete arbitrary posts.CVSS3.1: 7.5 - HIGH0 1Exploitation: noneAutomatable: yesTechnical Impact: partialFrontend File Manager <= 21.5 - Missing Authorization to Unauthenticated Arbitrary Post Deletiongithub
CVE-2025-5253Kron Technologies - Kron PAMAllocation of Resources Without Limits or Throttling vulnerability in Kron Technologies Kron PAM allows HTTP DoS.This issue affects Kron PAM: before 3.7.CVSS3.1: 6.5 - MEDIUM0Exploitation: noneAutomatable: noTechnical Impact: partialDoS in Kron Technologies’ Kron PAMgithub
This post is licensed under CC BY 4.0 by the author.