Post

2025-07-31 Daily Vulns

NEW:

CVEvendor-productdescriptionmetricReferenceurltitleGithubURL 
CVE-2024-45515n/a - n/aAn issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability exists in Zimbra webmail due to insufficient validation of the content type metadata when importing files into the briefcase. Attackers can exploit this issue by crafting a file with manipulated metadata, allowing them to bypass content type checks and execute arbitrary JavaScript within the victim’s session.CNA n/a CVSS3.1: 6.1 - MEDIUM0 1 2 3Exploitation: noneAutomatable: noTechnical Impact: partialundefinedgithub
CVE-2025-24119Apple - macOSApple - macOSApple - macOSThis issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3, macOS Ventura 13.7.7, macOS Sonoma 14.7.7. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.CNA n/a CVSS3.1: 9.8 - CRITICAL0 1 2Exploitation: noneAutomatable: yesTechnical Impact: totalundefinedgithub
CVE-2025-32510Ovatheme - Ovatheme Events ManagerUnrestricted Upload of File with Dangerous Type vulnerability in Ovatheme Ovatheme Events Manager allows Using Malicious Files.This issue affects Ovatheme Events Manager: from n/a through 1.8.4.CVSS3.1: 10 - CRITICAL0Exploitation: noneAutomatable: yesTechnical Impact: totalWordPress Ovatheme Events Manager plugin <= 1.8.4 - Arbitrary File Upload vulnerabilitygithub
This post is licensed under CC BY 4.0 by the author.