Post

2025-08-20 Daily Vulns

NEW:

CVEvendor-productdescriptionmetricReferenceurltitleGithubURL 
CVE-2024-44373n/a - n/aA Path Traversal vulnerability in AllSky v2023.05.01_04 allows an unauthenticated attacker to create a webshell and remote code execution via the path, content parameter to /includes/save_file.php.CNA n/a CVSS3.1: 9.8 - CRITICAL0 1 2Exploitation: pocAutomatable: yesTechnical Impact: totalundefinedgithub
CVE-2025-31988HCL Software - Digital ExperienceHCL Digital Experience is susceptible to cross site scripting (XSS) in an administrative UI with restricted access.CVSS3.1: 4.9 - MEDIUM0Exploitation: noneAutomatable: noTechnical Impact: partialHCL Digital Experience is susceptible to cross site scripting (XSS)github
CVE-2025-51489n/a - n/aAn arbitrary file upload vulnerability in MoonShine v3.12.4 allows attackers to execute arbitrary code via uploading a crafted SVG file.CNA n/a CVSS3.1: 4.5 - MEDIUM0 1Exploitation: pocAutomatable: noTechnical Impact: partialundefinedgithub
CVE-2025-54880mermaid-js - mermaidMermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. In the default configuration of mermaid 11.9.0 and earlier, user supplied input for architecture diagram icons is passed to the d3 html() method, creating a sink for cross site scripting. This vulnerability is fixed in 11.10.0.CVSS4.0: 5.1 - MEDIUM0 1 2Exploitation: pocAutomatable: noTechnical Impact: partialMermaid does not properly sanitize architecture diagram iconText leading to XSSgithub
This post is licensed under CC BY 4.0 by the author.