Post

2025-11-08 Daily Vulns

NEW:

CVEvendor-productdescriptionmetricReferenceurltitleGithubURL 
CVE-2025-11212Google - ChromeInappropriate implementation in Media in Google Chrome on Windows prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)CNA n/a CVSS3.1: 6.3 - MEDIUM0 1Exploitation: noneAutomatable: noTechnical Impact: partialundefinedgithub
CVE-2025-10968GG Soft Software Services Inc. - PaperWorkImproper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’), CWE - 564 - SQL Injection: Hibernate vulnerability in GG Soft Software Services Inc. PaperWork allows Blind SQL Injection, SQL Injection.This issue affects PaperWork: from 6.1.0.9390 before 6.1.0.9398.CVSS3.1: 8.8 - HIGH0Exploitation: noneAutomatable: noTechnical Impact: totalSQLi in GG Soft’s PaperWorkgithub
CVE-2022-50590SuiteCRM - SuiteCRMSuiteCRM versions prior to 7.12.6 contain a type confusion vulnerability within the processing of the ‘module’ parameter within the ‘deleteAttachment’ functionality. Successful exploitation allows remote unauthenticated attackers to alter database objects including changing the email address of the administrator.CVSS4.0: 8.8 - HIGH0 1 2Exploitation: noneAutomatable: yesTechnical Impact: partialSuiteCRM < 7.12.6 Type Confusion via ‘deleteAttachment’ Functionalitygithub
This post is licensed under CC BY 4.0 by the author.