Post

2026-04-25 Daily Vulns

NEW:

CVEvendor-productdescriptionmetricReferenceurltitleGithubURL 
CVE-2025-59308n/a - n/aIn Mahara before 24.04.10 and 25 before 25.04.1, an institution administrator or institution support administrator on a multi-tenanted site can masquerade as an institution member in an institution for which they are not an administrator, if they also have the ‘Site staff’ role.CNA n/a CVSS3.1: 4.7 - MEDIUM0 1Exploitation: noneAutomatable: noTechnical Impact: partialundefinedgithub
CVE-2026-25775SenseLive - X3050A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and update operations to be performed without authentication or authorization. The service accepts firmware-related requests from any reachable host and does not verify user privileges, integrity of uploaded images, or the authenticity of provided firmware.CVSS4.0: 9.3 - CRITICAL CVSS3.1: 9.8 - CRITICAL0 1 2Exploitation: noneAutomatable: yesTechnical Impact: totalSenseLive X3050 Missing authentication for critical functiongithub
This post is licensed under CC BY 4.0 by the author.