CVE-2025-68613: Critical n8n Expression Injection Vulnerability
CVE-2025-68613 is an expression injection vulnerability in n8n with a CVSS score of 9.9. It was added to CISA's Known Exploited Vulnerabilities…
CVE-2025-68613 is an expression injection vulnerability in n8n with a CVSS score of 9.9. It was added to CISA's Known Exploited Vulnerabilities…
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated…
A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` layer. Specifically,…
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application…
A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in…
A critical flaw (CVSS 9.1) in Gladinet Triofox exploited by Storm-2603 for initial access in ransomware attacks. Used to probe for local…
JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that allows network-adjacent attackers to gain unauthorized access by…
Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) without sanitization: exec("php jobs/subtitle_rendering.php ".$login_session."…
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELECT id, filename, extension, type,…