CVE-2025-24895 - Critical SAML Signature Validation Bypass in CIE.AspNetCore.Authentication
Published: June 2024
Affected package: cie-aspnetcore (CIE.AspNetCore.Authentication)
Fixed in: v2.1.
Impact: Remote user impersonation (Critical)
CVSS Score: 9.8 (Critical)
Introduction
CVE-2025-26620 - Race Condition Vulnerability in Duende.AccessTokenManagement for .NET
CVE-2025-26620 is a newly disclosed vulnerability affecting the Duende.AccessTokenManagement library for .NET, which is widely used for managing OAuth and OpenID Connect
CVE-2025-21703 - Linux Kernel netem Use-After-Free Exploit Explained
The Linux kernel is the backbone of almost every server and many desktops out there. When something’s wrong in the kernel, it can impact
CVE-2025-1414 - Memory Safety Bugs in Firefox 135 — How Attackers Could Execute Arbitrary Code
Mozilla Firefox is one of the world’s most trusted web browsers, but even the best software sometimes contains serious flaws. One such issue is
CVE-2025-1035 - How Path Traversal in Komtera KLog Server Lets Attackers Access and Modify Files (with PoC and Fixes)
*Published: 2024-06-18*
Komtera Technologies' KLog Server is a widely used log management solution. In early 2025, CVE-2025-1035 was assigned to
Episode
00:00:00
00:00:00