#cve-2025

[ follow ]
Information security
fromSecurityWeek
2 days ago

OpenSSL Vulnerabilities Allow Private Key Recovery, Code Execution, DoS Attacks

OpenSSL released multiple patched versions addressing three vulnerabilities, including a moderate-risk SM2 private-key recovery issue on 64-bit ARM and an out-of-bounds flaw.
Information security
fromThe Hacker News
1 month ago

Pre-Auth Exploit Chains Found in Commvault Could Enable Remote Code Execution Attacks

Four Commvault vulnerabilities (CVE-2025-57788/57789/57790/57791) enable unauthenticated or low-privilege remote code execution; fixes issued in 11.32.102 and 11.36.60.
[ Load more ]