<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>CERT Polska</title><link>https://cert.pl/en/</link><description>CERT.PL</description><lastBuildDate>Thu, 09 Apr 2026 11:55:00 +0100</lastBuildDate><item><title>Vulnerabilities in Hydrosystem Control System software</title><link>https://cert.pl/en/posts/2026/04/CVE-2026-4901/</link><description>CERT Polska has received a report about 3 vulnerabilities (CVE-2026-4901, CVE-2026-34184, CVE-2026-34185) found in Hydrosystem Control System software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 09 Apr 2026 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-04-09:/en/posts/2026/04/CVE-2026-4901/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Annual report from the actions of CERT Polska 2025</title><link>https://cert.pl/en/posts/2026/04/annual-report-2025/</link><description>Another year of CERT Polska’s activities is behind us. It was a special one, as it marked the end of the third decade of our operations – we are celebrating our 30th anniversary! The year 2025 was a time full of challenges, growth, and a comprehensive approach to shaping cybersecurity – from proactive threat detection, through handling reports and responding to incidents, to sharing knowledge and building public awareness.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 08 Apr 2026 09:00:00 +0200</pubDate><guid isPermaLink="false">tag:cert.pl,2026-04-08:/en/posts/2026/04/annual-report-2025/</guid><category>News</category><category>annual report</category><category>report</category></item><item><title>Vulnerabilities in Mlflow software</title><link>https://cert.pl/en/posts/2026/04/CVE-2026-33865/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2026-33865, CVE-2026-33866) found in Mlflow software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 07 Apr 2026 13:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-04-07:/en/posts/2026/04/CVE-2026-33865/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Bludit software</title><link>https://cert.pl/en/posts/2026/04/CVE-2026-4420/</link><description>CERT Polska has received a report about a Stored Cross-site Scripting vulnerability found in Bludit software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 07 Apr 2026 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-04-07:/en/posts/2026/04/CVE-2026-4420/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Analysis of cifrat: could this be an evolution of a mobile RAT?</title><link>https://cert.pl/en/posts/2026/04/cifrat-analysis/</link><description>CERT Polska analyzed a Booking themed Android malware chain delivered through phishing and a fake update website. The sample is a multistage dropper that installs a hidden accessibility controlled RAT with WebSocket C2.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Kacper Ratajczak</dc:creator><pubDate>Fri, 03 Apr 2026 12:00:00 +0200</pubDate><guid isPermaLink="false">tag:cert.pl,2026-04-03:/en/posts/2026/04/cifrat-analysis/</guid><category>News</category><category>android</category><category>analysis</category><category>booking</category><category>banker</category><category>rat</category></item><item><title>Vulnerabilities in Szafir software</title><link>https://cert.pl/en/posts/2026/04/CVE-2026-26927/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2026-26927, CVE-2026-26928) found in Szafir software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 02 Apr 2026 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-04-02:/en/posts/2026/04/CVE-2026-26927/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Analysis of FvncBot campaign</title><link>https://cert.pl/en/posts/2026/03/fvncbot-analysis/</link><description>CERT Polska has analyzed an SGB-branded Android malware sample from the FvncBot campaign targeting Poland. The app installs a second-stage implant, coerces the victim into enabling accessibility, and registers the device to a backend that issues per-device credentials.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Kacper Ratajczak</dc:creator><pubDate>Mon, 30 Mar 2026 14:00:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-03-30:/en/posts/2026/03/fvncbot-analysis/</guid><category>News</category><category>android</category><category>analysis</category><category>fvncbot</category></item><item><title>Vulnerability in Robolinho Update Software</title><link>https://cert.pl/en/posts/2026/03/CVE-2026-1612/</link><description>Use of Hard-coded Credentials vulnerability (CVE-2026-1612) has been found in Robolinho Update Software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 30 Mar 2026 09:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-03-30:/en/posts/2026/03/CVE-2026-1612/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Bludit software</title><link>https://cert.pl/en/posts/2026/03/CVE-2026-25099/</link><description>CERT Polska has received a report about 3 vulnerabilities (from CVE-2026-25099 to CVE-2026-25101) found in Bludit software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 27 Mar 2026 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-03-27:/en/posts/2026/03/CVE-2026-25099/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in KlinikaXP and KlinikaXP Insertino software</title><link>https://cert.pl/en/posts/2026/03/CVE-2026-1958/</link><description>Use of Hard-coded Credentials vulnerability (CVE-2026-1958) has been found in KlinikaXP and KlinikaXP Insertino software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 23 Mar 2026 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-03-23:/en/posts/2026/03/CVE-2026-1958/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Befree SDK software</title><link>https://cert.pl/en/posts/2026/03/CVE-2025-12518/</link><description>Cross-site Scripting vulnerability (CVE-2025-12518) has been found in Befree SDK software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 18 Mar 2026 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-03-18:/en/posts/2026/03/CVE-2025-12518/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Raytha software</title><link>https://cert.pl/en/posts/2026/03/CVE-2025-69236/</link><description>CERT Polska has received a report about 11 vulnerabilities (CVE-2025-15540 and from CVE-2025-69236 to CVE-2025-69243 and from CVE-2025-69245 to CVE-2025-69246) found in Raytha software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 16 Mar 2026 13:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-03-16:/en/posts/2026/03/CVE-2025-69236/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in multiple tinycontrol devices</title><link>https://cert.pl/en/posts/2026/03/CVE-2025-11500/</link><description>CERT Polska has received reports about 2 vulnerabilities (CVE-2025-11500 and CVE-2025-15587) found in multiple tinycontrol devices (tcPDU and LAN Controllers: LK3.5, LK3.9 and LK4).</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 16 Mar 2026 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-03-16:/en/posts/2026/03/CVE-2025-11500/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Streamsoft Prestiż software</title><link>https://cert.pl/en/posts/2026/03/CVE-2026-0809/</link><description>Weak Token Encoding vulnerability (CVE-2026-0809) has been found in Streamsoft Prestiż software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 12 Mar 2026 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-03-12:/en/posts/2026/03/CVE-2026-0809/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Coppermine Photo Gallery software</title><link>https://cert.pl/en/posts/2026/03/CVE-2026-3013/</link><description>Path Traversal vulnerability (CVE-2026-3013) has been found in Coppermine Photo Gallery software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 11 Mar 2026 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-03-11:/en/posts/2026/03/CVE-2026-3013/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in QuickCMS software</title><link>https://cert.pl/en/posts/2026/03/CVE-2026-1468/</link><description>Cross-Site Request Forgery (CSRF) vulnerability (CVE-2026-1468) has been found in QuickCMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 06 Mar 2026 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-03-06:/en/posts/2026/03/CVE-2026-1468/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in DobryCMS software</title><link>https://cert.pl/en/posts/2026/03/CVE-2025-12462/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2025-12462 and CVE-2025-14532) found in DobryCMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 02 Mar 2026 13:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-03-02:/en/posts/2026/03/CVE-2025-12462/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in CGM CLININET and CGM NETRAAD software</title><link>https://cert.pl/en/posts/2026/03/CVE-2025-10350/</link><description>CERT Polska has received reports about 8 vulnerabilities found in CGM CLININET and CGM NETRAAD software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 02 Mar 2026 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-03-02:/en/posts/2026/03/CVE-2025-10350/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Pro3W CMS software</title><link>https://cert.pl/en/posts/2026/02/CVE-2025-15498/</link><description>SQL Injection vulnerability (CVE-2025-15498) has been found in Pro3W CMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 27 Feb 2026 13:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-02-27:/en/posts/2026/02/CVE-2025-15498/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in PluXml CMS software</title><link>https://cert.pl/en/posts/2026/02/CVE-2026-24350/</link><description>CERT Polska has received a report about 3 vulnerabilities (from CVE-2026-24350 to CVE-2026-24352) found in PluXml CMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 27 Feb 2026 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-02-27:/en/posts/2026/02/CVE-2026-24350/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Omega-PSIR software</title><link>https://cert.pl/en/posts/2026/02/CVE-2026-1434/</link><description>Reflected XSS vulnerability (CVE-2026-1434) has been found in Omega-PSIR software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 26 Feb 2026 12:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-02-26:/en/posts/2026/02/CVE-2026-1434/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Simple.ERP software</title><link>https://cert.pl/en/posts/2026/02/CVE-2026-1198/</link><description>SQL Injection vulnerability (CVE-2026-1198) has been found in Simple.ERP software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 26 Feb 2026 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-02-26:/en/posts/2026/02/CVE-2026-1198/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in multiple Finka applications</title><link>https://cert.pl/en/posts/2026/02/CVE-2025-13776/</link><description>Use of Hard-coded Credentials vulnerability (CVE-2025-13776) has been found in Finka-FK, Finka-KPR, Finka-Płace, Finka-Faktura, Finka-Magazyn, Finka-STW applications.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 24 Feb 2026 15:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-02-24:/en/posts/2026/02/CVE-2025-13776/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in multiple Slican devices</title><link>https://cert.pl/en/posts/2026/02/CVE-2025-14577/</link><description>Missing Authentication for Critical Function vulnerability (CVE-2025-14577) has been found in in multiple Slican devices.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 24 Feb 2026 12:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-02-24:/en/posts/2026/02/CVE-2025-14577/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>ClickFix in action: how fake captcha can lead to a company-wide infection</title><link>https://cert.pl/en/posts/2026/02/fake-captcha-in-action/</link><description>We assisted a large organisation in the investigation and remediation of a live malware infection caused by a successful Fake Captcha attack. In this report, we summarize our observations and publish an in-depth malware analysis.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jarosław Jedynak</dc:creator><pubDate>Tue, 17 Feb 2026 10:00:00 +0200</pubDate><guid isPermaLink="false">tag:cert.pl,2026-02-17:/en/posts/2026/02/fake-captcha-in-action/</guid><category>News</category><category>malware</category><category>analysis</category><category>dfir</category></item><item><title>Vulnerabilities in Quick.Cart software</title><link>https://cert.pl/en/posts/2026/02/CVE-2026-23796/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2026-23796 and CVE-2026-23797) found in Quick.Cart software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 05 Feb 2026 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-02-05:/en/posts/2026/02/CVE-2026-23796/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in mObywatel application for iOS</title><link>https://cert.pl/en/posts/2026/02/CVE-2025-11598/</link><description>Exposure of Private Personal Information to an Unauthorized Actor vulnerability (CVE-2025-11598) has been found in mObywatel application for iOS.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 03 Feb 2026 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-02-03:/en/posts/2026/02/CVE-2025-11598/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in EAP Legislator software</title><link>https://cert.pl/en/posts/2026/02/CVE-2026-1186/</link><description>A vulnerability has been found in EAP Legislator software that allows a file archive to be extracted outside the target directory (CVE-2026-1186).</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 02 Feb 2026 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-02-02:/en/posts/2026/02/CVE-2026-1186/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Energy Sector Incident Report - 29 December 2025</title><link>https://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/</link><description>CERT Polska presents a report on the analysis of an incident in the energy sector that occurred on 29 December 2025. The attacks were destructive in nature and targeted wind and photovoltaic farms, a large combined heat and power plant, and a company from the manufacturing sector. The publication aims to raise awareness of the risks associated with sabotage in cyberspace.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 30 Jan 2026 11:00:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-01-30:/en/posts/2026/01/incident-report-energy-sector-2025/</guid><category>News</category><category>report</category><category>incident</category><category>energy</category></item><item><title>Vulnerabilities in firmware of Pix-Link LV-WR21Q routers</title><link>https://cert.pl/en/posts/2026/01/CVE-2025-12386/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2025-12386 and CVE-2025-12387) found in LV-WR21Q firmware.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 27 Jan 2026 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-01-27:/en/posts/2026/01/CVE-2025-12386/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>TCC Bypass vulnerability in Inkscape application for MacOS</title><link>https://cert.pl/en/posts/2026/01/CVE-2025-15523/</link><description>TCC Bypass vulnerability (CVE-2025-15523) has been found in Inkscape application for MacOS.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 22 Jan 2026 13:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-01-22:/en/posts/2026/01/CVE-2025-15523/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Quick.Cart software</title><link>https://cert.pl/en/posts/2026/01/CVE-2025-67683/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2025-67683 and CVE-2025-67684) found in Quick.Cart software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 22 Jan 2026 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-01-22:/en/posts/2026/01/CVE-2025-67683/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Crazy Bubble Tea mobile application</title><link>https://cert.pl/en/posts/2026/01/CVE-2025-14317/</link><description>Exposure of Private Personal Information (CVE-2025-14317) has been identified in Crazy Bubble Tea mobile application.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 14 Jan 2026 12:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-01-14:/en/posts/2026/01/CVE-2025-14317/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Ysoft SafeQ 6 software</title><link>https://cert.pl/en/posts/2026/01/CVE-2025-13175/</link><description>Missing Password Field Masking vulnerability (CVE-2025-13175) has been found in Ysoft SafeQ 6 software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 14 Jan 2026 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-01-14:/en/posts/2026/01/CVE-2025-13175/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in firmware of Vivotek IP7137 camera</title><link>https://cert.pl/en/posts/2026/01/CVE-2025-66049/</link><description>CERT Polska has received a report about 4 vulnerabilities (from CVE-2025-66049 to CVE-2025-66052) found in Vivotek IP7137 camera.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 09 Jan 2026 12:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-01-09:/en/posts/2026/01/CVE-2025-66049/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in firmware of KAON CG3000T/CG3000TC routers</title><link>https://cert.pl/en/posts/2026/01/CVE-2025-7072/</link><description>Use of Hard-coded Credentials vulnerability (CVE-2025-7072) has been found in firmware of KAON routers CG3000T and CG3000TC.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 09 Jan 2026 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-01-09:/en/posts/2026/01/CVE-2025-7072/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Asseco AMDX software</title><link>https://cert.pl/en/posts/2026/01/CVE-2025-4596/</link><description>An issue allowing unauthorized access to medical records (CVE-2025-4596) was found in Asseco AMDX software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 08 Jan 2026 15:56:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-01-08:/en/posts/2026/01/CVE-2025-4596/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Asseco InfoMedica Plus software</title><link>https://cert.pl/en/posts/2026/01/CVE-2025-8306/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2025-8306 and CVE-2025-8307) found in Asseco InfoMedica Plus software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 08 Jan 2026 13:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-01-08:/en/posts/2026/01/CVE-2025-8306/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Kieback&amp;Peter Neutrino-GLT software</title><link>https://cert.pl/en/posts/2026/01/CVE-2025-6225/</link><description>Command Injection vulnerability (CVE-2025-6225) has been found in Kieback&amp;Peter Neutrino-GLT software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 07 Jan 2026 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2026-01-07:/en/posts/2026/01/CVE-2025-6225/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in WODESYS WD-R608U router</title><link>https://cert.pl/en/posts/2025/12/CVE-2025-65007/</link><description>CERT Polska has received a report about 5 vulnerabilities (from CVE-2025-65007 to CVE-2025-65011) found in WODESYS WD-R608U router.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 18 Dec 2025 13:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-12-18:/en/posts/2025/12/CVE-2025-65007/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Govee devices with cloud connectivity firmware</title><link>https://cert.pl/en/posts/2025/12/CVE-2025-10910/</link><description>Authorization Bypass Through User-Controlled Key vulnerability (CVE-2025-10910) has been found in Govee devices with cloud connectivity firmware.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 18 Dec 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-12-18:/en/posts/2025/12/CVE-2025-10910/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in WaveStore Server software</title><link>https://cert.pl/en/posts/2025/12/CVE-2025-65074/</link><description>CERT Polska has received a report about 3 vulnerabilities (from CVE-2025-65074 to CVE-2025-65076) found in WaveStore Server software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 16 Dec 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-12-16:/en/posts/2025/12/CVE-2025-65074/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in OpenSolution QuickCMS software</title><link>https://cert.pl/en/posts/2025/12/CVE-2025-12465/</link><description>SQL Injection vulnerability (CVE-2025-12465) has been found in OpenSolution QuickCMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 02 Dec 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-12-02:/en/posts/2025/12/CVE-2025-12465/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Simple SA Wirtualna Uczelnia software</title><link>https://cert.pl/en/posts/2025/11/CVE-2025-12140/</link><description>Remote Code Execution vulnerability (CVE-2025-12140) has been found in Wirtualna Uczelnia software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 27 Nov 2025 14:40:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-11-27:/en/posts/2025/11/CVE-2025-12140/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in SDMC NE6037 routers</title><link>https://cert.pl/en/posts/2025/11/CVE-2025-8890/</link><description>Authorized shell command injection vulnerability (CVE-2025-8890) has been found in SDMC NE6037 routers.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 27 Nov 2025 14:30:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-11-27:/en/posts/2025/11/CVE-2025-8890/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in SOPlanning software</title><link>https://cert.pl/en/posts/2025/11/CVE-2025-62293/</link><description>CERT Polska has received a report about 8 vulnerabilities (from CVE-2025-62293 to 62297 and from 2025-62729 to CVE-2025-62731) found in SOPlanning software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 20 Nov 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-11-20:/en/posts/2025/11/CVE-2025-62293/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Times Software E-Payroll software</title><link>https://cert.pl/en/posts/2025/11/CVE-2025-9977/</link><description>An improper neutralization of input data has been detected in Times Software E-Payroll, resulting in the possibility of a DoS attack and (potentially) SQL Injection (CVE-2025-9977).</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 18 Nov 2025 14:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-11-18:/en/posts/2025/11/CVE-2025-9977/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Windu CMS software</title><link>https://cert.pl/en/posts/2025/11/CVE-2025-59110/</link><description>CERT Polska has received a report about 8 vulnerabilities (from CVE-2025-59110 to CVE-2025-59117) found in Windu CMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 18 Nov 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-11-18:/en/posts/2025/11/CVE-2025-59110/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in OpenSolution QuickCMS software</title><link>https://cert.pl/en/posts/2025/11/CVE-2025-9982/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2025-9982 and CVE-2025-10018) found in OpenSolution QuickCMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 14 Nov 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-11-14:/en/posts/2025/11/CVE-2025-9982/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Analysis of NGate malware campaign (NFC relay)</title><link>https://cert.pl/en/posts/2025/11/analiza-ngate/</link><description>CERT Polska has observed new samples of mobile malware in recent months associated with an NFC Relay (NGate) attack targeting users of Polish banks.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Kacper Ratajczak</dc:creator><pubDate>Mon, 03 Nov 2025 10:37:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-11-03:/en/posts/2025/11/analiza-ngate/</guid><category>News</category><category>nfc</category><category>analysis</category><category>android</category><category>analiza</category></item><item><title>Vulnerability in Eveo URVE Smart Office software</title><link>https://cert.pl/en/posts/2025/10/CVE-2025-10348/</link><description>Cross-site Scripting vulnerability (CVE-2025-10348) has been found in Eveo URVE Smart Office software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 30 Oct 2025 13:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-10-30:/en/posts/2025/10/CVE-2025-10348/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in OpenSolution Quick.Cart software</title><link>https://cert.pl/en/posts/2025/10/CVE-2025-10317/</link><description>Cross-Site Request Forgery (CSRF) vulnerability (CVE-2025-10317) has been found in OpenSolution Quick.Cart software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 30 Oct 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-10-30:/en/posts/2025/10/CVE-2025-10317/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Asseco Poland mMedica software</title><link>https://cert.pl/en/posts/2025/10/CVE-2025-9313/</link><description>Authentication Bypass Using an Alternate Path or Channel vulnerability (CVE-2025-9313) has been found in Asseco mMedica software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 28 Oct 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-10-28:/en/posts/2025/10/CVE-2025-9313/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Studio Fabryka DobryCMS software</title><link>https://cert.pl/en/posts/2025/10/CVE-2025-8536/</link><description>SQL Injection vulnerability (CVE-2025-8536) has been found in Studio Fabryka DobryCMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 24 Oct 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-10-24:/en/posts/2025/10/CVE-2025-8536/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Request Tracker software</title><link>https://cert.pl/en/posts/2025/10/CVE-2025-9158/</link><description>XSS vulnerability (CVE-2025-9158) has been found in Best Practical Request Tracker software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 24 Oct 2025 07:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-10-24:/en/posts/2025/10/CVE-2025-9158/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in firmware of Vilar VS-IPC1002 IP cameras</title><link>https://cert.pl/en/posts/2025/10/CVE-2025-53701/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2025-53701 and CVE-2025-53702) found in Vilar VS-IPC1002 software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 23 Oct 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-10-23:/en/posts/2025/10/CVE-2025-53701/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in OpenSolution QuickCMS software</title><link>https://cert.pl/en/posts/2025/10/CVE-2025-9980/</link><description>CERT Polska has received a report about 2 vulnerabilities (from CVE-2025-9980 to CVE-2025-9981) found in OpenSolution QuickCMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 23 Oct 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-10-23:/en/posts/2025/10/CVE-2025-9980/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in SIMPLE.ERP software</title><link>https://cert.pl/en/posts/2025/10/CVE-2025-9339/</link><description>SQL Injection vulnerability (CVE-2025-9339) has been found in SIMPLE.ERP software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 21 Oct 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-10-21:/en/posts/2025/10/CVE-2025-9339/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in NetBird VPN software</title><link>https://cert.pl/en/posts/2025/10/CVE-2025-10678/</link><description>Use of Default Credentials vulnerability (CVE-2025-10678) has been found in NetBird VPN software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 20 Oct 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-10-20:/en/posts/2025/10/CVE-2025-10678/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Strapi software</title><link>https://cert.pl/en/posts/2025/10/CVE-2025-3930/</link><description>Insufficient Session Expiration vulnerability (CVE-2025-3930) has been found in Strapi software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 16 Oct 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-10-16:/en/posts/2025/10/CVE-2025-3930/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in PAD CMS software</title><link>https://cert.pl/en/posts/2025/09/CVE-2025-7063/</link><description>CERT Polska has coordinated disclousure of 9 vulnerabilities (CVE-2025-7063, CVE-2025-7065 and from CVE-2025-8116 to CVE-2025-8122) found in PAD CMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 30 Sep 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-09-30:/en/posts/2025/09/CVE-2025-7063/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in CivetWeb software</title><link>https://cert.pl/en/posts/2025/09/CVE-2025-9648/</link><description>Improper Neutralization of NUL Character vulnerability (CVE-2025-9648) has been found in CivetWeb software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 29 Sep 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-09-29:/en/posts/2025/09/CVE-2025-9648/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in GALAYOU G2 software</title><link>https://cert.pl/en/posts/2025/09/CVE-2025-9983/</link><description>Missing Authentication for Critical Function vulnerability (CVE-2025-9983) has been found in GALAYOU G2 software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 22 Sep 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-09-22:/en/posts/2025/09/CVE-2025-9983/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Sparkle software</title><link>https://cert.pl/en/posts/2025/09/CVE-2025-10015/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2025-10015 and CVE-2025-10016) found in Sparkle software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 16 Sep 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-09-16:/en/posts/2025/09/CVE-2025-10015/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in SMSEagle devices</title><link>https://cert.pl/en/posts/2025/09/CVE-2025-10095/</link><description>SQL Injection (CVE-2025-10095) has been found in SMSEagle firmware.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 09 Sep 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-09-09:/en/posts/2025/09/CVE-2025-10095/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in ITCube CRM software</title><link>https://cert.pl/en/posts/2025/09/CVE-2025-5993/</link><description>Path Traversal vulnerability (CVE-2025-5993) has been found in ITCube CRM software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 08 Sep 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-09-08:/en/posts/2025/09/CVE-2025-5993/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Concept Intermedia GOV CMS software</title><link>https://cert.pl/en/posts/2025/09/CVE-2025-7385/</link><description>SQL Injection vulnerability (CVE-2025-7385) has been found in Concept Intermedia GOV CMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 04 Sep 2025 13:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-09-04:/en/posts/2025/09/CVE-2025-7385/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Payload CMS software</title><link>https://cert.pl/en/posts/2025/08/CVE-2025-4643/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2025-4643 and CVE-2025-4644).</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 29 Aug 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-08-29:/en/posts/2025/08/CVE-2025-4643/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in OpenSolution QuickCMS software</title><link>https://cert.pl/en/posts/2025/08/CVE-2025-54540/</link><description>CERT Polska has received a report about 6 vulnerabilities (from CVE-2025-54540 to CVE-2025-55175) found in OpenSolution QuickCMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 28 Aug 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-08-28:/en/posts/2025/08/CVE-2025-54540/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in CGM CLININET software</title><link>https://cert.pl/en/posts/2025/08/CVE-2025-2313/</link><description>CERT Polska has received a report about 17 vulnerabilities (between CVE-2025-2313 and CVE-2025-30064) found in CGM CLININET software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 27 Aug 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-08-27:/en/posts/2025/08/CVE-2025-2313/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in OpenSolution Quick.CMS and Quick.CMS.Ext software</title><link>https://cert.pl/en/posts/2025/08/CVE-2025-54172/</link><description>CERT Polska has received a report about 3 vulnerabilities (CVE-2025-54172, CVE-2025-54174 and CVE-2025-54175) found in OpenSolution Quick.CMS and Quick.CMS.Ext software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 20 Aug 2025 12:00:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-08-20:/en/posts/2025/08/CVE-2025-54172/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Akcess-Net Lepszy BIP software</title><link>https://cert.pl/en/posts/2025/08/CVE-2025-7761/</link><description>Cross-site Scripting (XSS) vulnerability (CVE-2025-7761) has been found in Akcess-Net Lepszy BIP software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 14 Aug 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-08-14:/en/posts/2025/08/CVE-2025-7761/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>TCC Bypass vulnerabilities in six applications for MacOS</title><link>https://cert.pl/en/posts/2025/08/tcc-bypass/</link><description>TCC Bypass vulnerabilities has been found in GIMP (CVE-2025-8672), Mosh-Pro (CVE-2025-53811), Cursor (CVE-2025-9190), MacVim (CVE-2025-8597), Nozbe (CVE-2025-53813) and Invoice Ninja (CVE-2025-8700) applications for MacOS.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 11 Aug 2025 15:00:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-08-11:/en/posts/2025/08/tcc-bypass/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Flexibits Fantastical software</title><link>https://cert.pl/en/posts/2025/08/CVE-2025-8533/</link><description>Incorrect Authorization vulnerability (CVE-2025-8533) has been found in Flexibits Fantastical software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 07 Aug 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-08-07:/en/posts/2025/08/CVE-2025-8533/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in TSplus Remote Access software</title><link>https://cert.pl/en/posts/2025/07/CVE-2025-5922/</link><description>Insufficiently Protected Credentials vulnerability (CVE-2025-5922) has been found in TSplus Remote Access software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 29 Jul 2025 15:00:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-07-29:/en/posts/2025/07/CVE-2025-5922/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in FARA software</title><link>https://cert.pl/en/posts/2025/07/CVE-2025-4049/</link><description>CERT Polska has received a report about Hard-coded Credentials vulnerability (CVE-2025-4049) found in SIGNUM-NET FARA software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 21 Jul 2025 10:00:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-07-21:/en/posts/2025/07/CVE-2025-4049/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in applications preloaded on Bluebird smartphones</title><link>https://cert.pl/en/posts/2025/07/CVE-2025-5344/</link><description>CERT Polska has received a report about 3 vulnerabilities (from CVE-2025-5344 to CVE-2025-5346) found in applications preloaded on Bluebird smartphones.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 17 Jul 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-07-17:/en/posts/2025/07/CVE-2025-5344/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in SUR-FBD CMMS software</title><link>https://cert.pl/en/posts/2025/07/CVE-2025-3920/</link><description>Use of Hard-coded Password vulnerability (CVE-2025-3920) has been found in SUR-FBD CMMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 07 Jul 2025 12:00:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-07-07:/en/posts/2025/07/CVE-2025-3920/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>TCC Bypass vulnerabilities in two macOS applications</title><link>https://cert.pl/en/posts/2025/06/tcc-bypass/</link><description>TCC Bypass vulnerability has been found in two macOS applications: Phoneix Code (CVE-2025-5255), Postbox (CVE-2025-5963).</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 20 Jun 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-06-20:/en/posts/2025/06/tcc-bypass/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>UNC1151 exploiting Roundcube to steal user credentials in a spearphishing campaign</title><link>https://cert.pl/en/posts/2025/06/unc1151-campaign-roundcube/</link><description>CERT Polska is observing a malicious email campaign conducted by the UNC1151 group against Polish entities, exploiting a vulnerability in the Roundcube software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 05 Jun 2025 14:00:00 +0200</pubDate><guid isPermaLink="false">tag:cert.pl,2025-06-05:/en/posts/2025/06/unc1151-campaign-roundcube/</guid><category>News</category><category>analysis</category><category>CVE-2024-42009</category><category>roundcube</category><category>unc1151</category></item><item><title>Vulnerability in 2ClickPortal software</title><link>https://cert.pl/en/posts/2025/06/CVE-2025-4568/</link><description>SQL Injection vulnerability (CVE-2025-4568) has been found in 2ClickPortal software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 05 Jun 2025 12:00:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-06-05:/en/posts/2025/06/CVE-2025-4568/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in applications preloaded on Ulefone and Krüger&amp;Matz smartphones</title><link>https://cert.pl/en/posts/2025/05/CVE-2024-13915/</link><description>CERT Polska has received a report about 3 vulnerabilities (from CVE-2024-13915 to CVE-2024-13917) found in applications preloaded on Ulefone and Krüger&amp;Matz smartphones.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 30 May 2025 16:00:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-05-30:/en/posts/2025/05/CVE-2024-13915/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>TCC Bypass vulnerabilities in three macOS applications</title><link>https://cert.pl/en/posts/2025/05/tcc-bypass/</link><description>TCC Bypass vulnerability has been found in three macOS applications: Poedit (CVE-2025-4280), Viscosity (CVE-2025-4412), DaVinci Resolve (CVE-2025-4081)</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 29 May 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-05-29:/en/posts/2025/05/tcc-bypass/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in hackney open-source project</title><link>https://cert.pl/en/posts/2025/05/CVE-2025-3864/</link><description>Incorrect connection releasing causing pool exhaustion (CVE-2025-3864) has been found in hackney software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 28 May 2025 11:00:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-05-28:/en/posts/2025/05/CVE-2025-3864/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Be-Tech Mifare Classic cards software</title><link>https://cert.pl/en/posts/2025/05/CVE-2025-4053/</link><description>Cleartext Storage of Sensitive Information vulnerability (CVE-2025-4053) has been found in Be-Tech Mifare Classic cards software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 26 May 2025 12:00:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-05-26:/en/posts/2025/05/CVE-2025-4053/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Studio Fabryka DobryCMS software</title><link>https://cert.pl/en/posts/2025/05/CVE-2025-4379/</link><description>Cross-site Scripting (XSS) vulnerability (CVE-2025-4379) has been found in Studio Fabryka DobryCMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 23 May 2025 11:55:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-05-23:/en/posts/2025/05/CVE-2025-4379/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Three vulnerabilities in MegaBIP software</title><link>https://cert.pl/en/posts/2025/05/CVE-2025-3893/</link><description>CERT Polska has received a report about 3 vulnerabilities (from CVE-2025-3893 to CVE-2025-3895) found in MegaBIP software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 23 May 2025 10:00:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-05-23:/en/posts/2025/05/CVE-2025-3893/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Multiple vulnerabilities in Proget software</title><link>https://cert.pl/en/posts/2025/05/CVE-2025-1415/</link><description>CERT Polska has received a report about 7 vulnerabilities (from CVE-2025-1415 to CVE-2025-1421) found in Proget software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 21 May 2025 12:00:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-05-21:/en/posts/2025/05/CVE-2025-1415/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in EZD RP software</title><link>https://cert.pl/en/posts/2025/05/CVE-2025-4430/</link><description>Missing Authorization vulnerability (CVE-2025-4430) has been found in EZD RP software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 14 May 2025 12:00:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-05-14:/en/posts/2025/05/CVE-2025-4430/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Netis Systems WF2220 software</title><link>https://cert.pl/en/posts/2025/05/CVE-2025-3758/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2025-3758 and CVE-2025-3759) found in Netis Systems WF2220 software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 08 May 2025 12:00:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-05-08:/en/posts/2025/05/CVE-2025-3758/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Deobfuscation techniques: Peephole deobfuscation</title><link>https://cert.pl/en/posts/2025/04/peephole-deobfuscation/</link><description>In this article we describe a basic deobfuscation technique by leveraging a code snippet substitution.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jarosław Jedynak</dc:creator><pubDate>Thu, 24 Apr 2025 15:00:00 +0200</pubDate><guid isPermaLink="false">tag:cert.pl,2025-04-24:/en/posts/2025/04/peephole-deobfuscation/</guid><category>News</category><category>re</category><category>deobfuscation</category><category>malware</category><category>analysis</category></item><item><title>Vulnerabilities in Symfonia Ready_ software</title><link>https://cert.pl/en/posts/2025/04/CVE-2025-1980/</link><description>CERT Polska has received a report about 4 vulnerabilities (from CVE-2025-1980 to CVE-2025-1983) found in Symfonia Ready_ software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 16 Apr 2025 15:00:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-04-16:/en/posts/2025/04/CVE-2025-1980/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in SoftCOM iKSORIS software</title><link>https://cert.pl/en/posts/2025/04/CVE-2024-10087/</link><description>CERT Polska has received a report about 11 vulnerabilities found in Internet Starter module of SoftCOM iKSORIS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 14 Apr 2025 12:00:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-04-14:/en/posts/2025/04/CVE-2024-10087/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Annual report from the actions of CERT Polska 2024</title><link>https://cert.pl/en/posts/2025/04/annual-report-2024/</link><description>Another year of CERT Polska’s activities is behind us. An absolutely record-breaking year, if we take into account practically all the statistics cited in our previous reports. Behind these numbers is the daily work of experts who care for the safety of Poles online every day. This year’s report is about this work, the key challenges we face and the threats we analyse.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 03 Apr 2025 12:40:00 +0200</pubDate><guid isPermaLink="false">tag:cert.pl,2025-04-03:/en/posts/2025/04/annual-report-2024/</guid><category>News</category><category>annual report</category><category>report</category></item><item><title>Meta is not adequately meeting the demands of CERT Polska</title><link>https://cert.pl/en/posts/2025/03/evaluation-of-expectations-towards-meta/</link><description>The problem of scammers exploiting social media platforms continues to persist. Meta has yet to fulfill all the recommendations made last year by experts from the CERT Polska team at NASK, which were intended to enhance the safety of Polish social media users.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 31 Mar 2025 13:45:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-03-31:/en/posts/2025/03/evaluation-of-expectations-towards-meta/</guid><category>News</category><category>facebook</category><category>meta</category><category>advertisements</category><category>scam</category></item><item><title>Two vulnerabilities in Streamsoft Prestiż software</title><link>https://cert.pl/en/posts/2025/03/CVE-2024-7407/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2024-11504 and CVE-2024-7407) found in Streamsoft Prestiż software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 28 Mar 2025 12:00:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-03-28:/en/posts/2025/03/CVE-2024-7407/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Fast CAD Reader application</title><link>https://cert.pl/en/posts/2025/03/CVE-2025-2098/</link><description>Incorrect Privilege Assignment vulnerability (CVE-2025-2098) has been found in Fast CAD Reader (Beijing Honghu Yuntu Technology) application.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 26 Mar 2025 16:00:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-03-26:/en/posts/2025/03/CVE-2025-2098/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in OXARI ServiceDesk software</title><link>https://cert.pl/en/posts/2025/03/CVE-2025-1542/</link><description>Incorrect Authorization vulnerability (CVE-2025-1542) has been found in Infonet Projekt SA OXARI ServiceDesk software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 26 Mar 2025 12:00:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-03-26:/en/posts/2025/03/CVE-2025-1542/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in SIMPLE.ERP software</title><link>https://cert.pl/en/posts/2025/03/CVE-2024-8773/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2024-8773 and CVE-2024-8774) found in SIMPLE.ERP software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 24 Mar 2025 12:00:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-03-24:/en/posts/2025/03/CVE-2024-8773/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in NASK-PIB BotSense software</title><link>https://cert.pl/en/posts/2025/03/CVE-2025-1774/</link><description>Improper Neutralization of Value Delimiters vulnerability (CVE-2025-1774) has been found in NASK - PIB BotSense software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 17 Mar 2025 16:00:00 +0100</pubDate><guid isPermaLink="false">tag:cert.pl,2025-03-17:/en/posts/2025/03/CVE-2025-1774/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item></channel></rss>