NVD disclosure day

Published threat advisories for July 24, 2025

CVE advisoryCRITICAL

CVE-2025-4784

Moderec Tourtella SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An SQL injection vulnerability exists in Moderec Tourtella, allowing attackers to manipulate database commands over the network. This could lead to unauthorized access, modification, or deletion of sensitive information. Readers should care because this impacts database integrity and confidentiality.

CVE advisoryCRITICAL

CVE-2025-5243

SMG Software Information Portal OS Command Injection and Dangerous File Upload

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unrestricted file upload and OS command injection vulnerability exists in SMG Software Information Portal, potentially allowing attackers to upload a web shell or inject code to compromise the web server. This issue affects versions prior to June 13, 2025, and is network-exploitable.