Het tempo om nieuwe mensen binnen te halen moet omhoog. Daarom heeft Defensie vandaag een nieuwe wervingscampagne gelanceerd. De organisatie moet in 2030 minstens 100.000 mannen en vrouwen tellen. In de jaren daarna kan dat aantal mogelijk nog verdubbelen. De nood is hoog, de urgentie om te werven ook.
Currently trending CVE - Hype Score: 60 - Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter ...
Currently trending CVE - Hype Score: 31 - Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite serving allow list. Adding `?raw??` or `?import&raw??` to the URL bypasses this limitation and ...
Currently trending CVE - Hype Score: 37 - CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0 are affected by a vulnerability that may result in unauthenticated access. Remote and unauthenticated HTTP requests to CrushFTP may allow attackers to gain unauthorized access.
Currently trending CVE - Hype Score: 10 - Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.
Currently trending CVE - Hype Score: 26 - Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High)
Currently trending CVE - Hype Score: 60 - A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx ...
Currently trending CVE - Hype Score: 62 - A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the ...
Currently trending CVE - Hype Score: 60 - A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mirror-host` Ingress annotations can be used to inject arbitrary configuration into nginx. This can lead to arbitrary code execution in the context of ...
Currently trending CVE - Hype Score: 60 - A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and ...
Currently trending CVE - Hype Score: 60 - Next.js is a React framework for building full-stack web applications. Prior to 14.2.25 and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware. If patching to a safe version is infeasible, it is ...
A vulnerability was found in Dell Avamar up to 19.10 SP1. It has been rated as critical. This issue affects some unknown processing of the component AUI. The manipulation leads to operation on a resource after expiration.
The identification of this vulnerability is CVE-2025-21117. An attack has to be approached locally. There is no exploit available.
A vulnerability was found in Cisco Identity Services Engine Software and ISE Passive Identity Connector. It has been classified as critical. Affected is an unknown function of the component API. The manipulation leads to deserialization.
This vulnerability is traded as CVE-2025-20124. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Cisco Identity Services Engine Software and ISE Passive Identity Connector. It has been rated as critical. Affected by this issue is some unknown functionality of the component API. The manipulation leads to improper authorization.
This vulnerability is handled as CVE-2025-20125. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in Cisco Identity Services Engine Software. This issue affects some unknown processing of the component Web-based Management Interface. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-20204. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in Cisco Identity Services Engine Software. Affected is an unknown function of the component Web-based Management Interface. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-20205. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in stylemix Directory Listings WordPress plugin up to 2.1.7 on WordPress. Affected is an unknown function of the component Post Meta Data Handler. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2025-1657. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability has been found in codexpert WC Affiliate Plugin up to 2.5.3 on WordPress and classified as problematic. Affected by this vulnerability is the function export_all_data. The manipulation leads to missing authorization.
This vulnerability is known as CVE-2024-12336. The attack can be launched remotely. There is no exploit available.