Aggregator
黑客入侵网站注入恶意链接,借机操纵搜索引擎优化
3 months ago
安全客
DragonForce勒索软件进化:利用BYOVD终结EDR并修复Conti V3加密缺陷
3 months ago
安全客
SuiteCRM中存在SQL注入漏洞(CVE-2025-64492与CVE-2025-64493),致客户数据面临泄露风险
3 months ago
安全客
Triofox零日漏洞(CVE-2025-12480)正遭积极利用:主机头验证绕过可导致未授权管理员接管
3 months ago
安全客
欧盟频谱争夺战:6GHz高频段将归属Wi-Fi 7还是6G网络?
3 months ago
安全客
Windows 11 Version 26H1正式发布,但仅面向骁龙X2等新款ARM芯片
3 months ago
安全客
CVE-2025-12815 | Amazon AWS Research and Engineering Studio prior 2025.09 Virtual Desktop Preview Page unverified ownership (GHSA-x3cx-g8g9-75hv / EUVD-2025-38148)
3 months ago
A vulnerability categorized as problematic has been discovered in Amazon AWS Research and Engineering Studio. This affects an unknown part of the component Virtual Desktop Preview Page. Such manipulation leads to unverified ownership.
This vulnerability is listed as CVE-2025-12815. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2024-33485 | CASAP Automated Enrollment System 1.0 sql injection (EUVD-2024-31223)
3 months ago
A vulnerability classified as critical was found in CASAP Automated Enrollment System 1.0. The impacted element is an unknown function. The manipulation results in sql injection.
This vulnerability was named CVE-2024-33485. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2025-12642 | lighttpd up to 1.4.80 HTTP Request request smuggling (EUVD-2025-37517 / Nessus ID 274352)
3 months ago
A vulnerability classified as problematic has been found in lighttpd up to 1.4.80. This affects an unknown function of the component HTTP Request Handler. Performing manipulation results in http request smuggling.
This vulnerability is reported as CVE-2025-12642. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-12390 | Red Hat Keycloak session fixiation (EUVD-2025-36502 / WID-SEC-2025-2438)
3 months ago
A vulnerability marked as critical has been reported in Red Hat Keycloak. Affected is an unknown function. Performing manipulation results in session fixiation.
This vulnerability is known as CVE-2025-12390. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2025-23419 | F5 NGINX Open Source/NGINX Plus improper authentication (K000149173 / EUVD-2025-3168)
3 months ago
A vulnerability marked as critical has been reported in F5 NGINX Open Source and NGINX Plus. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper authentication.
This vulnerability is uniquely identified as CVE-2025-23419. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-11962 | DivvyDrive Digital Corporate Warehouse prior 4.8.2.22 cross site scripting (EUVD-2025-124978)
3 months ago
A vulnerability was found in DivvyDrive Digital Corporate Warehouse. It has been declared as problematic. This affects an unknown part. Such manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-11962. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
DarkComet Spyware Resurfaces Disguised as Fake Bitcoin Wallet
3 months ago
Old DarkComet RAT spyware is back, hiding inside fake Bitcoin wallets and trading apps to steal credentials via keylogging.
Deeba Ahmed
CVE-2022-49353 | Linux Kernel up to 5.18.3 papr_scm drc_pmem_query_stats null pointer dereference (Nessus ID 274839)
3 months ago
A vulnerability classified as critical has been found in Linux Kernel up to 5.18.3. This issue affects the function drc_pmem_query_stats of the component papr_scm. Performing manipulation results in null pointer dereference.
This vulnerability was named CVE-2022-49353. The attack needs to be approached within the local network. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-49432 | Linux Kernel up to 5.18.2 icp_opal_init reference count (Nessus ID 274839)
3 months ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 5.18.2. The affected element is the function icp_opal_init. Performing manipulation results in improper update of reference count.
This vulnerability is cataloged as CVE-2022-49432. The attack must originate from the local network. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2022-49437 | Linux Kernel up to 5.15.45/5.17.13/5.18.2 of_find_compatible_node reference count (Nessus ID 274839)
3 months ago
A vulnerability was found in Linux Kernel up to 5.15.45/5.17.13/5.18.2 and classified as critical. This impacts the function of_find_compatible_node. The manipulation results in improper update of reference count.
This vulnerability is reported as CVE-2022-49437. The attacker must have access to the local network to execute the attack. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2022-49024 | Linux Kernel up to 5.15.81/6.0.11 m_can_class_free_dev allocation of resources (ea8dc27bb044/0bbb88651ef6/1eca1d4cc21b / Nessus ID 274839)
3 months ago
A vulnerability categorized as problematic has been discovered in Linux Kernel up to 5.15.81/6.0.11. Impacted is the function m_can_class_free_dev. The manipulation results in allocation of resources.
This vulnerability is reported as CVE-2022-49024. The attacker must have access to the local network to execute the attack. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2022-48830 | Linux Kernel up to 5.10.100/5.15.23/5.16.9 CAN isotp_rcv state issue (Nessus ID 274839)
3 months ago
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 5.10.100/5.15.23/5.16.9. Affected by this issue is the function isotp_rcv of the component CAN. This manipulation causes state issue.
This vulnerability is tracked as CVE-2022-48830. The attack is only possible within the local network. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
Stacking Your Defenses: Integrating Advanced Threat Prevention and SIEM
3 months ago
In today’s rapidly evolving threat landscape, effective security operations hinge on two critical pillars: automation and context aggregation. As organizations grapple with increasingly sophisticated attacks, the ability to seamlessly integrate diverse security solutions becomes paramount. This challenge is easily resolved through the successful integration of VMware vDefend Advanced Threat Prevention (ATP) with Security Information and … Continued
The post Stacking Your Defenses: Integrating Advanced Threat Prevention and SIEM appeared first on VMware Security Blog.
Stefano Ortolani and Aditya Gokhale