Aggregator
CVE-2025-2194 | MRCMS 3.1.2 org.marker.mushroom.controller.FileController /admin/file/list.do list path cross site scripting
CVE-2025-3102 | SureTriggers Plugin up to 1.0.78 on WordPress autheticate_user secret_key authorization
CVE-2024-13909 | Accredible Certificates & Open Badges Plugin up to 1.4.9 on WordPress orderby sql injection
CVE-2024-10894 | Payment Forms for Paystack Plugin up to 4.0.2 on WordPress Shortcode cross site scripting
CVE-2025-3489 | Nababur Simple-User-Management-System 1.0 /register.php name/username cross site scripting
CVE-2023-40159 | Philips Vue PACS prior 12.2.8.410 information disclosure (icsma-24-200-01)
CVE-2023-40223 | Philips Vue PACS prior 12.2.8.410 Actor privileges management (icsma-24-200-01)
CVE-2023-40539 | Philips Vue PACS prior 12.2.8.410 weak password (icsma-24-200-01)
CVE-2023-40704 | Philips Vue PACS prior 12.2.8.410 default credentials (icsma-24-200-01)
Set_password, и вуаля: FortiSwitch сам отдаёт ключи
Microsoft Identity Web Flaw Exposes Sensitive Client Secrets and Certificates
A new vulnerability has been discovered in the Microsoft.Identity.Web NuGet package under specific conditions, potentially exposing sensitive information such as client secrets and certificate details in service logs. The flaw, identified as CVE-2025-32016, has been rated as moderate, prompting developers to urgently address the issue to prevent unintended data exposure. Overview of the Vulnerability: The vulnerability […]
The post Microsoft Identity Web Flaw Exposes Sensitive Client Secrets and Certificates appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CatB Ransomware Abuses Microsoft Distributed Transaction Coordinator for Stealthy Payload Execution
The cybersecurity realm has encountered a formidable adversary with the emergence of CatB ransomware, also known as CatB99 or Baxtoy. First identified in late 2022, this strain has caught the eye of security analysts due to its sophisticated evasion techniques and its potential connection to established ransomware families. There’s speculation within the security community that […]
The post CatB Ransomware Abuses Microsoft Distributed Transaction Coordinator for Stealthy Payload Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-32145 | magepeopleteam WpEvently Plugin up to 4.3.5 on WordPress deserialization
CVE-2025-32128 | aaronfrey Nearby Locations Plugin up to 1.1.1 on WordPress sql injection
CVE-2025-32116 | Studi7 QR Master Plugin up to 1.0.5 on WordPress cross site scripting
CVE-2025-32115 | OTWthemes Popping Content Light Plugin up to 2.4 on WordPress cross site scripting
Hackers Allegedly Claiming WooCommerce Breach, 4.4 Million Customer Details Stolen
A hacker known by the alias “Satanic” has claimed responsibility for a massive data breach involving WooCommerce, one of the most widely used eCommerce platforms on the web. The breach, which reportedly occurred on April 6, 2025, involves the theft of over 4.4 million user records, including detailed personal and business information. Cyber Security News […]
The post Hackers Allegedly Claiming WooCommerce Breach, 4.4 Million Customer Details Stolen appeared first on Cyber Security News.