Aggregator
Zero-Day Vulnerability in Ivanti VPN
4 months 4 weeks ago
About Bruce SchneierI am a public-interest technologist, working at the intersection of security,
Fancy Product Designer Plugin Flaws Expose WordPress Sites
4 months 4 weeks ago
Critical Fancy Product Designer plugin flaws risk remote code execution and SQL injection attacks on WordPress sites
CVE-2025-21596 | Juniper Networks Junos OS up to 23.4R2 on SRX pem Command exceptional condition (JSA92864)
4 months 4 weeks ago
A vulnerability was found in Juniper Networks Junos OS up to 23.4R2 on SRX. It has been declared as problematic. This vulnerability affects unknown code of the component pem Command Handler. The manipulation leads to handling of exceptional conditions.
This vulnerability was named CVE-2025-21596. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21602 | Juniper Networks Junos OS/Junos OS Evolved Routing Protocol Daemon exceptional condition (JSA92872 / Nessus ID 213556)
4 months 4 weeks ago
A vulnerability was found in Juniper Networks Junos OS and Junos OS Evolved. It has been classified as critical. This affects an unknown part of the component Routing Protocol Daemon. The manipulation leads to handling of exceptional conditions.
This vulnerability is uniquely identified as CVE-2025-21602. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21599 | Juniper Networks Junos OS Evolved Tunnel Driver memory leak (JSA92869 / Nessus ID 213558)
4 months 4 weeks ago
A vulnerability was found in Juniper Networks Junos OS Evolved and classified as critical. Affected by this issue is some unknown functionality of the component Tunnel Driver. The manipulation leads to memory leak.
This vulnerability is handled as CVE-2025-21599. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21593 | Juniper Networks Junos OS/Junos OS Evolved BGP UPDATE Packet resource control (JSA92861)
4 months 4 weeks ago
A vulnerability has been found in Juniper Networks Junos OS and Junos OS Evolved and classified as critical. Affected by this vulnerability is an unknown functionality of the component BGP UPDATE Packet Handler. The manipulation leads to improper control of resource through lifetime.
This vulnerability is known as CVE-2025-21593. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21600 | Juniper Networks Junos OS/Junos OS Evolved Routing Protocol Daemon out-of-bounds (JSA92870)
4 months 4 weeks ago
A vulnerability, which was classified as critical, was found in Juniper Networks Junos OS and Junos OS Evolved. Affected is an unknown function of the component Routing Protocol Daemon. The manipulation leads to out-of-bounds read.
This vulnerability is traded as CVE-2025-21600. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Cas is Allegedly Selling Access to Huawei
4 months 4 weeks ago
Cas is Allegedly Selling Access to Huawei
Dark Web Informer - Cyber Threat Intelligence
CVE-2025-22823 | Justin Twerdy Genesis Style Shortcodes Plugin up to 1.0 on WordPress cross site scripting
4 months 4 weeks ago
A vulnerability, which was classified as problematic, has been found in Justin Twerdy Genesis Style Shortcodes Plugin up to 1.0 on WordPress. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-22823. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-22822 | Bishawjit Das wp custom countdown Plugin up to 2.8 on WordPress cross site scripting
4 months 4 weeks ago
A vulnerability classified as problematic was found in Bishawjit Das wp custom countdown Plugin up to 2.8 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-22822. The attack can be initiated remotely. There is no exploit available.
vuldb.com
Announcing Supporters of Chromium-based Browsers
4 months 4 weeks ago
Thursday, January 9, 2025
Microsoft fixes bug causing Outlook to freeze when copying text
4 months 4 weeks ago
Microsoft has fixed a known issue causing the classic Outlook email client to stop respondin
US Treasury hack linked to Silk Typhoon Chinese state hackers
4 months 4 weeks ago
Chinese state-backed hackers, tracked as Silk Typhoon, have been linked to the U.S. Office
Everest
4 months 4 weeks ago
cohenido
Everest
4 months 4 weeks ago
cohenido
Everest
4 months 4 weeks ago
cohenido
Seedless and Secure: How 2PC-MPC is Transforming Key Management in Web3
4 months 4 weeks ago
If you’ve spent any amount of time in crypto, you’re likely to have heard the expression “Not your k
CVE-2025-22820 | Daniel Walmsley VR Views Plugin up to 1.5.1 on WordPress cross site scripting
4 months 4 weeks ago
A vulnerability has been found in Daniel Walmsley VR Views Plugin up to 1.5.1 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-22820. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-22811 | Modeltheme MT Addons for Elementor Plugin up to 1.0.6 on WordPress cross site scripting
4 months 4 weeks ago
A vulnerability, which was classified as problematic, was found in Modeltheme MT Addons for Elementor Plugin up to 1.0.6 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-22811. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com