Aggregator
CVE-2022-3829 | Font Awesome 4 Menus Plugin up to 4.7.0 on WordPress Setting cross site scripting (EUVD-2022-43169)
CVE-2022-3764 | Form Vibes Plugin prior 1.4.6 on WordPress delete_entries sql injection (EUVD-2022-43118)
CVE-2023-0479 | Print Invoice & Delivery Notes for WooCommerce Plugin cross site scripting (EUVD-2023-12531)
CVE-2023-0824 | UserPlus Plugin up to 2.0 on WordPress cross-site request forgery (EUVD-2023-12827)
Insomnia API Client Vulnerability Enables Arbitrary Code Execution via Template Injection
A severe security vulnerability in the Insomnia API Client, a widely used tool by developers and security testers for interacting with APIs, has been uncovered by researchers at an offensive security consultancy. Discovered by Technical Director Marcio Almeida and Head of Research Justin Steven, the flaw allows for arbitrary code execution through a mechanism known […]
The post Insomnia API Client Vulnerability Enables Arbitrary Code Execution via Template Injection appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2023-36558 | Microsoft ASP.NET/.NET/Visual Studio information disclosure (Nessus ID 239747)
CVE-2023-36049 | Microsoft .NET/.NET Framework/Visual Studio privilege escalation (Nessus ID 239747)
CVE-2024-28835 | GnuTLS up to 3.8.3 PEM Bundle Verification uncaught exception (RHSA-2024:1879 / EUVD-2024-25921)
CVE-2020-14145 | OpenSSH up to 8.3 Algorithm Negotiation information disclosure (Nessus ID 239762)
CVE-2023-29533 | Mozilla Firefox up to 111 Notification (Bug 1814597 / Nessus ID 239763)
CVE-2023-29533 | Mozilla Thunderbird up to 102.9 Notification (Bug 1814597 / Nessus ID 239763)
CVE-2025-43200 | Apple watchOS iCloud Link Remote Code Execution (EUVD-2025-18428 / Nessus ID 238308)
Threat Actors Exploit Vercel Hosting Platform to Distribute Remote Access Malware
CyberArmor has uncovered a sophisticated phishing campaign exploiting Vercel, a widely used frontend hosting platform, to distribute a malicious variant of LogMeIn, a legitimate remote access tool. Over the past two months, threat actors have orchestrated at least 28 distinct campaigns, targeting more than 1,271 users with deceptive emails that lead to fraudulent pages hosted […]
The post Threat Actors Exploit Vercel Hosting Platform to Distribute Remote Access Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-43200 | Apple macOS iCloud Link Remote Code Execution (EUVD-2025-18428 / Nessus ID 238308)
Llama выучила Гарри Поттера наизусть. Судья скажет «Авада Кедавра» — и прощайте, миллиарды
AntiDot Android木马:新的MaaS恶意软件记录屏幕,拦截短信,并窃取财务数据
US Pig Butchering Victims ‘Will’ Get Refunds — Feds Seize $225M Cryptocurrency
DoJ, FBI, USSS yoinked USDT: Pretty girls plus investment fraud equals forfeiture recovery (eventually).
The post US Pig Butchering Victims ‘Will’ Get Refunds — Feds Seize $225M Cryptocurrency appeared first on Security Boulevard.