Aggregator
Ivanti: «Мы всё починили». UNC5221: «Спасибо за инструкцию»
10 months 1 week ago
Ivanti экстренно закрывает брешь в защите.
CVE-2010-4942 | E-Xoopport Samsara 3.0/3.1 location.php lid sql injection (EDB-15110 / XFDB-62017)
10 months 1 week ago
A vulnerability classified as critical has been found in E-Xoopport Samsara 3.0/3.1. This affects an unknown part of the file location.php. The manipulation of the argument lid leads to sql injection.
This vulnerability is uniquely identified as CVE-2010-4942. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-32657 | NixOS Hydra up to 23.10 ISO File cross site scripting (GHSA-2p75-6g9f-pqgx)
10 months 1 week ago
A vulnerability, which was classified as problematic, has been found in NixOS Hydra up to 23.10. This issue affects some unknown processing of the component ISO File Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-32657. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-2477 | wpDiscuz Plugin up to 7.6.15 on WordPress Image Alternative Text cross site scripting (ID 3060040)
10 months 1 week ago
A vulnerability classified as problematic was found in wpDiscuz Plugin up to 7.6.15 on WordPress. Affected by this vulnerability is an unknown functionality of the component Image Alternative Text Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-2477. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-3491 | Schema & Structured Data for WP & AMP Plugin up to 1.29 on WordPress How To/FAQ Block cross site scripting (ID 3071620)
10 months 1 week ago
A vulnerability, which was classified as problematic, has been found in Schema & Structured Data for WP & AMP Plugin up to 1.29 on WordPress. Affected by this issue is some unknown functionality of the component How To/FAQ Block Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-3491. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-3732 | GeoDirectory Plugin up to 2.3.48 on WordPress Shortcode gd_single_tabs cross site scripting
10 months 1 week ago
A vulnerability classified as problematic has been found in GeoDirectory Plugin up to 2.3.48 on WordPress. Affected is the function gd_single_tabs of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-3732. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-1959 | Social Sharing Plugin Plugin up to 4.4.6.1 on WordPress Shortcode cross site scripting
10 months 1 week ago
A vulnerability has been found in Social Sharing Plugin Plugin up to 4.4.6.1 on WordPress and classified as problematic. This vulnerability affects unknown code of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-1959. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2019-6215 | Apple iCloud up to 7.9 on Windows WebKit type conversion (HT209451 / EDB-46448)
10 months 1 week ago
A vulnerability, which was classified as critical, was found in Apple iCloud up to 7.9 on Windows. This affects an unknown part of the component WebKit. The manipulation leads to incorrect type conversion.
This vulnerability is uniquely identified as CVE-2019-6215. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CERT-UA reports attacks in March 2025 targeting Ukrainian agencies with WRECKSTEEL Malware
10 months 1 week ago
CERT-UA reported three cyberattacks targeting Ukraine’s state agencies and critical infrastructure to steal sensitive data. The Computer Emergency Response Team of Ukraine (CERT-UA) reported three cyberattacks in March 2025 targeting Ukrainian agencies and infrastructure to steal sensitive data. This activity is tracked under the identifier UAC-0219. “The Ukrainian government’s computer emergency response team, CERT-UA, is […]
Pierluigi Paganini
Rafts of Security Bugs Could Rain Out Solar Grids
10 months 1 week ago
At least three major energy solution and renewable energy companies have nearly 50 vulnerabilities — many of them "basic" mistakes — indicating a lack of developed cybersecurity safeguards.
Kristina Beek, Associate Editor, Dark Reading
CVE-2025-30432 | Apple iOS/iPadOS App state issue
10 months 1 week ago
A vulnerability was found in Apple iOS and iPadOS and classified as problematic. Affected by this issue is some unknown functionality of the component App. The manipulation leads to state issue.
This vulnerability is handled as CVE-2025-30432. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-30432 | Apple visionOS App state issue
10 months 1 week ago
A vulnerability was found in Apple visionOS. It has been classified as problematic. This affects an unknown part of the component App. The manipulation leads to state issue.
This vulnerability is uniquely identified as CVE-2025-30432. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-30432 | Apple macOS App state issue
10 months 1 week ago
A vulnerability was found in Apple macOS. It has been declared as problematic. This vulnerability affects unknown code of the component App. The manipulation leads to state issue.
This vulnerability was named CVE-2025-30432. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-29069 | lcms2 2.16 cmspack.c UnrollChunkyBytes heap-based overflow (Issue 476)
10 months 1 week ago
A vulnerability, which was classified as critical, has been found in lcms2 2.16. Affected by this issue is the function UnrollChunkyBytes of the file cmspack.c. The manipulation leads to heap-based buffer overflow.
This vulnerability is handled as CVE-2025-29069. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2025-29070 | lcms2 2.16 cmsgamma.c thesmooth2 denial of service (Issue 475)
10 months 1 week ago
A vulnerability classified as problematic has been found in lcms2 2.16. This affects the function thesmooth2 of the file cmsgamma.c. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2025-29070. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-1805 | HACHI Crypt::Salt 0.01 on Perl rand weak prng
10 months 1 week ago
A vulnerability was found in HACHI Crypt::Salt 0.01 on Perl and classified as problematic. Affected by this issue is the function rand. The manipulation leads to cryptographically weak prng.
This vulnerability is handled as CVE-2025-1805. The attack may be launched remotely. There is no exploit available.
vuldb.com
Вспомните «Терминатора». Теперь забудьте — DeepMind описала угрозу страшнее в 108-страничном докладе
10 months 1 week ago
Четыре способа, как AGI может всё испортить. И ни одного — как спасти.
HSCC Urges White House to Shift Gears on Health Cyber Regs
10 months 1 week ago
The Health Sector Coordinating Council is urging the Trump administration to drop work on a proposed HIPAA security rule update and instead engage in a collaborative dialogue with healthcare sector leaders to create alternative cyber requirements, said Greg Garcia, executive director of HSCC.
Webinar | Zero-Standing Privileges Explained
10 months 1 week ago