Aggregator
U.S. sanctioned North Korea bankers for laundering funds linked to cyberattacks and peapons program
3 months 1 week ago
U.S. sanctions North Korea bankers and firms accused of laundering cybercrime funds used to finance the country’s nuclear weapons program. The U.S. Government has imposed sanctions on several North Korea bankers, financial institutions, and individuals accused of laundering funds obtained from cybercrime operations. According to the U.S. Treasury Department, these illicit financial activities directly support […]
Pierluigi Paganini
CVE-2025-11268 | Strong Testimonials Plugin up to 3.2.16 on WordPress Shortcode Remote Code Execution (EUVD-2025-37981)
3 months 1 week ago
A vulnerability was found in Strong Testimonials Plugin up to 3.2.16 on WordPress. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the component Shortcode Handler. The manipulation leads to Remote Code Execution.
This vulnerability is documented as CVE-2025-11268. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2025-62161 | youki Mount race condition (CNNVD-202511-473)
3 months 1 week ago
A vulnerability was found in youki. It has been declared as problematic. Affected is an unknown function of the component Mount Handler. Executing manipulation can lead to race condition.
This vulnerability is registered as CVE-2025-62161. The attack requires access to the local network. No exploit is available.
vuldb.com
CVE-2025-62596 | youki access control (CNNVD-202511-472)
3 months 1 week ago
A vulnerability was found in youki. It has been classified as critical. This impacts an unknown function. Performing manipulation results in improper access controls.
This vulnerability is cataloged as CVE-2025-62596. The attack must originate from the local network. There is no exploit available.
vuldb.com
CVE-2025-52881 | opencontainers runc access control (Nessus ID 274068)
3 months 1 week ago
A vulnerability was found in opencontainers runc and classified as critical. This affects an unknown function. Such manipulation leads to improper access controls.
This vulnerability is listed as CVE-2025-52881. The attack must be carried out from within the local network. There is no available exploit.
vuldb.com
CVE-2025-52565 | opencontainers runc Config File /dev/console access control (Nessus ID 274068)
3 months 1 week ago
A vulnerability has been found in opencontainers runc and classified as critical. The impacted element is an unknown function of the file /dev/console of the component Config File Handler. This manipulation causes improper access controls.
This vulnerability is tracked as CVE-2025-52565. The attack is only possible within the local network. No exploit exists.
vuldb.com
CVE-2025-31133 | opencontainers runc Mount race condition (Nessus ID 274068)
3 months 1 week ago
A vulnerability, which was classified as problematic, was found in opencontainers runc. The affected element is an unknown function of the component Mount Handler. The manipulation results in race condition.
This vulnerability is identified as CVE-2025-31133. The attack can only be performed from the local network. There is not any exploit available.
vuldb.com
CVE-2025-12471 | Hubbub Lite Plugin up to 1.36.0 on WordPress dpsp_list_attention_search cross site scripting (EUVD-2025-37978)
3 months 1 week ago
A vulnerability, which was classified as problematic, has been found in Hubbub Lite Plugin up to 1.36.0 on WordPress. Impacted is an unknown function. The manipulation of the argument dpsp_list_attention_search leads to cross site scripting.
This vulnerability is referenced as CVE-2025-12471. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2025-12360 | Better Find and Replace Plugin up to 1.7.7 on WordPress API rtafar_ajax authorization (EUVD-2025-37979)
3 months 1 week ago
A vulnerability classified as critical was found in Better Find and Replace Plugin up to 1.7.7 on WordPress. This issue affects the function rtafar_ajax of the component API. Executing manipulation can lead to missing authorization.
The identification of this vulnerability is CVE-2025-12360. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-10853 | WSO2 Open Banking IAM Management Console cross site scripting
3 months 1 week ago
A vulnerability classified as problematic has been found in WSO2 Open Banking IAM, API Manager, Identity Server, Open Banking AM, Identity Server as Key Manager, Enterprise Integrator, API Control Plane, Universal Gateway, Traffic Manager, org.wso2.carbon.registry:org.wso2.carbon.registry.info.ui, org.wso2.carbon.registry:org.wso2.carbon.registry.resource.ui, org.wso2.carbon.governance:org.wso2.carbon.governance.wsdltool.ui and org.wso2.carbon.identity.inbound.auth.oauth2:org.wso2.carbon.identity.oauth.ui. This vulnerability affects unknown code of the component Management Console. Performing manipulation results in cross site scripting.
This vulnerability was named CVE-2025-10853. The attack needs to be approached within the local network. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-63418 | SelfBest Platform 2023.3 cross site scripting
3 months 1 week ago
A vulnerability described as problematic has been identified in SelfBest Platform 2023.3. This affects an unknown part. Such manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-63418. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2025-63417 | SelfBest Platform 2023.3 Chat Message cross site scripting
3 months 1 week ago
A vulnerability marked as problematic has been reported in SelfBest Platform 2023.3. Affected by this issue is some unknown functionality of the component Chat Message Handler. This manipulation causes cross site scripting.
This vulnerability is handled as CVE-2025-63417. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2025-56231 | Tonec Internet Download Manager up to 6.42.41.1 certificate validation
3 months 1 week ago
A vulnerability labeled as critical has been found in Tonec Internet Download Manager up to 6.42.41.1. Affected by this vulnerability is an unknown functionality. The manipulation results in improper certificate validation.
This vulnerability is known as CVE-2025-56231. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2025-5770 | WSO2 Identity Server/API Manager/API Control Plane Authentication Endpoint cross site scripting
3 months 1 week ago
A vulnerability identified as problematic has been detected in WSO2 Identity Server, API Manager and API Control Plane. Affected is an unknown function of the component Authentication Endpoint. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-5770. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2025-63416 | SelfBest Platform 2023.3 Chat /admin/users cross site scripting
3 months 1 week ago
A vulnerability categorized as problematic has been discovered in SelfBest Platform 2023.3. This impacts an unknown function of the file /admin/users of the component Chat. Executing manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2025-63416. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2025-43418 | Apple iOS/iPadOS up to 18.7.1 information disclosure
3 months 1 week ago
A vulnerability was found in Apple iOS and iPadOS up to 18.7.1. It has been rated as problematic. This affects an unknown function. Performing manipulation results in information disclosure.
This vulnerability is reported as CVE-2025-43418. The attack may be carried out on the physical device. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-55341 | Quipux up to 4.0.1 anexos/anexos_nuevo.php asocImgRad cross site scripting
3 months 1 week ago
A vulnerability was found in Quipux up to 4.0.1. It has been declared as problematic. The impacted element is an unknown function of the file anexos/anexos_nuevo.php. Such manipulation of the argument asocImgRad leads to cross site scripting.
This vulnerability is documented as CVE-2025-55341. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2025-11093 | WSO2 Micro Integrator Script Mediator Engine code injection
3 months 1 week ago
A vulnerability was found in WSO2 Micro Integrator, API Manager, Enterprise Integrator, Universal Gateway, API Control Plane, Traffic Manager, Open Banking IAM, Open Banking AM, Identity Server as Key Manager, org.apache.synapse:synapse-core and org.apache.synapse:synapse-extensions. It has been classified as critical. The affected element is an unknown function of the component Script Mediator Engine. This manipulation causes code injection.
This vulnerability is registered as CVE-2025-11093. The attack requires access to the local network. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-56232 | GOG Galaxy 2.0.0.2 certificate validation
3 months 1 week ago
A vulnerability was found in GOG Galaxy 2.0.0.2 and classified as critical. Impacted is an unknown function. The manipulation results in improper certificate validation.
This vulnerability is cataloged as CVE-2025-56232. The attack may be launched remotely. There is no exploit available.
vuldb.com