Aggregator
CVE-2025-14450 | WP Swings Wallet System for WooCommerce Plugin up to 2.7.2 on WordPress change_wallet_fund_request_status_callback authorization
CVE-2025-15403 | RegistrationMagic Plugin up to 6.0.7.1 on WordPress Setting add_menu admin_order Remote Code Execution
CVE-2025-12002 | Feeds for YouTube Pro Plugin up to 2.6.0 on WordPress sby_check_wp_submit path traversal
Ядерный удар спасёт Землю от астероида. ЦЕРН доказал: космические камни не разлетаются на осколки при взрыве
CVE-2025-59870 | HCL MyXalytics up to 6.7 JWT Signing Secret nonce re-use (KB0128115)
CVE-2026-0696 | ConnectWise PSA 2025.9 cookie httponly flag
CVE-2026-0695 | ConnectWise PSA 2025.9 cross site scripting
CVE-2025-14510 | ABB Ability OPTIMAX prior 6.3.1-251120/6.4.1-251120 incorrect implementation of authentication algorithm
CVE-2026-0616 | TheLibrarian up to 1.0 web_fetch exposure of sensitive system information to an unauthorized control sphere
CVE-2026-0615 | TheLibrarian up to 1.0 web_fetch exposure of sensitive system information to an unauthorized control sphere
CVE-2026-0613 | TheLibrarian up to 1.0 web_fetch exposure of sensitive system information to an unauthorized control sphere
CVE-2026-0612 | TheLibrarian up to 1.0 web_fetch exposure of sensitive system information to an unauthorized control sphere
CVE-2025-14435 | Mattermost up to 10.11.8/11.0.6/11.1.1 allocation of resources
Cisco fixes AsyncOS vulnerability exploited in zero-day attacks (CVE-2025-20393)
Cisco has finally shipped security updates for its Email Security Gateway and Secure Email and Web Manager devices, which fix CVE-2025-20393, a vulnerability in the devices’ AsyncOS that has been exploited as a zero-day by suspected Chinese attackers since at least late November 2025. The company revealed the flaw’s existence and in-the-wild exploitation on December 17, 2025, and urged customers to check whether their appliances had been breached and to rebuild them in case of … More →
The post Cisco fixes AsyncOS vulnerability exploited in zero-day attacks (CVE-2025-20393) appeared first on Help Net Security.
CVE-2025-15104 | Validator.nu Nu Html Checker 127.0.0.1 server-side request forgery
CVE-2025-14894 | Bee Interactive Livewire Filemanager 0.x LivewireFilemanagerComponent.php unrestricted upload
Никакой Windows, никаких лицензий. Вышел Wine 11.0 — главный способ запускать нужный софт на Linux и Mac
Why Traditional Firewalls Fail Against Today’s High-Volume DDoS Attacks
Traditional firewalls can’t stop modern DDoS attacks. Learn why high-volume, multi-layer attacks overwhelm perimeter defenses—and how to build real DDoS resilience.
The post Why Traditional Firewalls Fail Against Today’s High-Volume DDoS Attacks appeared first on Security Boulevard.