Aggregator
CVE-2025-49185 | SICK Field Analytics Dashboard Widget Transform cross site scripting
3 months ago
A vulnerability has been found in SICK Field Analytics and classified as problematic. This vulnerability affects the function Transform of the component Dashboard Widget. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-49185. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-49187 | SICK Field Analytics Failed Login observable response discrepancy
3 months ago
A vulnerability, which was classified as problematic, was found in SICK Field Analytics. This affects an unknown part of the component Failed Login Handler. The manipulation leads to observable response discrepancy.
This vulnerability is uniquely identified as CVE-2025-49187. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-49191 | SICK Field Analytics iFrame Widget ui layer
3 months ago
A vulnerability, which was classified as problematic, has been found in SICK Field Analytics. Affected by this issue is some unknown functionality of the component iFrame Widget. The manipulation leads to improper restriction of rendered ui layers.
This vulnerability is handled as CVE-2025-49191. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-9512 | GitLab Enterprise Edition up to 17.10.7/17.11.3/18.0.1 toctou (Issue 497748 / EUVD-2024-54676)
3 months ago
A vulnerability classified as problematic was found in GitLab Enterprise Edition up to 17.10.7/17.11.3/18.0.1. Affected by this vulnerability is an unknown functionality. The manipulation leads to time-of-check time-of-use.
This vulnerability is known as CVE-2024-9512. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-49183 | SICK Media Server REST API cleartext transmission
3 months ago
A vulnerability classified as problematic has been found in SICK Media Server. Affected is an unknown function of the component REST API. The manipulation leads to cleartext transmission of sensitive information.
This vulnerability is traded as CVE-2025-49183. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
微软修补被阿联酋黑客利用的零日漏洞
3 months ago
安全客
CVE-2025-49181 | SICK SICK Media Server API Endpoint authorization
3 months ago
A vulnerability was found in SICK SICK Media Server. It has been rated as critical. This issue affects some unknown processing of the component API Endpoint. The manipulation leads to missing authorization.
The identification of this vulnerability is CVE-2025-49181. The attack may be initiated remotely. There is no exploit available.
vuldb.com
Multiple GitLab Vulnerabilities Allow Attackers to Achieve Complete Account Takeover
3 months ago
A series of critical security vulnerabilities across GitLab Community Edition (CE) and Enterprise Edition (EE) platforms that could enable attackers to achieve complete account takeover and compromise entire development infrastructures. The company released emergency patch versions 18.0.2, 17.11.4, and 17.10.8 to address ten distinct security flaws, with several carrying high-severity CVSS scores above 8.0. These […]
The post Multiple GitLab Vulnerabilities Allow Attackers to Achieve Complete Account Takeover appeared first on Cyber Security News.
Guru Baran
The $200,000 Zoom call
3 months ago
A crypto CEO shared his screen. What happened next unraveled his digital life.
西门子能源紧急警报:专用 5G 核心中的关键漏洞 (CVSS 9.9) 暴露了敏感数据!
3 months ago
安全客
CVE-2025-47279 | nodejs undici up to 5.28.x/6.21.1/7.4.x memory leak (ID 3895 / Nessus ID 238268)
3 months ago
A vulnerability was found in nodejs undici up to 5.28.x/6.21.1/7.4.x. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to memory leak.
The identification of this vulnerability is CVE-2025-47279. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-48387 | mafintosh tar-fs up to 1.16.4/2.1.2/3.0.8 path traversal (EUVD-2025-16687 / Nessus ID 238247)
3 months ago
A vulnerability, which was classified as critical, has been found in mafintosh tar-fs up to 1.16.4/2.1.2/3.0.8. This issue affects some unknown processing. The manipulation leads to path traversal.
The identification of this vulnerability is CVE-2025-48387. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-40914 | MIK CryptX up to 0.086 on Perl vulnerable third-party component (GHSA-j3xv-6967-cv88 / Nessus ID 238261)
3 months ago
A vulnerability classified as critical was found in MIK CryptX up to 0.086 on Perl. Affected by this vulnerability is an unknown functionality. The manipulation leads to dependency on vulnerable third-party component.
This vulnerability is known as CVE-2025-40914. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-46802 | GNU screen Multiuser Session Attach multiattach user session (Nessus ID 238263)
3 months ago
A vulnerability was found in GNU screen and classified as problematic. This issue affects the function Attach of the component Multiuser Session Handler. The manipulation of the argument multiattach leads to manage user sessions.
The identification of this vulnerability is CVE-2025-46802. The attack needs to be approached locally. There is no exploit available.
vuldb.com
CVE-2024-36967 | Linux Kernel up to 5.15.159/6.1.91/6.6.31/6.8.10/6.9.1 tpm2_key_encode memory leak (Nessus ID 238278)
3 months ago
A vulnerability has been found in Linux Kernel up to 5.15.159/6.1.91/6.6.31/6.8.10/6.9.1 and classified as critical. This vulnerability affects the function tpm2_key_encode. The manipulation leads to memory leak.
This vulnerability was named CVE-2024-36967. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-36975 | Linux Kernel up to 5.15.159/6.1.91/6.6.31/6.8.10/6.9.1 lib/asn1_encode.c asn1_encode_sequence return value (Nessus ID 238278)
3 months ago
A vulnerability was found in Linux Kernel up to 5.15.159/6.1.91/6.6.31/6.8.10/6.9.1. It has been classified as problematic. This affects the function asn1_encode_sequence in the library lib/asn1_encode.c. The manipulation leads to unchecked return value.
This vulnerability is uniquely identified as CVE-2024-36975. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-37978 | Linux Kernel up to 6.12.24/6.14.3/6.15-rc2 set_page_dirty_lock buffer overflow (Nessus ID 238279)
3 months ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.12.24/6.14.3/6.15-rc2. This issue affects the function set_page_dirty_lock. The manipulation leads to buffer overflow.
The identification of this vulnerability is CVE-2025-37978. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-27534 | Oracle Hyperion Infrastructure Technology 11.2.14.0.000 path traversal (Nessus ID 238296)
3 months ago
A vulnerability classified as critical was found in Oracle Hyperion Infrastructure Technology 11.2.14.0.000. Affected by this vulnerability is an unknown functionality of the component Infrastructure. The manipulation leads to path traversal.
This vulnerability is known as CVE-2023-27534. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-27534 | cURL up to 7.x SFTP /~2/foo path traversal (FEDORA-2023-7e7414e64d / Nessus ID 238296)
3 months ago
A vulnerability has been found in cURL up to 7.x and classified as critical. Affected by this vulnerability is an unknown functionality of the file /~2/foo of the component SFTP. The manipulation leads to path traversal.
This vulnerability is known as CVE-2023-27534. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com