Aggregator
CVE-2024-36486 | Parallels Desktop 20.1.1 on macOS Virtual Machine Archive Restoration prl_vmarchiver unix hard link (TALOS-2024-2126 / EUVD-2024-54643)
CVE-2024-52561 | Parallels Desktop 20.1.1 on macOS Snapshot incorrect ownership assignment (TALOS-2024-2123 / EUVD-2024-54641)
CVE-2025-23105 | Samsung 1480/2200/2400 use after free (EUVD-2025-16678)
CVE-2025-23099 | Samsung Exynos 1480/2400 out-of-bounds write (EUVD-2025-16677)
New Safari XSS Flaw Leverages JavaScript Error Handling to Execute Arbitrary Code
A new cross-site scripting (XSS) vulnerability in Safari that exploits the browser’s TypeError exception handling mechanism to execute arbitrary JavaScript code. The flaw, discovered during Gareth Heyes research into payload concealment techniques, demonstrates how Safari’s improper handling of quote escaping in TypeError messages can be weaponized for malicious code execution. This vulnerability represents a significant […]
The post New Safari XSS Flaw Leverages JavaScript Error Handling to Execute Arbitrary Code appeared first on Cyber Security News.
CVE-2024-54189 | Parallels Desktop 20.1.1 on macOS Snapshot unix hard link (TALOS-2024-2124 / EUVD-2024-54642)
CVE-2025-31359 | Parallels Desktop 20.2.2 (55879) on macOS PVMP Package Unpacking path traversal (TALOS-2025-2160 / EUVD-2025-16718)
CVE-2025-4671 | Profile Builder Plugin up to 3.13.8 on WordPress Shortcode user_meta/compare cross site scripting (EUVD-2025-16720)
CVE-2025-5340 | Music Player for Elementor Plugin up to 2.4.6 on WordPress album_buy_url cross site scripting (EUVD-2025-16721)
CVE-2025-4205 | Popup Maker Plugin up to 1.20.4 on WordPress popupID cross site scripting (EUVD-2025-16719)
Europol Targets Over 2,000 Extremist Links Exploiting Minors Online
捷克技术大学 | 加密流量分类:QUIC协议场景下的分析
Splunk Universal Forwarder on Windows Lets Non-Admin Users Access All Contents
A high-severity vulnerability was uncovered in Splunk Universal Forwarder for Windows that compromises directory access controls. The flaw, designated CVE-2025-20298 with a CVSSv3.1 score of 8.0, affects multiple versions of the software and poses significant security risks to enterprise environments relying on Splunk’s data forwarding capabilities. The vulnerability stems from incorrect permission assignment during the […]
The post Splunk Universal Forwarder on Windows Lets Non-Admin Users Access All Contents appeared first on Cyber Security News.