Aggregator
ZDI-CAN-26051: Ashlar-Vellum
JVN: 複数のAutomationDirect製C-more EA9 HMIにおける古典的バッファーオーバーフローの脆弱性
我国牵头提出的国际标准《信息技术 信息安全事件管理 第4部分:协同》正式发布
Zyxel发现不良签名更新导致防火墙关键错误
CVE-2024-53965 | Adobe Experience Manager up to 6.5.21 URL cross site scripting (apsb24-69)
CISA Adds Apache, Microsoft Vulnerabilities to Its Database that Are Actively Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) Catalog, adding several newly identified vulnerabilities to its authoritative list of security flaws exploited in the wild. This catalog Developed to assist cybersecurity professionals in prioritizing vulnerability management, the KEV catalog serves as a critical resource for organizations aiming to […]
The post CISA Adds Apache, Microsoft Vulnerabilities to Its Database that Are Actively Exploited in the Wild appeared first on Cyber Security News.
CVE-2025-1026 | Spatie browsershot up to 5.0.4 URL Validation setUrl file inclusion (SNYK-PHP-SPATIEBROWSERSHOT-8533024)
CVE-2025-1028 | kleor Contact Manager Plugin up to 8.6.4 on WordPress unrestricted upload
CVE-2025-1025 | Cockpit up to 2.4.0 unrestricted upload (SNYK-PHP-COCKPITHQCOCKPIT-8516320)
CVE-2024-48445 | compop Online Mall 3.5.3 rid/tid/et/ts Privilege Escalation
CVE-2025-25246 | NETGEAR XR1000/XR1000v2/XR500 code injection (PSV-2023-0039)
CVE-2024-13722 | Checkmk NagVis up to 1.9.41/2.3.0p9 cross site scripting
Veeam Backup Vulnerability Allows Attackers to Execute Arbitrary Code
A critical vulnerability, CVE-2025-23114, has been discovered within the Veeam Updater component that poses a serious risk to organizations utilizing Veeam’s backup solutions. The flaw allows attackers to leverage a Man-in-the-Middle (MitM) attack to inject and execute arbitrary code with root-level permissions on the affected appliance server. The vulnerability, reported through HackerOne by security researcher […]
The post Veeam Backup Vulnerability Allows Attackers to Execute Arbitrary Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.