Aggregator
CVE-2022-3069 | WordLift Plugin up to 3.37.1 on WordPress Setting cross site scripting
CVE-2022-3070 | Generate PDF Plugin up to 3.5 on WordPress Setting cross site scripting
CVE-2022-3074 | Slider Hero Plugin up to 8.4.3 on WordPress Slider Name cross site scripting
CVE-2022-40785 | mIPC 5.3.1.2003161406 os command injection
CVE-2022-2857 | Google Chrome up to 104.0.5112.101 Blink use after free (Nessus ID 211177)
CVE-2022-2854 | Google Chrome up to 104.0.5112.101 SwiftShader use after free (Nessus ID 211177)
CVE-2022-2855 | Google Chrome up to 104.0.5112.101 ANGLE use after free (Nessus ID 211177)
CVE-2022-3044 | Google Chrome up to 104.0.5112.102 Site Isolation authorization (FEDORA-2022-3f28aa88cf / Nessus ID 211177)
CVE-2022-3045 | Google Chrome up to 104.0.5112.102 V8 out-of-bounds write (FEDORA-2022-3f28aa88cf / Nessus ID 211177)
CVE-2022-3046 | Google Chrome up to 104.0.5112.102 Browser Tag use after free (FEDORA-2022-3f28aa88cf / Nessus ID 211177)
HPE security advisory (AV25-289)
Ivanti EPMM flaw exploited by Chinese hackers to breach govt agencies
CVE-2005-4671 | CityPost Simple PHP Upload 5.3 simple-upload-53.php Message cross site scripting (EDB-25464 / XFDB-20164)
New Signal update stops Windows from capturing user chats
Multiple GitLab Vulnerabilities Let Attackers Trigger DoS Attacks
GitLab has released critical security patches addressing 11 vulnerabilities across its Community Edition (CE) and Enterprise Edition (EE) platforms, with several high-risk flaws enabling denial-of-service (DoS) attacks. The coordinated release of versions 18.0.1, 17.11.3, and 17.10.7 comes as the DevOps platform confronts multiple attack vectors that could destabilize systems through resource exhaustion, authentication bypasses, and […]
The post Multiple GitLab Vulnerabilities Let Attackers Trigger DoS Attacks appeared first on Cyber Security News.
CVE-2006-0663 | IBM Lotus Domino iNotes Client 6.5.4 Domino Web Access cross site scripting (EDB-27181 / XFDB-24614)
Coinbase Breach Affected Almost 70,000 Customers
Versa Concerto 0-Day Authentication Bypass Vulnerability Allows Remote Code Execution
Significant vulnerabilities were uncovered in Versa Concerto, a widely deployed SD-WAN orchestration platform used by major enterprises and government entities. The flaws include authentication bypass vulnerabilities that can be chained to achieve remote code execution and complete system compromise. Despite responsible disclosure efforts beginning in February 2025, these critical issues remain unpatched, leaving organizations vulnerable […]
The post Versa Concerto 0-Day Authentication Bypass Vulnerability Allows Remote Code Execution appeared first on Cyber Security News.