Aggregator
RSAC 2025创新沙盒 | TwineSecurity :数字员工驱动企业安全建设
41国参加“锁盾2025”网络防御演习
CVE-2025-30328 | Adobe Animate up to 23.0.11/24.0.8 out-of-bounds write (apsb25-42 / Nessus ID 235862)
CVE-2025-43555 | Adobe Animate up to 23.0.11/24.0.8 integer underflow (apsb25-42 / Nessus ID 235862)
CVE-2025-43556 | Adobe Animate up to 23.0.11/24.0.8 integer overflow (apsb25-42 / Nessus ID 235862)
CVE-2025-43557 | Adobe Animate up to 23.0.11/24.0.8 uninitialized pointer (apsb25-42 / Nessus ID 235862)
CVE-2025-30329 | Adobe Animate up to 23.0.11/24.0.8 null pointer dereference (apsb25-42 / Nessus ID 235862)
CVE-2025-30325 | Adobe Photoshop Desktop up to 25.12.2/26.5 integer overflow (apsb25-40 / Nessus ID 235864)
CVE-2025-30314 | Adobe Connect up to 12.8 cross site scripting (apsb25-36 / Nessus ID 235875)
CVE-2025-30315 | Adobe Connect up to 12.8 cross site scripting (apsb25-36 / Nessus ID 235875)
CVE-2025-30316 | Adobe Connect up to 12.8 cross site scripting (apsb25-36 / Nessus ID 235875)
CVE-2025-43567 | Adobe Connect up to 12.8 cross site scripting (apsb25-36 / Nessus ID 235875)
82,000+ WordPress Sites Exposed to Remote Code Execution Attacks
Critical vulnerabilities were identified in TheGem, a premium WordPress theme with more than 82,000 installations worldwide. Researchers identified two separate but interconnected vulnerabilities in TheGem theme versions 5.10.3 and earlier. When combined, these vulnerabilities create a dangerous attack vector that could lead to remote code execution and complete site compromise. “The downloaded file is copied […]
The post 82,000+ WordPress Sites Exposed to Remote Code Execution Attacks appeared first on Cyber Security News.
CVE-2024-52290 | lf-edge ekuiper up to 2.0.x cross site scripting (EUVD-2024-54482)
CVE-2019-0227 | Oracle Internet Directory 12.2.1.3.0/12.2.1.4.0 Directory Services Mngr server-side request forgery (EDB-46682)
Услуги 18+, отмывание и прописка в США — как один Telegram-рынок объединил КНДР и китайскую мафию
New Microsoft Scripting Engine Vulnerability Exposes Systems to Remote Code Attacks
Critical zero-day vulnerability in Microsoft’s Scripting Engine (CVE-2025-30397) has been confirmed to enable remote code execution (RCE) attacks over networks, raising urgent concerns for enterprises and individual users alike. The flaw, classified as a type confusion weakness (CWE-843), allows attackers to bypass security mechanisms by manipulating how the engine processes data types in memory. Microsoft […]
The post New Microsoft Scripting Engine Vulnerability Exposes Systems to Remote Code Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Critical Microsoft Office Vulnerabilities Enable Malicious Code Execution
Microsoft has addressed three critical security flaws in its Office suite, including two vulnerabilities rated Critical and one Important, all enabling remote code execution (RCE) via use-after-free memory corruption weaknesses. These vulnerabilities, disclosed between March and May 2025, expose systems to attacks where malicious actors could execute arbitrary code by enticing users to open specially […]
The post Critical Microsoft Office Vulnerabilities Enable Malicious Code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
New Windows RDP Vulnerability Enables Network-Based Attacks
Microsoft has disclosed two critical vulnerabilities in its Windows Remote Desktop services that could allow attackers to execute arbitrary code on vulnerable systems over a network. Designated CVE-2025-29966 and CVE-2025-29967, these heap-based buffer overflow flaws affect the Windows Remote Desktop Protocol (RDP) and Remote Desktop Gateway (RD Gateway) service, respectively. Both vulnerabilities carry a CVSS […]
The post New Windows RDP Vulnerability Enables Network-Based Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.