Aggregator
CVE-2024-51961 | ESRI ArcGIS Server 10.9.1/11.1/11.2/11.3 Configuration file inclusion
CVE-2024-47260 | AXIS OS VAPIX API mediaclip.cgi improper restriction of names for files and other resources
CVE-2025-1889 | mmaitre314 picklescan up to 0.0.21 File Extension reliance on untrusted inputs in a security decision (GHSA-655q-fx9r-782v)
CVE-2024-47259 | AXIS OS VAPIX API dynamicoverlay.cgi unrestricted upload
CVE-2025-0360 | AXIS OS VAPIX Device Configuration Framework authorization
CVE-2025-0359 | AXIS OS ACAP Application Framework authorization
CVE-2024-47262 | AXIS OS VAPIX API param.cgi improper validation of specified type of input
CVE-2024-51966 | ESRI ArcGIS Server 10.9.1/11.1/11.2/11.3 path traversal
CVE-2024-51958 | ESRI ArcGIS Server 10.9.1/11.1/11.2/11.3 path traversal
CVE-2024-51954 | ESRI ArcGIS Server 10.9.1/11.1/11.2/11.3 on Windows access control
CVE-2024-51962 | ESRI ArcGIS Server 10.9.1/11.1/11.2/11.3 Edit Operation sql injection
CVE-2025-27499 | LabRedesCefetRJ WeGIA up to 3.2.9 processa_edicao_socio.php socio_nome cross site scripting (GHSA-v248-mr5r-87pf)
CVE-2025-27221 | URI Gem up to 0.11.2/0.12.3/0.13.1/1.0.2 on Ruby URI.join/URI#merge/URI#+ improper removal of sensitive information before storage or transfer
CVE-2025-1306 | spicethemes Newscrunch Plugin up to 1.8.4 on WordPress newscrunch_install_and_activate_plugin cross-site request forgery
CVE-2025-27219 | CGI Gem up to 0.3.6/0.4.1 on Ruby Cookie CGI::Cookie.parse allocation of resources
CVE-2025-1307 | spicethemes Newscrunch Plugin up to 1.8.4 on WordPress newscrunch_install_and_activate_plugin authorization
Progress WhatsUp Gold Path Traversal Vulnerability Exposes Systems to Remote code Execution
A newly disclosed path traversal vulnerability (CVE-2024-4885) in Progress Software’s WhatsUp Gold network monitoring solution has raised alarms across the cybersecurity community. Rated as critical, this flaw enables unauthenticated attackers to execute arbitrary code on affected systems by exploiting improper input validation in file path handling mechanisms. The vulnerability, classified under CWE-22 (Improper Limitation of […]
The post Progress WhatsUp Gold Path Traversal Vulnerability Exposes Systems to Remote code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Why a push for encryption backdoors is a global security risk
Governments in the UK, US, and Europe are pressuring tech companies to weaken encryption in the name of security. The latest push from the UK government demanding Apple create a backdoor to encrypted iCloud data is just one example, one that should alarm privacy advocates, businesses, and governments. In this Help Net Security video, professor Nigel Smart, Chief Academic Officer at Zama and a leading expert in cryptography, warns that these measures don’t just threaten … More →
The post Why a push for encryption backdoors is a global security risk appeared first on Help Net Security.