Aggregator
SonicWall security advisory (AV25-007) - Update 1
1 year 4 months ago
Canadian Centre for Cyber Security
Эмодзи вместо ножа: как соцсети научили нас искусству пассивной агрессии
1 year 4 months ago
Градус токсичности в интернете медленно, но верно повышается.
CVE-2023-0272 | NEX-Forms Plugin up to 8.3.2 on WordPress Shortcode Attribute cross site scripting
1 year 4 months ago
A vulnerability was found in NEX-Forms Plugin up to 8.3.2 on WordPress and classified as problematic. Affected by this issue is some unknown functionality of the component Shortcode Attribute Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2023-0272. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-28597 | Zoom Client up to 5.13.4 SMB trust boundary violation
1 year 4 months ago
A vulnerability was found in Zoom Client up to 5.13.4. It has been classified as problematic. Affected is an unknown function of the component SMB Handler. The manipulation leads to trust boundary violation.
This vulnerability is traded as CVE-2023-28597. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-42447 | HCL Compass cross-domain policy (KB0103581)
1 year 4 months ago
A vulnerability was found in HCL Compass. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to permissive cross-domain policy with untrusted domains.
This vulnerability is known as CVE-2022-42447. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-3565 | Content Blocks Plugin up to 3.3.0 on WordPress Shortcode content_block cross site scripting
1 year 4 months ago
A vulnerability classified as problematic has been found in Content Blocks Plugin up to 3.3.0 on WordPress. Affected is the function content_block of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-3565. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-21685 | Atlassian Jira Core Data Center up to 9.4.20/9.4.22/9.12.7/9.12.9/9.16.0 information disclosure
1 year 4 months ago
A vulnerability was found in Atlassian Jira Core Data Center up to 9.4.20/9.4.22/9.12.7/9.12.9/9.16.0. It has been classified as problematic. This affects an unknown part. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-21685. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43128 | WC Product Table WooCommerce Product Table Lite Plugin up to 3.5.1 on WordPress code injection
1 year 4 months ago
A vulnerability was found in WC Product Table WooCommerce Product Table Lite Plugin up to 3.5.1 on WordPress. It has been classified as critical. This affects an unknown part. The manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2024-43128. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
Patch Now: CISA Warns of Palo Alto Flaw Exploited in the Wild
1 year 4 months ago
The authentication bypass vulnerability in the OS for the company's firewall devices is under increasing attack and being chained with other bugs, making it imperative for organizations to mitigate the issue ASAP.
Elizabeth Montalbano, Contributing Writer
A Threat Actor Claims to have Leaked the Data of Ferum Shop
1 year 4 months ago
A Threat Actor Claims to have Leaked the Data of Ferum Shop
Dark Web Informer - Cyber Threat Intelligence
Finastra Notifies Customers of Data Breach
1 year 4 months ago
Finastra notifies customers of data breach that took place more than three months ago, impacting sensitive financial information
A Threat Actor Claims to have Leaked The Unified State Register of Real Estate of the Russian Federation
1 year 4 months ago
A Threat Actor Claims to have Leaked The Unified State Register of Real Estate of the Russian Federation
Dark Web Informer - Cyber Threat Intelligence
9 - CVE-2025-26617
1 year 4 months ago
Currently trending CVE - hypeScore: 3 - WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `historico_paciente.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL queries, a
10 - CVE-2025-1094
1 year 4 months ago
Currently trending CVE - hypeScore: 1 - Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires t
2025-02-18: SmartApeSG script for fake browser update leads to NetSupport RAT and StealC
1 year 4 months ago
T00ls第十二届年度(2024)人物风云榜
1 year 4 months ago
T00ls第十二届年度(2024)人物风云榜
1 year 4 months ago
T00ls第十二届年度(2024)人物风云榜
1 year 4 months ago
T00ls第十二届年度(2024)人物风云榜
1 year 4 months ago