Aggregator
CVE-2025-25151 | StylemixThemes uListing Plugin up to 2.1.6 on WordPress sql injection
CVE-2025-25116 | sudipto Link to URL Post Plugin up to 1.3 on WordPress sql injection
CVE-2025-25079 | Garrett Grimm Simple Select All Text Box Plugin up to 3.2 on WordPress cross site scripting
Microsoft Sysinternals 0-Day Vulnerability Enables DLL Injection Attacks on Windows
A critical zero-day vulnerability has been discovered in Microsoft Sysinternals tools, posing a serious security threat to IT administrators and developers worldwide. The vulnerability enables attackers to exploit DLL injection techniques to execute malicious code, putting systems at risk of compromise. Despite being disclosed to Microsoft over 90 days ago, the issue remains unresolved, leaving users reliant on manual […]
The post Microsoft Sysinternals 0-Day Vulnerability Enables DLL Injection Attacks on Windows appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-25073 | Vasilis Triantafyllou Easy WP Tiles Plugin up to 1 on WordPress cross site scripting
CVE-2025-25076 | nicholaswilson Graceful Email Obfuscation Plugin up to 0.2.2 on WordPress cross site scripting
CVE-2025-25141 | zankover Fami Sales Popup Plugin up to 2.0.0 on WordPress filename control
CVE-2025-25094 | Amitythemes Breaking News Ticker Plugin up to 2.4.4 on WordPress cross site scripting
CVE-2025-25078 | Andrew Norcross Google Earth Embed Plugin up to 1.0 on WordPress cross site scripting
CVE-2025-25120 | Melodic Media Slide Banners Plugin up to 1.3 on WordPress authorization
CVE-2025-25110 | Metagauss Event Kikfyre Plugin up to 2.1.8 on WordPress authorization
CVE-2009-0457 | Magtrb AJA Portal 1.2 case.php module_name path traversal (EDB-7939 / BID-33565)
DeepSeek应用未加密传输敏感用户和设备数据,引发安全担忧
Microsoft исправила по-настоящему серьёзную проблему Windows 11
CVE-2012-1507 | OrangeHRM up to 2.6.12.1 uri cross site scripting (EDB-37143 / XFDB-75473)
新产品
新产品
Attackers compromise IIS servers by leveraging exposed ASP.NET machine keys
A ViewState code injection attack spotted by Microsoft threat researchers in December 2024 could be easily replicated by other attackers, the company warned. “In the course of investigating, remediating, and building protections against this activity, we observed an insecure practice whereby developers have incorporated various publicly disclosed ASP.NET machine keys from publicly accessible resources, such as code documentation and repositories, which threat actors have used to perform malicious actions on target servers.” The attack ASP.NET … More →
The post Attackers compromise IIS servers by leveraging exposed ASP.NET machine keys appeared first on Help Net Security.