Aggregator
CVE-2025-30187 | PowerDNS DNSdist up to 1.9.10/2.0.0 nghttp2 infinite loop (Nessus ID 265571 / WID-SEC-2025-2112)
Salesforce CLI Installer Vulnerability Let Attackers Execute Code and Gain SYSTEM-Level Access
A critical vulnerability in the Salesforce CLI installer (sf-x64.exe) enables attackers to achieve arbitrary code execution, privilege escalation, and SYSTEM-level access on Windows systems. Tracked as CVE-2025-9844, the flaw stems from improper handling of executable file paths by the installer, allowing malicious files to be executed in place of legitimate binaries when the software is […]
The post Salesforce CLI Installer Vulnerability Let Attackers Execute Code and Gain SYSTEM-Level Access appeared first on Cyber Security News.
CISA Reveals Hackers Breached U.S. Federal Agency via GeoServer RCE Flaw
Federal cybersecurity agency CISA has disclosed that attackers exploited a remote code execution vulnerability in GeoServer to breach a U.S. federal civilian executive branch agency. The incident response began after endpoint detection alerts sounded at the agency. Over three weeks, cyber intruders used the flaw to gain initial access, move laterally, and establish persistence across […]
The post CISA Reveals Hackers Breached U.S. Federal Agency via GeoServer RCE Flaw appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2001-1534 | Apache HTTP Server up to 1.3.20 mod_usertrack improper authentication (ID 86274 / XFDB-7494)
CVE-2001-1528 | Amtote International Homebet Authentication User information disclosure (EDB-21116 / ID 23015)
CVE-2001-1537 | Twig Webmail 2.7.4 Cookie config.php Password missing encryption (ID 10439 / XFDB-7619)
超越 AGI,阿里剑指「超级智能」
活动|秋日“挖洞”季,邀您来测!
«Польша не боится кибератак» — министр цифровизации невозмутим, пока аэропорты соседей парализованы
超微公司两个新漏洞可导致恶意固件逃避信任根安全机制
SolarWinds 第三次修复 Web Help Desk RCE漏洞
超微公司两个新漏洞可导致恶意固件逃避信任根安全机制
SolarWinds 第三次修复 Web Help Desk RCE漏洞
Reliable, Compliant APIs with Akamai Managed Service for API Performance
CVE-2025-10909 | Mangati NovoSGA up to 2.2.9 SVG File /admin logoNavbar/logoLogin cross site scripting
Critical DNN Platform Vulnerability Let Attackers Execute Malicious Scripts
A severe Stored Cross-Site Scripting (XSS) vulnerability in the Prompt module of the DNN Platform enables low-privilege attackers to inject and execute arbitrary scripts in the context of privileged users. Published as GHSA-2qxc-mf4x-wr29 by Daniel Valadas yesterday, this vulnerability affects all versions of the DotNetNuke.Core package prior to 10.1.0 and carries a CVSS v3.1 base […]
The post Critical DNN Platform Vulnerability Let Attackers Execute Malicious Scripts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.