Aggregator
384 ядра против Intel и AMD: Китайский KH-5000 бросает вызов мировым серверным чипам
8 months 3 weeks ago
KH-5000 превращает сервер в монстра вычислений с новым интерфейсом ZPI 5.0.
CVE-2025-8279 | GitLab Language Server up to 7.29.x GraphQL Query missing authentication (Issue 538205)
8 months 3 weeks ago
A vulnerability was found in GitLab Language Server up to 7.29.x. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component GraphQL Query Handler. The manipulation leads to missing authentication.
This vulnerability is known as CVE-2025-8279. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-53695 | Johnson Controls iSTAR Ultra up to 6.9.2 Web Application os command injection
8 months 3 weeks ago
A vulnerability was found in Johnson Controls iSTAR Ultra up to 6.9.2. It has been classified as critical. Affected is an unknown function of the component Web Application. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2025-53695. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-30133 | IROAD FX2 IROAD X View Registration default password
8 months 3 weeks ago
A vulnerability was found in IROAD FX2 and classified as critical. This issue affects some unknown processing of the component IROAD X View Registration. The manipulation leads to use of default password.
The identification of this vulnerability is CVE-2025-30133. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2025-30124 | Marbella KR8s Dashcam FF 2.0.8 SD Card missing encryption
8 months 3 weeks ago
A vulnerability has been found in Marbella KR8s Dashcam FF 2.0.8 and classified as problematic. This vulnerability affects unknown code of the component SD Card Handler. The manipulation leads to missing encryption of sensitive data.
This vulnerability was named CVE-2025-30124. It is possible to launch the attack on the physical device. There is no exploit available.
vuldb.com
CVE-2025-30126 | Marbella KR8s Dashcam FF 2.0.8 Service Port 7777 improper authorization
8 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Marbella KR8s Dashcam FF 2.0.8. This affects an unknown part of the component Service Port 7777. The manipulation leads to improper authorization.
This vulnerability is uniquely identified as CVE-2025-30126. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2025-26469 | MedDream PACS Premium 7.3.3.840 SetRegistryValues permission assignment (TALOS-2025-2154)
8 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in MedDream PACS Premium 7.3.3.840. Affected by this issue is the function CServerSettings::SetRegistryValues. The manipulation leads to incorrect permission assignment.
This vulnerability is handled as CVE-2025-26469. Attacking locally is a requirement. There is no exploit available.
vuldb.com
CVE-2025-24485 | MedDream PACS Premium 7.3.5.860 HTTP Request cecho.php server-side request forgery (TALOS-2025-2177)
8 months 3 weeks ago
A vulnerability classified as critical was found in MedDream PACS Premium 7.3.5.860. Affected by this vulnerability is an unknown functionality of the file cecho.php of the component HTTP Request Handler. The manipulation leads to server-side request forgery.
This vulnerability is known as CVE-2025-24485. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-27724 | MedDream PACS Premium 7.3.3.840 login.php access control (TALOS-2025-2156)
8 months 3 weeks ago
A vulnerability classified as critical has been found in MedDream PACS Premium 7.3.3.840. Affected is an unknown function of the file login.php. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2025-27724. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
Stay Ahead of Ransomware: How Threat Actor Profiling Can Help Prevent Ransomware Attacks
8 months 3 weeks ago
SANS Digital Forensics and Incident Response
FBI alerts tie together threats of cybercrime, physical violence from The Com
8 months 3 weeks ago
Officials said thousands of people, typically between 11 and 25 years old, are engaged in a growing and evolving online threat to commit crime for money, retaliation, ideology, sexual gratification and notoriety.
The post FBI alerts tie together threats of cybercrime, physical violence from The Com appeared first on CyberScoop.
Matt Kapko
CVE-2025-32731 | MedDream PACS Premium 7.3.5.860 radiationDoseReport.php cross site scripting (TALOS-2025-2176)
8 months 3 weeks ago
A vulnerability was found in MedDream PACS Premium 7.3.5.860. It has been rated as problematic. This issue affects some unknown processing of the file radiationDoseReport.php. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-32731. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2010-2920 | Foobla Com Foobla Suggestions 1.5.1.2 index.php controller path traversal (EDB-12120 / XFDB-57660)
8 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Foobla Com Foobla Suggestions 1.5.1.2. This affects an unknown part of the file index.php. The manipulation of the argument controller leads to path traversal.
This vulnerability is uniquely identified as CVE-2010-2920. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2010-1302 | DecryptWeb Com Dwgraphs 1.0 dwgraphs.php controller path traversal (EDB-11978 / BID-39108)
8 months 3 weeks ago
A vulnerability classified as problematic has been found in DecryptWeb Com Dwgraphs 1.0. Affected is an unknown function of the file dwgraphs.php. The manipulation of the argument controller leads to path traversal.
This vulnerability is traded as CVE-2010-1302. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2010-1981 | Fabrikar Com Fabrikar 2.0 index.php controller path traversal (EDB-12087 / Nessus ID 43636)
8 months 3 weeks ago
A vulnerability was found in Fabrikar Com Fabrikar 2.0 and classified as problematic. This issue affects some unknown processing of the file index.php. The manipulation of the argument controller leads to path traversal.
The identification of this vulnerability is CVE-2010-1981. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2010-2045 | Dionesoft Com Dioneformwizard 1.0.2 index.php controller path traversal (EDB-12595 / XFDB-58574)
8 months 3 weeks ago
A vulnerability was found in Dionesoft Com Dioneformwizard 1.0.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument controller leads to path traversal.
This vulnerability is known as CVE-2010-2045. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2010-5042 | Blueconstantmedia Com Djartgallery 0.9.1 administrator/index.php cid[] cross site scripting (EDB-13737 / XFDB-59143)
8 months 3 weeks ago
A vulnerability classified as problematic has been found in Blueconstantmedia Com Djartgallery 0.9.1. This affects an unknown part of the file administrator/index.php. The manipulation of the argument cid[] leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2010-5042. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2010-4993 | Kay Messerschmidt Com Eventcal 1.6.4 index.php Itemid sql injection (EDB-14187 / XFDB-60060)
8 months 3 weeks ago
A vulnerability was found in Kay Messerschmidt Com Eventcal 1.6.4 and classified as critical. This issue affects some unknown processing of the file index.php. The manipulation of the argument Itemid leads to sql injection.
The identification of this vulnerability is CVE-2010-4993. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2010-1265 | Ekith Com Dcs Flashgames 2.0 index.php catid sql injection (EDB-11884 / BID-38981)
8 months 3 weeks ago
A vulnerability classified as critical was found in Ekith Com Dcs Flashgames 2.0. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument catid leads to sql injection.
This vulnerability is known as CVE-2010-1265. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com