Aggregator
CVE-2025-54260 | Adobe Substance3D Modeler up to 1.22.2 File Parser out-of-bounds (apsb25-92)
CVE-2025-59036 | opsmill infrahub up to 1.3.8/1.4.4 improper validation of certificate expiration (GHSA-v2p7-4pv4-3wwh)
美国指控勒索软件 LockerGoga、MegaCortex 和 Nefilim 的管理员
美国指控勒索软件 LockerGoga、MegaCortex 和 Nefilim 的管理员
CVE-2025-59039 | prebid-universal-creative 1.17.3 JavaScript API Prebid.js malicious code (GHSA-m662-56rj-8fmm)
CVE-2025-9997 | Schneider Electric Saitel DR RTU/Saitel DP RTU os command injection (SEVD-2025-252-02)
CVE-2025-54259 | Adobe Substance3D Modeler up to 1.22.2 File integer overflow (apsb25-92)
CVE-2025-54258 | Adobe Substance3D Modeler up to 1.22.2 File use after free (apsb25-92)
CVE-2025-59046 | ninofiliu interactive-git-checkout up to 1.1.4 command injection (GHSA-4wcm-7hjf-6xw5)
Windows BitLocker Vulnerability Let Attackers Elevate Privileges
Microsoft has addressed two significant elevation of privilege vulnerabilities affecting its Windows BitLocker encryption feature. The flaws, tracked as CVE-2025-54911 and CVE-2025-54912, were disclosed on September 9, 2025, and carry an “Important” severity rating. Both vulnerabilities could allow an authorized attacker to gain full SYSTEM privileges on a compromised machine, bypassing the security layers that […]
The post Windows BitLocker Vulnerability Let Attackers Elevate Privileges appeared first on Cyber Security News.
CVE-2025-59038 | Prebid.js 10.9.2 malicious code (GHSA-jwq7-6j4r-2f92 / BID-10)
CVE-2025-58750 | rAthena chclif_parse_moveCharSlot memory corruption (GHSA-pjh7-jgr8-4ff6)
CVE-2025-58448 | rAthena PartyBooking WorldName sql injection (GHSA-x99j-36m7-4vv7)
微软强制执行重返办公室政策
微软强制执行重返办公室政策
CVE-2025-58447 | rAthena CA_SSO_LOGIN_REQ heap-based overflow (GHSA-4p33-6xqr-cm6x)
CVE-2025-59042 | PyInstaller up to 5.x code injection (GHSA-p2xp-xx3r-mffc)
Critical SAP NetWeaver Vulnerability Let Attackers Execute Arbitrary Code And Compromise System
A critical vulnerability CVE-2025-42922 has been discovered in SAP NetWeaver that allows an authenticated, low-privileged attacker to execute arbitrary code and achieve a full system compromise. The flaw resides in the Deploy Web Service upload mechanism, where insufficient access control validation permits the upload and execution of malicious files. This vulnerability poses a significant risk […]
The post Critical SAP NetWeaver Vulnerability Let Attackers Execute Arbitrary Code And Compromise System appeared first on Cyber Security News.