Aggregator
Alleged data leak of Pengadilan Negeri Pekanbaru
10 months 2 weeks ago
Alleged data leak of Pengadilan Negeri Pekanbaru
Dark Web Informer - Cyber Threat Intelligence
Xenserver虚拟机工具for Windows漏洞让攻击者执行任意代码
10 months 2 weeks ago
安全客
PumaBot恶意软件瞄准Linux物联网设备
10 months 2 weeks ago
安全客
CVE-2025-31642 | WPCHURCH Plugin up to 2.7.0 on WordPress cross site scripting
10 months 2 weeks ago
A vulnerability classified as problematic was found in WPCHURCH Plugin up to 2.7.0 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-31642. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-32300 | DZS Video Gallery Plugin up to 12.25 on WordPress cross site scripting
10 months 2 weeks ago
A vulnerability classified as problematic has been found in DZS Video Gallery Plugin up to 12.25 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-32300. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-48143 | Formulario de Contacto SalesUp Plugin up to 1.0.14 on WordPress cross site scripting
10 months 2 weeks ago
A vulnerability was found in Formulario de Contacto SalesUp Plugin up to 1.0.14 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-48143. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-47553 | DZS Video Gallery Plugin up to 12.25 on WordPress deserialization
10 months 2 weeks ago
A vulnerability was found in DZS Video Gallery Plugin up to 12.25 on WordPress. It has been classified as critical. Affected is an unknown function. The manipulation leads to deserialization.
This vulnerability is traded as CVE-2025-47553. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-47552 | DZS Video Gallery Plugin up to 12.25 on WordPress deserialization
10 months 2 weeks ago
A vulnerability was found in DZS Video Gallery Plugin up to 12.25 on WordPress. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to deserialization.
This vulnerability is known as CVE-2025-47552. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-48748 | Netwrix Directory Manager up to 10.0.7784.0 hard-coded password (adv-2025-013)
10 months 2 weeks ago
A vulnerability was found in Netwrix Directory Manager up to 10.0.7784.0 and classified as problematic. This issue affects some unknown processing. The manipulation leads to use of hard-coded password.
The identification of this vulnerability is CVE-2025-48748. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
ConnectWise Confirms Hack, “Very Small Number” of Customers Affected
10 months 2 weeks ago
The firm’s remote monitoring management tool, ScreenConnect, has reportedly been patched
CVE-2025-46078 | HuoCMS up to 3.5.1 unrestricted upload
10 months 2 weeks ago
A vulnerability has been found in HuoCMS up to 3.5.1 and classified as critical. This vulnerability affects unknown code. The manipulation leads to unrestricted upload.
This vulnerability was named CVE-2025-46078. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-22654 | tcpreplay 4.4.4 get.c tcprewrite infinite loop
10 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in tcpreplay 4.4.4. This affects the function tcprewrite of the file get.c. The manipulation leads to infinite loop.
This vulnerability is uniquely identified as CVE-2024-22654. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-22653 | yasm 9defefae section.c yasm_section_bcs_append null pointer dereference
10 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in yasm 9defefae. Affected by this issue is the function yasm_section_bcs_append of the file section.c. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2024-22653. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2025-46080 | HuoCMS 3.5.1 unrestricted upload
10 months 2 weeks ago
A vulnerability classified as critical was found in HuoCMS 3.5.1. Affected by this vulnerability is an unknown functionality. The manipulation leads to unrestricted upload.
This vulnerability is known as CVE-2025-46080. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-33043 | AMI AptioV up to 5.011 input validation
10 months 2 weeks ago
A vulnerability classified as problematic has been found in AMI AptioV up to 5.011. Affected is an unknown function. The manipulation leads to improper input validation.
This vulnerability is traded as CVE-2025-33043. Attacking locally is a requirement. There is no exploit available.
vuldb.com
CVE-2025-5334 | Devolutions Remote Desktop Manager up to 2025.1.34.0 exposure of private personal information to an unauthorized actor (DEVO-2025-0009)
10 months 2 weeks ago
A vulnerability was found in Devolutions Remote Desktop Manager up to 2025.1.34.0. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to exposure of private personal information to an unauthorized actor.
The identification of this vulnerability is CVE-2025-5334. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-5124
10 months 2 weeks ago
Currently trending CVE - Hype Score: 1 - A vulnerability classified as critical has been found in Sony SNC-M1, SNC-M3, SNC-RZ25N, SNC-RZ30N, SNC-DS10, SNC-CS3N and SNC-RX570N up to 1.30. This affects an unknown part of the component Administrative Interface. The manipulation leads to use of default credentials. It is ...
CVE-2025-48047 | MICI Network NetFax Server prior 3.0.1.0 Ping /test.php os command injection
10 months 2 weeks ago
A vulnerability was found in MICI Network NetFax Server. It has been declared as critical. This vulnerability affects unknown code of the file /test.php of the component Ping Handler. The manipulation leads to os command injection.
This vulnerability was named CVE-2025-48047. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-48046 | MICI Network NetFax Server prior 3.0.1.0 HTTP GET Request /config.php password in configuration file
10 months 2 weeks ago
A vulnerability was found in MICI Network NetFax Server. It has been classified as problematic. This affects an unknown part of the file /config.php of the component HTTP GET Request Handler. The manipulation leads to password in configuration file.
This vulnerability is uniquely identified as CVE-2025-48046. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com