Aggregator
Space Bears
10 months 3 weeks ago
cohenido
INC
10 months 3 weeks ago
cohenido
CVE-2017-7643 | Proxifier for Mac up to 2.18 KLoader Parameter access control (EDB-41854)
10 months 3 weeks ago
A vulnerability classified as problematic was found in Proxifier for Mac up to 2.18. Affected by this vulnerability is an unknown functionality of the component KLoader. The manipulation as part of Parameter leads to improper access controls.
This vulnerability is known as CVE-2017-7643. The attack needs to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Не Manifestом единым: раскрыта крупная сеть шпионов в Google Chrome
10 months 3 weeks ago
Что не сделал Google в Manifest V3, чтобы Chrome стал пристанищем вредоносов?
恶意扩展伪装Zoom应用窃取VS Code用户数据
10 months 3 weeks ago
Cybersecurity researchers have uncovered a new threat targeting developer
EnGenius Cloud Managed ESG320 VPN Router improves security and network performance
10 months 3 weeks ago
EnGenius released EnGenius Cloud Managed ESG320 VPN Router. Designed to meet the growing demands of small businesses, the ESG320 delivers enterprise-grade performance, security, and simplified cloud-based management, making it the ideal choice for companies looking to optimize their network infrastructure, ensure data protection, and increase operational efficiency. Comprehensive security with a stateful firewall Businesses face the challenge of securing their networks from external threats while maintaining smooth operations. The ESG320 Cloud Managed VPN Router addresses this … More →
The post EnGenius Cloud Managed ESG320 VPN Router improves security and network performance appeared first on Help Net Security.
Industry News
深入《无边记》:一种革命性的知识管理体系
10 months 3 weeks ago
传统的知识管理体系实在是太无聊了。无论基于传统笔记的《Evernote》类,还是基于区块的《Notion》类,抑或基于 To-do 的《Todoist》类工具,它们都要涉及很复杂的素材分类和整理环
CVE-2007-5265 | Dawnoftime Dawn of Time up to 1.69s_beta4 websrv.cpp format string (EDB-30644 / XFDB-36973)
10 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Dawnoftime Dawn of Time up to 1.69s_beta4. Affected is an unknown function of the file websrv.cpp. The manipulation leads to format string.
This vulnerability is traded as CVE-2007-5265. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Murdoc Botnet: как базовые команды Linux стали оружием злоумышленников
10 months 3 weeks ago
Уязвимости в IoT-устройствах становятся плацдармом для новых киберугроз.
PlushDaemon APT Targets South Korean VPN Provider in Supply Chain Attack
10 months 3 weeks ago
A previously undocumented China-aligned advanced persistent threat (APT) group named PlushDaemon has been linked to a supply chain attack targeting a South Korean virtual private network (VPN) provider in 2023, according to new findings from ESET.
"The attackers replaced the legitimate installer with one that also deployed the group's signature implant that we have named SlowStepper – a
The Hacker News
PlushDaemon APT Targets South Korean VPN Provider in Supply Chain Attack
10 months 3 weeks ago
A previously undocumented China-aligned advanced persistent threat (APT) group named PlushDaemon ha
Frame & Optic - 15,678 breached accounts
10 months 3 weeks ago
Here's an overview of the various breaches that have been consolidated into this Have I Been
CVE-2025-0428 | AI Power Plugin up to 1.8.96 on WordPress wpaicg_export_prompts code injection
10 months 3 weeks ago
A vulnerability was found in AI Power Plugin up to 1.8.96 on WordPress. It has been classified as critical. This affects the function wpaicg_export_prompts. The manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2025-0428. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-13360 | AI Power Plugin up to 1.8.96 on WordPress server-side request forgery
10 months 3 weeks ago
A vulnerability was found in AI Power Plugin up to 1.8.96 on WordPress. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to server-side request forgery.
The identification of this vulnerability is CVE-2024-13360. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-13361 | AI Power Plugin up to 1.8.96 on WordPress Shortcode authorization
10 months 3 weeks ago
A vulnerability classified as critical was found in AI Power Plugin up to 1.8.96 on WordPress. Affected by this vulnerability is an unknown functionality of the component Shortcode Handler. The manipulation leads to missing authorization.
This vulnerability is known as CVE-2024-13361. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-0429 | AI Power Plugin up to 1.8.96 on WordPress wpaicg_export_ai_forms code injection
10 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in AI Power Plugin up to 1.8.96 on WordPress. Affected by this issue is the function wpaicg_export_ai_forms. The manipulation leads to code injection.
This vulnerability is handled as CVE-2025-0429. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2000-0589 | Flowerfire Sawmill 5.0.21 Password Storage cryptographic issues (EDB-20042 / Nessus ID 10454)
10 months 3 weeks ago
A vulnerability was found in Flowerfire Sawmill 5.0.21. It has been classified as critical. This affects an unknown part of the component Password Storage. The manipulation leads to cryptographic issues.
This vulnerability is uniquely identified as CVE-2000-0589. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
WordPecker App – 开源、多邻国式,自定义学习工具
10 months 3 weeks ago
HomeAIWordPecker App – 开源、多邻国式,自定义学习工具
CVE-2024-12477 | Avada Builder Plugin up to 3.11.11 on WordPress Widgets cross site scripting
10 months 3 weeks ago
A vulnerability classified as problematic was found in Avada Builder Plugin up to 3.11.11 on WordPress. Affected by this vulnerability is an unknown functionality of the component Widgets. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-12477. The attack can be launched remotely. There is no exploit available.
vuldb.com