Aggregator
Severe WordPress Plugin Flaw Puts 200,000 Sites at Risk of Full Takeover
A critical arbitrary file deletion vulnerability has been discovered in the SureForms WordPress plugin, affecting over 200,000 active installations and potentially enabling unauthenticated attackers to achieve full site takeover. The flaw, tracked as CVE-2025-6691 with a CVSS score of 8.8 (High), resides in versions up to 1.7.3 of the plugin, which is developed by Brainstorm […]
The post Severe WordPress Plugin Flaw Puts 200,000 Sites at Risk of Full Takeover appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
纽创信安邀您参加2025 RISC-V中国峰会,共筑后量子时代芯片级安全底座!
纽创信安邀您参加2025 RISC-V中国峰会,共筑后量子时代芯片级安全底座!
中国在建太阳能风电装机容量占全球四分之三
2025-07-11 HW情报分享(四)
CVE-2025-2523 | Honeywell C300 PCNT02 Control Data Access integer underflow (EUVD-2025-21063)
CVE-2025-30024 | Axis Device Manager Communication Protocol certificate validation (EUVD-2025-21111)
CVE-2025-30025 | Axis Device Manager/Camera Station Pro/Camera Station Communication Protocol deserialization (EUVD-2025-21110)
CVE-2025-30026 | Axis Camera Station Pro/Camera Station authentication bypass (EUVD-2025-21109)
Hackers Actively Exploiting CitrixBleed 2 Vulnerability in the Wild
Researchers have observed widespread exploitation attempts targeting a critical memory disclosure vulnerability in Citrix NetScaler devices, designated as CVE-2025-5777 and dubbed “CitrixBleed 2.” This pre-authentication flaw enables attackers to craft malicious requests that leak uninitialized memory from affected NetScaler ADC and Gateway devices, potentially exposing sensitive data, including session tokens, passwords, and configuration values. The […]
The post Hackers Actively Exploiting CitrixBleed 2 Vulnerability in the Wild appeared first on Cyber Security News.
Cyber Security expert, Difesa, Legioni e Milizie.
【开放注册公告】吾爱破解论坛2025年7月21日暑假开放注册公告
【开放注册公告】吾爱破解论坛2025年7月21日暑假开放注册公告
Critical D-Link Vulnerability Lets Remote Attackers Crash Servers Without Authentication
Security researchers have discovered a critical stack-based buffer overflow vulnerability in D-Link DIR-825 Rev.B 2.10 routers that allows remote attackers to crash servers without requiring authentication. The vulnerability, designated as CVE-2025-7206, affects the router’s httpd binary and can be exploited by manipulating the language parameter in the switch_language.cgi script. This flaw poses significant risks to […]
The post Critical D-Link Vulnerability Lets Remote Attackers Crash Servers Without Authentication appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.