Aggregator
Postcard теперь open source: Ruby, Docker, два режима — всё на GitHub
2 months 1 week ago
Закрытый личный сайт стал открытым кодом.
XMRig Malware Disables Windows Updates and Scheduled Tasks to Maintain Persistence
2 months 1 week ago
Monero (XMR), a cryptocurrency, saw a spectacular surge in early 2025, rising 45% from $196 to $285 by May, with a notable peak in April. This surge coincided with a high-profile Bitcoin theft in the US, where the stolen assets were reportedly converted into Monero by a single individual, drawing attention to the privacy-focused coin. […]
The post XMRig Malware Disables Windows Updates and Scheduled Tasks to Maintain Persistence appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Aman Mishra
CVE-2025-6491 | PHP SOAP Extension null pointer dereference
2 months 1 week ago
A vulnerability has been found in PHP and classified as problematic. This vulnerability affects unknown code of the component SOAP Extension. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2025-6491. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-1735 | PHP pgsql Extension null pointer dereference
2 months 1 week ago
A vulnerability, which was classified as problematic, was found in PHP. This affects an unknown part of the component pgsql Extension. The manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2025-1735. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-53204 | Event List Plugin up to 1.9.2 on WordPress file inclusion
2 months 1 week ago
A vulnerability, which was classified as critical, has been found in Event List Plugin up to 1.9.2 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to file inclusion.
This vulnerability is handled as CVE-2025-53204. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-6742 | SureForms Plugin up to 1.7.3 on WordPress file_exists Remote Code Execution
2 months 1 week ago
A vulnerability classified as critical was found in SureForms Plugin up to 1.7.3 on WordPress. Affected by this vulnerability is the function file_exists. The manipulation leads to Remote Code Execution.
This vulnerability is known as CVE-2025-6742. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-6691 | SureForms Plugin up to 1.7.3 on WordPress delete_entry_files
2 months 1 week ago
A vulnerability classified as critical has been found in SureForms Plugin up to 1.7.3 on WordPress. Affected is the function delete_entry_files. The manipulation leads to an unknown weakness.
This vulnerability is traded as CVE-2025-6691. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-5804 | Case Theme User Plugin up to 1.0.3 on WordPress file inclusion
2 months 1 week ago
A vulnerability was found in Case Theme User Plugin up to 1.0.3 on WordPress. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to file inclusion.
The identification of this vulnerability is CVE-2025-5804. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21167 | Adobe Substance3D up to 14.1 out-of-bounds (apsb25-62)
2 months 1 week ago
A vulnerability was found in Adobe Substance3D up to 14.1. It has been classified as problematic. This affects an unknown part. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2025-21167. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-48300 | Groundhogg Plugin up to 4.2.1 on WordPress unrestricted upload
2 months 1 week ago
A vulnerability was found in Groundhogg Plugin up to 4.2.1 on WordPress. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to unrestricted upload.
This vulnerability was named CVE-2025-48300. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-53209 | Masteriyo LMS PRO Plugin up to 2.20.0 on WordPress Remote Code Execution
2 months 1 week ago
A vulnerability was found in Masteriyo LMS PRO Plugin up to 2.20.0 on WordPress and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to Remote Code Execution.
This vulnerability is handled as CVE-2025-53209. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-21168 | Adobe Substance3D up to 14.1 out-of-bounds (apsb25-62)
2 months 1 week ago
A vulnerability has been found in Adobe Substance3D up to 14.1 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to out-of-bounds read.
This vulnerability is known as CVE-2025-21168. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-53207 | WP Travel Gutenberg Blocks Plugin up to 3.9.0 on WordPress file inclusion
2 months 1 week ago
A vulnerability, which was classified as critical, was found in WP Travel Gutenberg Blocks Plugin up to 3.9.0 on WordPress. Affected is an unknown function. The manipulation leads to file inclusion.
This vulnerability is traded as CVE-2025-53207. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-53198 | Houzez Plugin up to 4.0.4 on WordPress file inclusion
2 months 1 week ago
A vulnerability, which was classified as critical, has been found in Houzez Plugin up to 4.0.4 on WordPress. This issue affects some unknown processing. The manipulation leads to file inclusion.
The identification of this vulnerability is CVE-2025-53198. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-36349 | AMD EPYC 7002 Processors information disclosure
2 months 1 week ago
A vulnerability classified as problematic was found in AMD EPYC 7002 Processors, EPYC 7003 Processors, EPYC 9004 Processors, EPYC 8004 Processors, EPYC 4004 Processors, EPYC 9V64H Processor, Ryzen 5000 Desktop Processors, Ryzen 5000 Desktop Processor with Radeon Graphics, Ryzen 3000 Desktop Processors, Athlon 3000 Desktop Processors with Radeon Graphics, Ryzen 7000 Desktop Processors, Ryzen 4000 Desktop Processor with Radeon Graphics, Ryzen 8000 Processor with Radeon Graphics, Ryzen Threadripper 3000 Processors, Ryzen Threadripper PRO 7000 WX-Series Processors, Ryzen Threadripper PRO 3000WX Processors, Ryzen Threadripper PRO 5000WX- Desktop Processors, Ryzen 7020 Processors with Radeon Graphics, Ryzen 6000 Processor with Radeon Graphics, Ryzen 7035 Processor with Radeon Graphics, Ryzen 7000 Processors with Radeon Graphics, Ryzen 7040 Processors with Radeon Graphics, Ryzen 8040 Mobile Processors with Radeon Graphics, Ryzen 7000 Mobile Processors, EPYC Embedded 7002 Processors, EPYC Embedded 7003 Processors, EPYC Embedded 8004 Processors, EPYC Embedded 9004 Processors, Ryzen Embedded 5000 Processors, Ryzen Embedded 7000 Processors, Ryzen Embedded V2000 Processors, Ryzen Embedded V3000 Processors, Athlon 3000 Mobile Processors with Radeon Graphics, Ryzen 3000 Mobile Processor with Radeon Graphics, EPYC Embedded 3000 Processors, Ryzen Embedded R1000 Processors, Ryzen Embedded R2000 Processors and Ryzen Embedded V1000 Processors. This vulnerability affects unknown code. The manipulation leads to information disclosure.
This vulnerability was named CVE-2024-36349. An attack has to be approached locally. There is no exploit available.
vuldb.com
CVE-2025-53512 | Canonical Juju up to 2.9.51/3.6.7 /log information disclosure (GHSA-r64v-82fh-xc63)
2 months 1 week ago
A vulnerability classified as problematic has been found in Canonical Juju up to 2.9.51/3.6.7. This affects an unknown part of the file /log. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2025-53512. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-36350 | AMD EPYC 7003 Processors information disclosure
2 months 1 week ago
A vulnerability was found in AMD EPYC 7003 Processors, EPYC 9004 Processors, EPYC 8004 Processors, EPYC 9V64H Processor, Ryzen 5000 Desktop Processors, Ryzen 5000 Desktop Processor with Radeon Graphics, Ryzen 7000 Desktop Processors, Ryzen 8000 Processor with Radeon Graphics, Ryzen Threadripper PRO 7000 WX-Series Processors, Ryzen 6000 Processor with Radeon Graphics, Ryzen 7035 Processor with Radeon Graphics, Ryzen 7000 Processors with Radeon Graphics, Ryzen 7040 Processors with Radeon Graphics, Ryzen 8040 Mobile Processors with Radeon Graphics, Ryzen 7000 Mobile Processors, EPYC Embedded 7003 Processors, EPYC Embedded 8004 Processors, EPYC Embedded 9004 Processors, Ryzen Embedded 5000 Processors, Ryzen Embedded 7000 Processors, Ryzen Embedded V3000 Processors, EPYC Embedded 97X4 and Ryzen 5000 Processors with Radeon Graphics. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2024-36350. It is possible to launch the attack on the local host. There is no exploit available.
vuldb.com
CVE-2024-36348 | AMD EPYC 7002 Processors UMIP Feature information disclosure
2 months 1 week ago
A vulnerability was found in AMD EPYC 7002 Processors, EPYC 7003 Processors, EPYC 9004 Processors, EPYC 8004 Processors, EPYC 4004 Processors, EPYC 9V64H Processor, Ryzen 5000 Desktop Processors, Ryzen 5000 Desktop Processor with Radeon Graphics, Ryzen 3000 Desktop Processors, Athlon 3000 Desktop Processors with Radeon Graphics, Ryzen 7000 Desktop Processors, Ryzen 4000 Desktop Processor with Radeon Graphics, Ryzen 8000 Processor with Radeon Graphics, Ryzen Threadripper 3000 Processors, Ryzen Threadripper PRO 7000 WX-Series Processors, Ryzen Threadripper PRO 3000WX Processors, Ryzen Threadripper PRO 5000WX- Desktop Processors, Ryzen 7020 Processors with Radeon Graphics, Ryzen 6000 Processor with Radeon Graphics, Ryzen 7035 Processor with Radeon Graphics, Ryzen 7000 Processors with Radeon Graphics, Ryzen 7040 Processors with Radeon Graphics, Ryzen 8040 Mobile Processors with Radeon Graphics, Ryzen 7000 Mobile Processors, EPYC Embedded 7002 Processors, EPYC Embedded 7003 Processors, EPYC Embedded 8004 Processors, EPYC Embedded 9004 Processors, Ryzen Embedded 5000 Processors, Ryzen Embedded 7000 Processors, Ryzen Embedded V2000 Processors and Ryzen Embedded V3000 Processors. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component UMIP Feature. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2024-36348. Attacking locally is a requirement. There is no exploit available.
vuldb.com
CVE-2024-36357 | AMD EPYC 7003 Processors L1D Cache information disclosure
2 months 1 week ago
A vulnerability was found in AMD EPYC 7003 Processors, EPYC 9004 Processors, EPYC 8004 Processors, EPYC 9V64H Processor, Ryzen 5000 Desktop Processors, Ryzen 5000 Desktop Processor with Radeon Graphics, Ryzen 7000 Desktop Processors, Ryzen 8000 Processor with Radeon Graphics, Ryzen Threadripper PRO 7000 WX-Series Processors, Ryzen 6000 Processor with Radeon Graphics, Ryzen 7035 Processor with Radeon Graphics, Ryzen 7000 Processors with Radeon Graphics, Ryzen 7040 Processors with Radeon Graphics, Ryzen 8040 Mobile Processors with Radeon Graphics, Ryzen 7000 Mobile Processors, EPYC Embedded 7003 Processors, EPYC Embedded 8004 Processors, EPYC Embedded 9004 Processors, Ryzen Embedded 5000 Processors, Ryzen Embedded 7000 Processors, Ryzen Embedded V3000 Processors, EPYC Embedded 97X4 and Ryzen 5000 Processors with Radeon Graphics. It has been classified as problematic. Affected is an unknown function of the component L1D Cache Handler. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-36357. Local access is required to approach this attack. There is no exploit available.
vuldb.com