Aggregator
CVE-2024-0403 | Recipes 1.5.10 HTTP Request server-side request forgery
CVE-2024-2568 | heyewei JFinalCMS 5.0.0 Custom Data Page delete?divId=9 sql injection
CVE-2024-1538 | File Manager Plugin up to 7.2.4 on WordPress JS File cross-site request forgery (ID 3051451)
CVE-2024-2969 | backie WP-Eggdrop Plugin up to 0.1 on WordPress Setting wpegg_updateOptions cross-site request forgery
CVE-2024-2968 | WP-Eggdrop Plugin up to 0.1 on WordPress cross site scripting
Как объяснить турбулентность? Бросаешь в реку двух утят — получаешь ответ на уравнение тысячелетия
科威特遭受攻击:230多个域名用于复杂的网络钓鱼行动
Federal cyber workforce training institute eyed in bipartisan House bill
The legislation comes amid DOGE-fueled cuts to CISA and warnings from lawmakers that Trump administration policies will cripple federal cyber recruiting.
The post Federal cyber workforce training institute eyed in bipartisan House bill appeared first on CyberScoop.
67% of Organizations Faces Cyber Attack in The Past 12 Months – New Report
Cyber attacks continue to plague organizations worldwide, with a staggering 67% of businesses reporting they faced at least one attack in the past year, according to the newly released Hiscox Cyber Readiness Report 2024. This marks the fourth consecutive annual increase in attack frequency, rising from 53% in the previous report and highlighting the escalating […]
The post 67% of Organizations Faces Cyber Attack in The Past 12 Months – New Report appeared first on Cyber Security News.
CVE-2025-4712 | Campcodes Sales and Inventory System 1.0 account_summary.php cid sql injection (EUVD-2025-15366)
CVE-2025-4713 | Campcodes Sales and Inventory System 1.0 /pages/print.php sid sql injection (EUVD-2025-15367)
CVE-2025-4714 | Campcodes Sales and Inventory System 1.0 /pages/reprint.php sid sql injection (EUVD-2025-15376)
CVE-2025-4848 | FreeFloat FTP Server 1.0 RECV Command buffer overflow (EUVD-2025-15714)
glibc漏洞使数百万Linux系统面临代码执行风险
Alleged Sale of Unauthorized Admin Access to a UK WordPress Gambling Platform
木马化的KeePass用于部署Cobalt Strike并窃取凭据
RVTools供应链攻击:Bumblebee恶意软件通过可信的VMware实用程序交付
Auth0-PHP Vulnerability Enables Unauthorized Access for Attackers
Critical security vulnerability has been discovered in the Auth0-PHP SDK that could potentially allow unauthorized access to applications through brute force attacks on session cookie authentication tags. The vulnerability specifically affects versions 8.0.0-BETA1 and newer of the SDK when configured with CookieStore for session storage. A patch has been released in version 8.14.0, and Okta, […]
The post Auth0-PHP Vulnerability Enables Unauthorized Access for Attackers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Ivanti EPMM 0-day Vulnerability Actively Exploited in the Wild
Ivanti has disclosed two zero-day vulnerabilities in its Endpoint Manager Mobile (EPMM) solution. When chained together, these vulnerabilities allow attackers to execute unauthenticated remote code. Security researchers have confirmed active exploitation in the wild, with the Shadowserver Foundation tracking nearly 800 vulnerable instances still exposed online. The vulnerabilities, identified as CVE-2025-4427 and CVE-2025-4428, were disclosed […]
The post Ivanti EPMM 0-day Vulnerability Actively Exploited in the Wild appeared first on Cyber Security News.