Aggregator
Qilin
4 months 3 weeks ago
cohenido
Qilin
4 months 3 weeks ago
cohenido
Qilin
4 months 3 weeks ago
cohenido
红队视角:Gitlab已知攻击面与潜在风险
4 months 3 weeks ago
1nhann
CVE-2024-57805 | Linux Kernel up to 6.12.7 /dev/zero denial of service (Nessus ID 233479)
4 months 3 weeks ago
A vulnerability classified as problematic was found in Linux Kernel up to 6.12.7. This vulnerability affects unknown code of the file /dev/zero. The manipulation leads to denial of service.
This vulnerability was named CVE-2024-57805. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47794 | Linux Kernel up to 6.12.4 tailcall_freplace.c entry_freplace infinite loop (Nessus ID 233479)
4 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.12.4. It has been classified as critical. This affects the function entry_freplace of the file tailcall_freplace.c. The manipulation leads to infinite loop.
This vulnerability is uniquely identified as CVE-2024-47794. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-48876 | Linux Kernel up to 6.12.4 stack_depot_save_flags deadlock (Nessus ID 233479)
4 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.12.4. It has been declared as critical. This vulnerability affects the function stack_depot_save_flags. The manipulation leads to deadlock.
This vulnerability was named CVE-2024-48876. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-56580 | Linux Kernel up to 6.12.3 dev_pm_domain_detach null pointer dereference (Nessus ID 233479)
4 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.12.3. It has been rated as critical. Affected by this issue is the function dev_pm_domain_detach. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2024-56580. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-56771 | Linux Kernel up to 6.12.3 winbond get_status privilege escalation (Nessus ID 233479)
4 months 3 weeks ago
A vulnerability has been found in Linux Kernel up to 6.12.3 and classified as problematic. Affected by this vulnerability is the function get_status of the component winbond. The manipulation leads to privilege escalation.
This vulnerability is known as CVE-2024-56771. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-54460 | Linux Kernel up to 6.12.5 iso_listen_bis deadlock (Nessus ID 233479)
4 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.12.5. It has been declared as critical. This vulnerability affects the function iso_listen_bis. The manipulation leads to deadlock.
This vulnerability was named CVE-2024-54460. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-2588 | Hercules Augeas 1.14.1 src/fa.c re_case_expand re null pointer dereference (Issue 852 / Nessus ID 233483)
4 months 3 weeks ago
A vulnerability has been found in Hercules Augeas 1.14.1 and classified as problematic. This vulnerability affects the function re_case_expand of the file src/fa.c. The manipulation of the argument re leads to null pointer dereference.
This vulnerability was named CVE-2025-2588. Attacking locally is a requirement. Furthermore, there is an exploit available.
vuldb.com
Разведка США: Китай заложил "закладки" в американские энергосистемы
4 months 3 weeks ago
ATA-2025 раскрывает кибершаги на случай войны за Тайвань.
【安全圈】数据罗生门:600 万用户泄露信息被证真实,甲骨文坚称未被入侵
4 months 3 weeks ago
关键词数据泄露科技媒体 bleepingcomputer 昨日(3 月 26 日)发布博文,尽管甲骨文(Ora
【安全圈】黑客组织攻击纽约大学官网,泄露 300 万学生敏感信息
4 months 3 weeks ago
关键词黑客近日,一个自称为“Computer Niggy Exploitation”的黑客组织对美国著名高等学
【安全圈】王者荣耀崩了,官方致歉:问题已修复,补偿方案公布
4 months 3 weeks ago
关键词网络崩溃3月28日晚,“王者荣耀崩了”登上热搜,引发网友热议。
Babuk Locker 2.0 vs Seceon Platform: MITRE ATT&CK Mapping and Early-Stage Detection & Remediation
4 months 3 weeks ago
Overview of Babuk Locker 2.0 Babuk Locker 2.0 is a ransomware strain that employs double extortion, where attackers encrypt victim files and exfiltrate sensitive data for ransom. It targets organizations by exploiting RDP vulnerabilities, unpatched systems, weak credentials, and phishing attacks. MITRE ATT&CK Mapping of Babuk Locker 2.0 & Seceon’s Early Detection & Remediation MITRE
The post Babuk Locker 2.0 vs Seceon Platform: MITRE ATT&CK Mapping and Early-Stage Detection & Remediation appeared first on Seceon Inc.
The post Babuk Locker 2.0 vs Seceon Platform: MITRE ATT&CK Mapping and Early-Stage Detection & Remediation appeared first on Security Boulevard.
Chandra Shekhar Pandey
CVE-2025-2840 | DAP to Autoresponders Email Syncing Plugin up to 1.0 on WordPress phpinfo.php information disclosure
4 months 3 weeks ago
A vulnerability classified as problematic has been found in DAP to Autoresponders Email Syncing Plugin up to 1.0 on WordPress. This affects an unknown part of the file phpinfo.php. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2025-2840. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-2006 | WP Zone Inline Image Upload for BBPress Plugin up to 1.1.19 on WordPress unrestricted upload
4 months 3 weeks ago
A vulnerability classified as critical was found in WP Zone Inline Image Upload for BBPress Plugin up to 1.1.19 on WordPress. This vulnerability affects unknown code. The manipulation leads to unrestricted upload.
This vulnerability was named CVE-2025-2006. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-2249 | SoJ SoundSlides Plugin up to 1.2.2 on WordPress soj_soundslides_options_subpanel unrestricted upload
4 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in SoJ SoundSlides Plugin up to 1.2.2 on WordPress. This issue affects the function soj_soundslides_options_subpanel. The manipulation leads to unrestricted upload.
The identification of this vulnerability is CVE-2025-2249. The attack may be initiated remotely. There is no exploit available.
vuldb.com