Angry Likho APT resurfaces, targeting Russian and Belarusian organizations with Lumma Stealer malware via phishing attacks, stealing credentials, banking data, and more.
A vulnerability was found in Xen up to 4.17. It has been declared as critical. This vulnerability affects unknown code of the component Legacy PCI Device Handler. The manipulation leads to deadlock.
This vulnerability was named CVE-2025-1713. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in TrivisionSecurity Trivision Camera NC227WF up to 5.7.x. It has been classified as problematic. This affects an unknown part. The manipulation leads to use of get request method with sensitive query strings.
This vulnerability is uniquely identified as CVE-2025-1738. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Boss Media Buddyboss Platform Plugin up to 2.7.70 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument link_title leads to cross site scripting.
This vulnerability is handled as CVE-2024-13402. The attack may be launched remotely. There is no exploit available.
A vulnerability has been found in TrivisionSecurity Trivision Camera NC227WF up to 5.7.x and classified as critical. Affected by this vulnerability is an unknown functionality of the file /en/player/activex_pal.asp. The manipulation leads to authentication bypass using alternate channel.
This vulnerability is known as CVE-2025-1739. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in MongoDB mongosh up to 2.3.8. Affected is an unknown function of the component Control Character Handler. The manipulation leads to improper neutralization of escape, meta, or control sequences.
This vulnerability is traded as CVE-2025-1692. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in MongoDB mongosh up to 2.3.8. This issue affects some unknown processing of the component Control Character Handler. The manipulation leads to injection.
The identification of this vulnerability is CVE-2025-1691. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic was found in MongoDB mongosh up to 2.3.8. This vulnerability affects unknown code of the component Control Character Handler. The manipulation leads to improper neutralization of escape, meta, or control sequences.
This vulnerability was named CVE-2025-1693. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in libmodbus up to 3.1.10. This affects the function tries. The manipulation leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2024-10918. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in jegtheme Jeg Elementor Kit Plugin up to 2.6.11 on WordPress. It has been rated as problematic. Affected by this issue is the function expired_data/build_content of the component Template Data Handler. The manipulation leads to exposure of private personal information to an unauthorized actor.
This vulnerability is handled as CVE-2024-13217. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in ATISoluciones CIGES 2.15.5. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /modules/ajaxBloqueaCita.php. The manipulation of the argument idServicio leads to sql injection.
This vulnerability is known as CVE-2025-1751. The attack can be launched remotely. There is no exploit available.
东京都政府将从今年 4 月开始推行四天工作制,它还引入了一个新的育儿假允许部分工作人员提前两小时下班。东京都知事小池百合子表示,此举旨在帮助新父母们平衡育儿和工作。四天工作制可能有助于解决日本繁重劳动文化给职业女性带来巨大压力的问题。根据国际货币基金组织的数据,日本男性和女性在家庭劳动上的时间差距是经合组织中最大的。日本女性从事育儿和护理老人等无偿工作的时间是男性的五倍。超过半数生育数量低于其意愿的女性表示,少生孩子是因为多一个孩子会增加更多家务负担。四天工作制在实验中被证明有助于解决该问题。4 Day Week Global 的实验显示,男性育儿时长增加了 22%,家务时长增加了 23%。普及四天工作制被认为需要重大的社会变革。
A vulnerability was found in Adobe Substance3D Painter up to 10.1.0. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to out-of-bounds write.
The identification of this vulnerability is CVE-2024-47429. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in Adobe Substance3D Painter up to 10.1.0. Affected is an unknown function. The manipulation leads to out-of-bounds write.
This vulnerability is traded as CVE-2024-47430. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Adobe Substance3D Painter up to 10.1.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to heap-based buffer overflow.
This vulnerability is known as CVE-2024-47431. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Adobe Substance3D Painter up to 10.1.0. Affected by this issue is some unknown functionality. The manipulation leads to out-of-bounds write.
This vulnerability is handled as CVE-2024-47432. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Adobe Substance3D Painter up to 10.1.0. This affects an unknown part. The manipulation leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2024-47433. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Adobe Substance3D Painter up to 10.1.0 and classified as critical. This vulnerability affects unknown code. The manipulation leads to out-of-bounds write.
This vulnerability was named CVE-2024-47434. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.