Aggregator
CVE-2025-1548 | iteachyou Dreamer CMS 4.1.3 /admin/archives/edit editorValue/answer/content cross site scripting
1 year 3 months ago
A vulnerability was found in iteachyou Dreamer CMS 4.1.3. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/archives/edit. The manipulation of the argument editorValue/answer/content leads to cross site scripting.
This vulnerability was named CVE-2025-1548. The attack can be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
U.S. CISA adds Craft CMS and Palo Alto Networks PAN-OS flaws to its Known Exploited Vulnerabilities catalog
1 year 3 months ago
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Craft CMS and Palo Alto Networks PAN-OS vulnerabilities to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SonicWall SonicOS and Palo Alto PAN-OS vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. The two vulnerabilities are: Craft is a flexible, user-friendly CMS, affected […]
Pierluigi Paganini
CVE-2025-1471 | Eclipse OMR 0.2.x/0.3.x out-of-bounds write (ID 55)
1 year 3 months ago
A vulnerability was found in Eclipse OMR 0.2.x/0.3.x. It has been classified as critical. This affects an unknown part. The manipulation leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2025-1471. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-1470 | Eclipse OMR up to 0.4.0 null pointer dereference (ID 54)
1 year 3 months ago
A vulnerability was found in Eclipse OMR up to 0.4.0 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2025-1470. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Submit #497604: iteachyou Dreamer CMS 4.1.3 Stored Cross Site Scripting (XSS) [Duplicate]
1 year 3 months ago
Submit #497604 / VDB-296494
vastzero
Submit #497603: iteachyou Dreamer CMS 4.1.3 Server-Side Request Forgery [Duplicate]
1 year 3 months ago
Submit #497603 / VDB-296494
vastzero
Submit #497602: iteachyou Dreamer CMS 4.1.3 Remote File Inclusion [Accepted]
1 year 3 months ago
Submit #497602 / VDB-296494
vastzero
CVE-2023-22044 | Oracle Java SE up to 8u371-perf/17.0.7/20.0.1 Hotspot information disclosure (Nessus ID 216569)
1 year 3 months ago
A vulnerability was found in Oracle Java SE up to 8u371-perf/17.0.7/20.0.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Hotspot. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2023-22044. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-22025 | Oracle Java SE 8u381-perf/17.0.8/20.0.2 Hotspot (Nessus ID 216569)
1 year 3 months ago
A vulnerability was found in Oracle Java SE 8u381-perf/17.0.8/20.0.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Hotspot. The manipulation leads to an unknown weakness.
This vulnerability is known as CVE-2023-22025. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2021-43519 | Lua up to 5.4.4 Script File ldo.c lua_resume stack-based overflow (Nessus ID 216572)
1 year 3 months ago
A vulnerability was found in Lua up to 5.4.4 and classified as critical. Affected by this issue is the function lua_resume of the file ldo.c of the component Script File Handler. The manipulation leads to stack-based buffer overflow.
This vulnerability is handled as CVE-2021-43519. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-22025 | OpenJDK on x64 Ideal memory corruption (Nessus ID 216569)
1 year 3 months ago
A vulnerability, which was classified as critical, was found in OpenJDK on x64. This affects the function LoadVectorMaskedNode::Ideal. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2023-22025. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-20932 | Oracle Java SE Security (Nessus ID 216569)
1 year 3 months ago
A vulnerability has been found in Oracle Java SE and classified as critical. This vulnerability affects unknown code of the component Security. The manipulation leads to an unknown weakness.
This vulnerability was named CVE-2024-20932. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2021-44647 | Lua 5.4.2/5.4.4 ldebug.c funcnamefromcode denial of service (Nessus ID 216573)
1 year 3 months ago
A vulnerability was found in Lua 5.4.2/5.4.4. It has been declared as problematic. Affected by this vulnerability is the function funcnamefromcode of the file ldebug.c. The manipulation leads to denial of service.
This vulnerability is known as CVE-2021-44647. The attack can be launched remotely. There is no exploit available.
vuldb.com
隐匿黑手:基于 JavaScript 的恶意软件借隐写术暗偷数据
1 year 3 months ago
安全客
Atlassian 修复Confluence 和 Crowd 中的多个严重漏洞
1 year 3 months ago
已修复
微软修复已遭利用的 Power Pages 0day
1 year 3 months ago
速修复
Банки или мошенники? Виртуальные АТС получат специальную маркировку
1 year 3 months ago
Звонки через интернет станут прозрачными.
New Darcula 3.0 Tool Generates Phishing Kits to Mimic Global Brands
1 year 3 months ago
The cybercriminal group behind the notorious “darcula-suite” platform has unveiled its latest iteration, darcula 3.0, which introduces groundbreaking capabilities for creating phishing kits targeting any brand globally. This “Phishing-as-a-Service” (PhaaS) platform lowers the technical barrier for bad actors by automating the cloning of legitimate websites and enabling non-technical users to deploy sophisticated phishing campaigns with […]
The post New Darcula 3.0 Tool Generates Phishing Kits to Mimic Global Brands appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Aman Mishra
如何让CISO巧妙说服董事会支持IAM投资?| CSO Online
1 year 3 months ago
CISO需将IAM定位为战略业务投资,展示其降低风险、推动数字化转型的直接价值,并强调长期竞争优势,才能获得董事会支持。