Aggregator
Undisclosed AI Chat Platform Listed in Alleged Customer Data Sale With Card Details
6 days 7 hours ago
A threat actor using the alias yeblan claims to be selling private customer data from an unnamed AI chatting platform, offered in a structured format containing user and customer emails, the last four digits of payment cards, and subscription IDs.
Dark Web Informer
G.O.S.S.I.P 阅读推荐 2026-05-26 隔离浏览器也会“对⼝供”
6 days 7 hours ago
警惕Underminr新型网络规避技术:CDN共享边缘的隐形漏洞
6 days 8 hours ago
当你以为域前置技术已经被各大 CDN 厂商彻底封堵时,一种更隐蔽、更危险的规避技术正在悄然兴起。
«Самая анонимная биржа» потеряла 7000 Monero — монет, которые нельзя заморозить, отследить или вернуть. Удобно. Для хакера
6 days 8 hours ago
Площадка остановила торги, но вернуть доверие будет куда сложнее.
CVE-2018-25361 | Soroush IM Desktop App 0.17.0 authentication spoofing (Exploit 45171 / EUVD-2018-21883)
6 days 8 hours ago
A vulnerability categorized as critical has been discovered in Soroush IM Desktop App 0.17.0. This issue affects some unknown processing. Such manipulation leads to authentication bypass by spoofing.
This vulnerability is traded as CVE-2018-25361. An attack has to be approached locally. Furthermore, there is an exploit available.
vuldb.com
CVE-2026-47076 | benoitc hackney up to 4.0.0 interpretation conflict (GHSA-pj7v-xfvx-wmjq / EUVD-2026-31689)
6 days 8 hours ago
A vulnerability was found in benoitc hackney up to 4.0.0. It has been rated as problematic. This vulnerability affects unknown code. This manipulation causes interpretation conflict.
This vulnerability appears as CVE-2026-47076. The attack requires local access. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-42797 | Apache Syncope up to 3.0.16/4.0.5/4.1.0 JEXL information exposure (EUVD-2026-31702)
6 days 8 hours ago
A vulnerability was found in Apache Syncope up to 3.0.16/4.0.5/4.1.0. It has been declared as problematic. This affects an unknown part of the component JEXL Handler. The manipulation results in exposure of sensitive information through data queries.
This vulnerability is reported as CVE-2026-42797. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-42782 | Apache Syncope up to 3.0.16/4.0.5/4.1.0 Groovy Code improper isolation or compartmentalization (EUVD-2026-31696)
6 days 8 hours ago
A vulnerability was found in Apache Syncope up to 3.0.16/4.0.5/4.1.0. It has been classified as problematic. Affected by this issue is some unknown functionality of the component Groovy Code Handler. The manipulation leads to improper isolation or compartmentalization.
This vulnerability is documented as CVE-2026-42782. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-9078 | Mozilla Firefox up to 151.0 on iOS RTL ui layer (EUVD-2026-31693)
6 days 8 hours ago
A vulnerability was found in Mozilla Firefox up to 151.0 on iOS and classified as problematic. Affected by this vulnerability is an unknown functionality of the component RTL Handler. Executing a manipulation can lead to improper restriction of rendered ui layers.
This vulnerability is registered as CVE-2026-9078. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2018-25378 | Stokedonit Notebook Pro 2.0 memory allocation (Exploit 45420 / EUVD-2018-21898)
6 days 8 hours ago
A vulnerability has been found in Stokedonit Notebook Pro 2.0 and classified as problematic. Affected is an unknown function. Performing a manipulation results in uncontrolled memory allocation.
This vulnerability is cataloged as CVE-2018-25378. The attack must be initiated from a local position. Furthermore, there is an exploit available.
vuldb.com
CVE-2018-25376 | SocuSoft 3GP Photo Slideshow 8.05 buffer overflow (Exploit 45352 / EUVD-2018-21900)
6 days 8 hours ago
A vulnerability, which was classified as critical, was found in SocuSoft 3GP Photo Slideshow 8.05. This impacts an unknown function. Such manipulation leads to buffer overflow.
This vulnerability is listed as CVE-2018-25376. The attack must be carried out locally. In addition, an exploit is available.
vuldb.com
CVE-2018-25375 | SocuSoft iPod Photo Slideshow 8.05 stack-based overflow (Exploit 45350 / EUVD-2018-21896)
6 days 8 hours ago
A vulnerability, which was classified as critical, has been found in SocuSoft iPod Photo Slideshow 8.05. This affects an unknown function. This manipulation causes stack-based buffer overflow.
This vulnerability is tracked as CVE-2018-25375. The attack is restricted to local execution. Moreover, an exploit is present.
vuldb.com
CVE-2018-25377 | SocuSoft Flash Slideshow Maker Professional 5.20 buffer overflow (Exploit 45355 / EUVD-2018-21899)
6 days 8 hours ago
A vulnerability classified as critical was found in SocuSoft Flash Slideshow Maker Professional 5.20. The impacted element is an unknown function. The manipulation results in buffer overflow.
This vulnerability is identified as CVE-2018-25377. The attack is only possible with local access. Additionally, an exploit exists.
vuldb.com
CVE-2018-25371 | Moosocial mooSocial Store Plugin 2.6 Product sql injection (Exploit 45330 / EUVD-2018-21892)
6 days 8 hours ago
A vulnerability classified as critical has been found in Moosocial mooSocial Store Plugin 2.6. The affected element is an unknown function. The manipulation of the argument Product leads to sql injection.
This vulnerability is referenced as CVE-2018-25371. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
vuldb.com
CVE-2018-25369 | scanwith Visual Ping 0.8.0.0 buffer overflow (Exploit 45316 / EUVD-2018-21890)
6 days 8 hours ago
A vulnerability described as critical has been identified in scanwith Visual Ping 0.8.0.0. Impacted is an unknown function. Executing a manipulation can lead to buffer overflow.
The identification of this vulnerability is CVE-2018-25369. The attack can only be executed locally. Furthermore, there is an exploit available.
vuldb.com
CVE-2018-25367 | NASA openVSP 3.16.1 buffer overflow (Exploit 45281 / EUVD-2018-21888)
6 days 8 hours ago
A vulnerability marked as critical has been reported in NASA openVSP 3.16.1. This issue affects some unknown processing. Performing a manipulation results in buffer overflow.
This vulnerability was named CVE-2018-25367. The attack needs to be approached locally. In addition, an exploit is available.
vuldb.com
KnowledgeDeliver LMS Zero-Day Exploited to Deploy BLUEBEAM Web Shell
6 days 8 hours ago
A newly disclosed zero-day vulnerability in the KnowledgeDeliver Learning Management System (LMS) has been actively exploited in the wild to deploy the BLUEBEAM in-memory web shell, according to Mandiant’s incident response findings. The flaw, now tracked as CVE-2026-5426, enables unauthenticated remote code execution (RCE) and affects deployments that relied on default ASP.NET configuration settings prior […]
The post KnowledgeDeliver LMS Zero-Day Exploited to Deploy BLUEBEAM Web Shell appeared first on Cyber Security News.
Guru Baran
CVE-2018-25373 | SocuSoft DVD Photo Slideshow Professional 8.07 stack-based overflow (Exploit 45346 / EUVD-2018-21894)
6 days 8 hours ago
A vulnerability labeled as critical has been found in SocuSoft DVD Photo Slideshow Professional 8.07. This vulnerability affects unknown code. Such manipulation leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2018-25373. Local access is required to approach this attack. Moreover, an exploit is present.
vuldb.com
CVE-2026-47072 | benoitc hackney up to 4.0.0 URL src/hackney_ws.erl crlf injection (EUVD-2026-31690)
6 days 8 hours ago
A vulnerability identified as problematic has been detected in benoitc hackney up to 4.0.0. This affects an unknown part of the file src/hackney_ws.erl of the component URL Handler. This manipulation causes crlf injection.
This vulnerability is handled as CVE-2026-47072. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
vuldb.com