Aggregator
Interlock勒索软件采用“FileFix”手法投递恶意程序
2 months 1 week ago
安全客
PerfektBlue漏洞链曝光:汽车面临蓝牙黑客攻击风险,或致信息娱乐系统遭劫持
2 months 1 week ago
安全客
Китай захватил 70% американского неба без единого выстрела
2 months 1 week ago
Китайские дроны — новая угроза Пентагону?
Zyxel security advisory (AV25-423)
2 months 1 week ago
Canadian Centre for Cyber Security
98% вашей ДНК считались балластом. Теперь туда добрался ИИ от Google. И всё переписал
2 months 1 week ago
Добро пожаловать в чёрный ящик генома.
North Korean XORIndex malware hidden in 67 malicious npm packages
2 months 1 week ago
North Korean threat actors planted 67 malicious packages in the Node Package Manager (npm) online repository to deliver a new malware loader called XORIndex to developer systems. [...]
Bill Toulas
Attackers Hide JavaScript in SVG Images to Lure Users to Malicious Sites
2 months 1 week ago
Beware! SVG images are now being used with obfuscated JavaScript for stealthy redirect attacks via spoofed emails. Get insights from Ontinue's latest research on detection and defence.
Deeba Ahmed
Самые точные часы в истории. Настолько точные, что ставят под вопрос саму секунду
2 months 1 week ago
Они приручили алюминий и заставили его считать до 19 знаков после запятой.
Android Malware Konfety evolves with ZIP manipulation and dynamic loading
2 months 1 week ago
A new Konfety Android malware variant uses a malformed ZIP and obfuscation to evade detection, posing as fake apps with no real functionality. Zimperium zLabs researchers are tracking a new, sophisticated Konfety Android malware variant that uses an “evil-twin” tactic and duplicate package names to avoid detection. The new Konfety malware variants use malformed ZIP, […]
Pierluigi Paganini
CVE-2024-5822 | gaizhenbiao ChuanhuChatGPT up to 20240410 server-side request forgery
2 months 1 week ago
A vulnerability was found in gaizhenbiao ChuanhuChatGPT up to 20240410. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to server-side request forgery.
This vulnerability is known as CVE-2024-5822. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-53947 | Apache Superset up to 4.0.x sql injection
2 months 1 week ago
A vulnerability was found in Apache Superset up to 4.0.x and classified as critical. Affected by this issue is the function query_to_xml_and_xmlschema/table_to_xml/table_to_xml_and_xmlschema. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2024-53947. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-29869 | Apache Hive up to 4.0.0 permission assignment
2 months 1 week ago
A vulnerability classified as problematic was found in Apache Hive up to 4.0.0. This vulnerability affects unknown code. The manipulation leads to incorrect permission assignment.
This vulnerability was named CVE-2024-29869. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-45588 | Fortinet FortiClientMac up to 7.0.10/7.2.3 Configuration File /tmp file inclusion (FG-IR-23-345)
2 months 1 week ago
A vulnerability was found in Fortinet FortiClientMac up to 7.0.10/7.2.3. It has been rated as critical. Affected by this issue is some unknown functionality of the file /tmp of the component Configuration File Handler. The manipulation leads to file inclusion.
This vulnerability is handled as CVE-2023-45588. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-2359 | D-Link DIR-823G 1.0.2B05_20181207 DDNS Service /HNAP1/ SetDDNSSettings SOAPAction improper authorization
2 months 1 week ago
A vulnerability classified as critical has been found in D-Link DIR-823G 1.0.2B05_20181207. Affected is the function SetDDNSSettings of the file /HNAP1/ of the component DDNS Service. The manipulation of the argument SOAPAction leads to improper authorization. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is traded as CVE-2025-2359. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply restrictive firewalling.
vuldb.com
CVE-2025-2360 | D-Link DIR-823G 1.0.2B05_20181207 UPnP Service /HNAP1/ SetUpnpSettings SOAPAction improper authorization
2 months 1 week ago
A vulnerability classified as critical was found in D-Link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is the function SetUpnpSettings of the file /HNAP1/ of the component UPnP Service. The manipulation of the argument SOAPAction leads to improper authorization. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is known as CVE-2025-2360. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to apply restrictive firewalling.
vuldb.com
CVE-2025-24783 | Apache Cocoon prng seed
2 months 1 week ago
A vulnerability was found in Apache Cocoon. It has been classified as problematic. Affected is an unknown function. The manipulation leads to incorrect usage of seeds in prng.
This vulnerability is traded as CVE-2025-24783. Attacking locally is a requirement. There is no exploit available.
It is recommended to apply the suggested workaround.
vuldb.com
CVE-2024-46901 | Apache Subversion up to 1.14.4 Incomplete Fix CVE-2013-1968 mod_dav_svn denial of service (Nessus ID 213027)
2 months 1 week ago
A vulnerability was found in Apache Subversion up to 1.14.4. It has been rated as problematic. This issue affects the function mod_dav_svn of the component Incomplete Fix CVE-2013-1968. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2024-46901. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-41137 | Apache Hive 4.0.0-alpha-1 Metastore deserialization
2 months 1 week ago
A vulnerability was found in Apache Hive 4.0.0-alpha-1. It has been classified as problematic. Affected is an unknown function of the component Metastore. The manipulation leads to deserialization.
This vulnerability is traded as CVE-2022-41137. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-7747 | Wallet for WooCommerce Plugin up to 1.5.6 on WordPress numeric conversion
2 months 1 week ago
A vulnerability was found in Wallet for WooCommerce Plugin up to 1.5.6 on WordPress. It has been classified as critical. Affected is an unknown function. The manipulation leads to incorrect conversion between numeric types.
This vulnerability is traded as CVE-2024-7747. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com