Aggregator
CVE-2024-22041 | Siemens Cerberus PRO EN Engineering Tool Network Communication Library memory corruption (ssa-225840 / EUVD-2024-19644)
CVE-2024-22246 | Vmware SD-WAN Edge up to 4.5.0/5.0.0 command injection (VMSA-2024-0008 / EUVD-2024-19815)
CVE-2024-29945 | Splunk Enterprise up to 9.0.8/9.1.3/9.2.0 JsonWebToken log file (SVD-2024-0301 / EUVD-2024-26919)
CVE-2024-29204 | Ivanti Avalanche up to 6.4.2 WLAvalancheService heap-based overflow (EUVD-2024-26221)
CVE-2024-29011 | SonicWall GMS up to 9.3.4 hard-coded password (SNWLID-2024-0007 / EUVD-2024-26073)
CVE-2024-4947 | Google Chrome up to 124.0.6367.207 V8 type confusion (ID 340221 / EUVD-2024-44509)
CVE-2024-0518 | Google Chrome up to 120.0.6099.216 V8 type confusion (FEDORA-2024-049f068a8c / EUVD-2024-16313)
Amazon: Russian GRU hackers favor misconfigured devices over vulnerabilities
How test data generators support compliance and data privacy
Whether you’re generating data from scratch or transforming sensitive production data, performant test data generators are critical tools for achieving compliance in development workflows.
The post How test data generators support compliance and data privacy appeared first on Security Boulevard.
Microsoft Details Mitigations Against React2Shell RCE Vulnerability in React Server Components
Microsoft has released comprehensive mitigations for a critical vulnerability dubbed React2Shell (CVE-2025-55182), which poses severe risks to React Server Components and Next.js environments. With a maximum CVSS score of 10.0, this pre-authentication remote code execution flaw allows threat actors to compromise servers through a single malicious HTTP request. Exploitation attempts were first detected on December […]
The post Microsoft Details Mitigations Against React2Shell RCE Vulnerability in React Server Components appeared first on Cyber Security News.