Aggregator
CVE-2019-19985 | Email Subscribers / Newsletters up to 4.2.2 on WordPress File Download information disclosure (News 158563 / EDB-48698)
CVE-2019-20361 | Email Subscribers / Newsletters up to 4.3.0 on WordPress hash sql injection (News 158568 / EDB-48699)
CVE-2019-15889 | download-manager Plugin up to 2.9.93 on WordPress Category orderby/search[publish_date] cross site scripting (ID 154356 / EDB-47350)
CVE-2019-16223 | WordPress up to 5.2.2 Post Preview cross site scripting (Bug 160745 / EDB-49338)
CVE-2019-16902 | ARforms Plugin 3.7.1 on WordPress arformcontroller.php arf_delete_file Path input validation (EDB-47443)
CVE-2019-8404 | Webiness Inventory 2.3 ProductModel unrestricted upload (EDB-46405)
CVE-2019-12460 | Web Port 1.19.1 /access/setup Type cross site scripting (ID 158174 / EDB-48612)
CVE-2019-13292 | webERP 4.15 Payments.php SQL Query sql injection (EDB-47013)
ИИ защитит от ИИ? Каждый четвертый IT-специалист в России считает дипфейки самой опасной угрозой.
CVE-2025-10205 | ABB FLXEON up to 9.3.5 hash without salt
CVE-2025-10664 | PHPGurukul Small CRM 4.0 /create-ticket.php subject sql injection
6000 чужих миров и один из них может быть обитаемым. NASA переписала карту космоса
Google fixes actively exploited Chrome zero-day vulnerability (CVE-2025-10585)
Google has released a security update for the Chrome stable channel to fix a zero‑day vulnerability (CVE-2025-10585) reported by its Threat Analysis Group (TAG) on Tuesday. “Google is aware that an exploit for CVE-2025-10585 exists in the wild,” the company announced. About CVE-2025-10585 Like CVE-2025-6554, which was fixed earlier this year, CVE-2025-10585 is a type confusion vulnerability in V8, Chrome’s JavaScript and WebAssembly engine. Unfortunately, that’s the only information Google has shared about it. As … More →
The post Google fixes actively exploited Chrome zero-day vulnerability (CVE-2025-10585) appeared first on Help Net Security.
CVE-2025-10662 | SeaCMS up to 13.3 admin_members.php?ac=editsave ID sql injection
CVE-2025-10663 | PHPGurukul Online Course Registration 3.1 /my-profile.php cgpa sql injection
LinkedIn now uses your data for AI by default, opt out now!
LinkedIn is making major changes to its User Agreement and Privacy Policy, effective November 3, 2025. Among the most notable updates, the company will now use member data by default to improve its generative AI models, unless users manually opt out. The update reflects LinkedIn’s growing reliance on AI-powered features across its platform. While the company says the data will help improve content-generating tools and user experiences, privacy-conscious members may want to review their settings. … More →
The post LinkedIn now uses your data for AI by default, opt out now! appeared first on Help Net Security.
Tracking New Entrants in Global Spyware Markets
Lurking in the murky depths of the global marketplace for offensive cyber capabilities sits a particularly dangerous instrument—spyware. Spyware’s danger stems from its acute contribution to human rights abuses and national security risks. Most recently, NSO Group, a notorious spyware vendor known to have contributed to the surveillance of journalists, diplomats, and civil society actors […]
The post Tracking New Entrants in Global Spyware Markets appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.