Aggregator
Network Edge Devices the Biggest Entry Point for Attacks on SMBs
CVE-2024-40582 | Pentaminds CuroVMS 2.0.1 information disclosure
CVE-2024-40583 | Pentaminds CuroVMS 2.0.1 Credential information disclosure
CVE-2023-22697 | Survey Maker Plugin up to 3.2.0 on WordPress authorization
CVE-2024-12946 | 1000 Projects Attendance Tracking Management System 1.0 /admin/admin_action.php admin_user_name sql injection
CVE-2024-56410 | PHPOffice PhpSpreadsheet up to 1.29.6/2.1.5/2.3.4/3.6.x cross site scripting (GHSA-wv23-996v-q229)
CVE-2025-21613 | go-git up to 5.12.x argument injection (Nessus ID 213966)
CVE-2024-12927 | 1000 Projects Attendance Tracking Management System 1.0 check_faculty_login.php faculty_emailid sql injection
CVE-2024-12935 | code-projects Simple Admin Panel 1.0 editItemForm.php record sql injection
CVE-2024-12936 | code-projects Simple Admin Panel 1.0 catDeleteController.php record sql injection
CVE-2024-10706 | Download Manager Plugin up to 3.3.02 on WordPress Setting cross site scripting
Apple plugs zero-day holes used in targeted iPhone attacks (CVE-2025-31200, CVE-2025-31201)
Apple has released emergency security updates for iOS/iPadOS, macOS, tvOS and visionOS that fix two zero-day vulnerabilities (CVE-2025-31200, CVE-2025-31201) that have been exploited “in an extremely sophisticated attack against specific targeted individuals on iOS.” CVE-2025-31200 and CVE-2025-31201 CVE-2025-31200 affects CoreAudio, an API Apple devices use for processing audio. The memory corruption vulnerability can be triggered with a maliciously crafted media file: when the audio stream in it is processed, it allows attackers to execute malicious … More →
The post Apple plugs zero-day holes used in targeted iPhone attacks (CVE-2025-31200, CVE-2025-31201) appeared first on Help Net Security.
Java代码审计之命令执行漏洞详解
«Активный инцидент» в Atlassian: только ошибки и пустота
emlog2.5.3代码审计(后台文件上传漏洞)
MCP安全检查清单:AI⼯具⽣态系统安全指南
近800万条医护职工敏感信息泄露:因软件厂商关键数据库公网暴露
Cyber threats against energy sector surge as global tensions mount
Cyberattacks targeting the energy sector are increasing, driven by a host of geopolitical and technological factors. A report published by Sophos in July 2024, and which surveyed 275 cybersecurity and IT leaders from the energy, oil/gas, and utilities sector across 14 countries, found 67% of respondents who said their organizations had suffered a ransomware attack in the last year. While Sophos’ figure remained steady year-over-year, a January 2025 report authored by TrustWave said that ransomware … More →
The post Cyber threats against energy sector surge as global tensions mount appeared first on Help Net Security.