Aggregator
CVE-2025-1097 | Kubernetes ingress-nginx up to 1.11.4/1.12.0 auth-tls-match-cn Ingress Annotation IngressNightmare input validation (Issue 131007 / Nessus ID 233357)
5 months 4 weeks ago
A vulnerability, which was classified as very critical, has been found in Kubernetes ingress-nginx up to 1.11.4/1.12.0. This issue affects some unknown processing of the component auth-tls-match-cn Ingress Annotation. The manipulation leads to improper input validation.
The identification of this vulnerability is CVE-2025-1097. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-1098 | Kubernetes ingress-nginx up to 1.11.4/1.12.0 Ingress Annotation IngressNightmare input validation (Issue 131008 / Nessus ID 233357)
5 months 4 weeks ago
A vulnerability, which was classified as very critical, was found in Kubernetes ingress-nginx up to 1.11.4/1.12.0. Affected is an unknown function of the component Ingress Annotation Handler. The manipulation leads to improper input validation.
This vulnerability is traded as CVE-2025-1098. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
RALord
5 months 4 weeks ago
cohenido
RALord
5 months 4 weeks ago
cohenido
VanHelsing
5 months 4 weeks ago
cohenido
CVE-2009-4175 | Korn19 UTF-8 CuteNews up to 7 Error Message search.php from_date_day information disclosure (EDB-33341 / XFDB-54235)
5 months 4 weeks ago
A vulnerability has been found in Korn19 UTF-8 CuteNews up to 7 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file search.php of the component Error Message Handler. The manipulation of the argument from_date_day leads to information disclosure.
This vulnerability is known as CVE-2009-4175. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Broadcom Extends Scope of VMware vDefend Cybersecurity Platform
5 months 4 weeks ago
Broadcom today updated its VMware vDefend platform to add additional security intelligence capabilities along with a streamlined ability to micro-segment networks using code to programmatically deploy virtual firewalls. Additionally, Broadcom has made it simpler to deploy and scale out the Security Services Platform (SSP) it uses to provide a data lake for collecting telemetry data..
The post Broadcom Extends Scope of VMware vDefend Cybersecurity Platform appeared first on Security Boulevard.
Michael Vizard
CVE-2024-5302 | Kofax Power PDF PDF File Parser out-of-bounds write
5 months 4 weeks ago
A vulnerability was found in Kofax Power PDF. It has been classified as critical. Affected is an unknown function of the component PDF File Parser. The manipulation leads to out-of-bounds write.
This vulnerability is traded as CVE-2024-5302. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-5301 | Kofax Power PDF PSD File Parser heap-based overflow
5 months 4 weeks ago
A vulnerability was found in Kofax Power PDF. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component PSD File Parser. The manipulation leads to heap-based buffer overflow.
This vulnerability is known as CVE-2024-5301. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-5307 | Kofax Power PDF PDF AcroForm Annotation out-of-bounds
5 months 4 weeks ago
A vulnerability, which was classified as problematic, has been found in Kofax Power PDF. This issue affects some unknown processing of the component PDF AcroForm Annotation Handler. The manipulation leads to out-of-bounds read.
The identification of this vulnerability is CVE-2024-5307. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-2295 | Contact Form Manager Plugin up to 1.6.1 on WordPress cross site scripting
5 months 4 weeks ago
A vulnerability was found in Contact Form Manager Plugin up to 1.6.1 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-2295. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-35636 | Uploadcare File Uploader and Adaptive Delivery Plugin cross-site request forgery
5 months 4 weeks ago
A vulnerability, which was classified as problematic, was found in Uploadcare File Uploader and Adaptive Delivery Plugin up to 3.0.11 on WordPress. This affects an unknown part. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2024-35636. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
New ReaderUpdate malware variants target macOS users
5 months 4 weeks ago
New ReaderUpdate malware variants, now written in Crystal, Nim, Rust, and Go, targets macOS users, SentinelOne warns. SentinelOne researchers warn that multiple versions of the ReaderUpdate malware written in Crystal, Nim, Rust, and Go programming languages, are targeting macOS users. ReaderUpdate is a macOS malware loader that has been active since 2020, the malicious code […]
Pierluigi Paganini
CVE-2025-2835 | zhangyd-c OneBlog up to 2.3.9 RestApiController.java autoLink server-side request forgery (Issue 36)
5 months 4 weeks ago
A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been declared as problematic. Affected by this vulnerability is the function autoLink of the file com/zyd/blog/controller/RestApiController.java. The manipulation leads to server-side request forgery.
This vulnerability is known as CVE-2025-2835. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-2833 | zhangyd-c OneBlog up to 2.3.9 HTTP Header X-Forwarded-For redos (Issue 35)
5 months 4 weeks ago
A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been classified as problematic. Affected is an unknown function of the component HTTP Header Handler. The manipulation of the argument X-Forwarded-For leads to inefficient regular expression complexity.
This vulnerability is traded as CVE-2025-2833. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #521815: https://github.com/zhangyd-c/OneBlog oneblog 2.3.9 SSRF [Accepted]
5 months 4 weeks ago
Submit #521815 / VDB-301471
s1mple_xy
CVE-2025-2832 | mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 cross-site request forgery (IBTSPH)
5 months 4 weeks ago
A vulnerability was found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2025-2832. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-2831 | mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 bookList?page=1&limit=10 getBookList condition sql injection (IBTSJL)
5 months 4 weeks ago
A vulnerability has been found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as critical. This vulnerability affects the function getBookList of the file /admin/bookList?page=1&limit=10. The manipulation of the argument condition leads to sql injection.
This vulnerability was named CVE-2025-2831. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #521813: https://github.com/zhangyd-c/OneBlog oneblog 2.3.9 redos [Accepted]
5 months 4 weeks ago
Submit #521813 / VDB-301470
s1mple_xy