Aggregator
CVE-2024-1287 | WP-FeedStats pmpro-member-directory Plugin up to 1.2.5 on WordPress access control
CVE-2020-18442 | ZZIPlib 0.13.69 unzzip_cat_file zzip_file_read infinite loop (Nessus ID 211358)
外交部警告美国,不要搞“长臂管辖”
海洋中的纳米塑料多达数千万吨
CVE-2025-7031 | Config Pages Viewer up to 1.0.3 on Drupal missing authentication (sa-contrib-2025-086 / EUVD-2025-20697)
CVE-2024-38327 | IBM Analytics Content Hub 2.0/2.1/2.2/2.3 API sensitive information in source (EUVD-2024-54770)
CVE-2025-46334 | j6t git-gui up to 2.50.0 sh.exe os command injection (GHSA-7px4-9hg2-fvhx / EUVD-2025-21003)
CVE-2025-46334 | Microsoft Visual Studio Git privilege escalation (EUVD-2025-21003)
CVE-2025-53624 | webbertakken docusaurus-plugin-content-gists up to 3.x GitHub Personal Access Token information disclosure (GHSA-qf34-qpr4-5pph / EUVD-2025-20874)
CVE-2025-7407 | Netgear D6400 1.0.0.114 diag.cgi host_name os command injection (EUVD-2025-20999)
CVE-2025-53364 | parse-server up to 7.5.2/8.2.1 GraphQL Schema exposure of sensitive system information to an unauthorized control sphere (EUVD-2025-21001)
CVE-2025-46835 | Microsoft Visual Studio Git privilege escalation (EUVD-2025-21002 / Nessus ID 241644)
CVE-2025-7425 | libxslt Attribute Type key atype use after free (EUVD-2025-20998)
CVE-2025-6395 | GnuTLS _gnutls_figure_common_ciphersuite null pointer dereference (EUVD-2025-21000)
4 Arrests in Dawn Raid of Scattered-Spider Suspects
Alleged arachnid arrests: Three teenage males and a young woman hauled away by cops, suspected of hacking huge retailers.
The post 4 Arrests in Dawn Raid of Scattered-Spider Suspects appeared first on Security Boulevard.
Пощёчина BigTech: крошечная страна создала ИИ мощнее ChatGPT и отдаёт его даром
Palo Alto Networks GlobalProtect Vulnerability Allows Root User Privilege Escalation
Palo Alto Networks has disclosed a critical security vulnerability in its GlobalProtect VPN application that enables locally authenticated users to escalate their privileges to root access on macOS and Linux systems, or NT AUTHORITY\SYSTEM on Windows machines. The vulnerability, classified as an incorrect privilege assignment flaw, poses significant security risks for organizations relying on the […]
The post Palo Alto Networks GlobalProtect Vulnerability Allows Root User Privilege Escalation appeared first on Cyber Security News.