Aggregator
CVE-2025-7341
1 week 4 days ago
Currently trending CVE - Hype Score: 14 - The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the temp_file_delete() function in all versions up to, and including, 2.2.1. This ...
CVE-2025-7340
1 week 4 days ago
Currently trending CVE - Hype Score: 14 - The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the temp_file_upload function in all versions up to, and including, 2.2.1. This makes it ...
«Глаз шторма»: Китай готовится ослепить армии мира одним сигналом
1 week 4 days ago
Новая технология позволяет глушить врага, сохраняя собственные коммуникации.
CVE-2023-38559 | Artifex Ghostscript base/gdevdevn.c devn_pcx_write_rle out-of-bounds (DLA 3519-1 / EUVD-2023-42358)
1 week 4 days ago
A vulnerability was found in Artifex Ghostscript. It has been declared as problematic. Affected by this vulnerability is the function devn_pcx_write_rle of the file base/gdevdevn.c. The manipulation leads to out-of-bounds read.
This vulnerability is known as CVE-2023-38559. The attack can only be done within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-38560 | Artifex Ghostscript pcl/pl/plfont.c pl_glyph_name integer overflow (EUVD-2023-42359)
1 week 4 days ago
A vulnerability was found in Artifex Ghostscript. It has been rated as problematic. Affected by this issue is the function pl_glyph_name of the file pcl/pl/plfont.c. The manipulation leads to integer overflow.
This vulnerability is handled as CVE-2023-38560. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-39328 | OpenJPEG File resource consumption (EUVD-2023-43059 / Nessus ID 210667)
1 week 4 days ago
A vulnerability, which was classified as problematic, was found in OpenJPEG. This affects an unknown part of the component File Handler. The manipulation leads to resource consumption.
This vulnerability is uniquely identified as CVE-2023-39328. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
纽约大学 | Lost at C:关于大型语言模型代码助手安全影响的用户级研究
1 week 4 days ago
本文提出了一种名为MH-Net的新型多视角异构图模型,通过将不同位数的流量比特聚合为多种类型的流量单元,构建多视角流量图,丰富了信息表达粒度,并提升了模型性能。
CVE-2018-18797 | School Attendance Monitoring System 1.0 /user/user/edit.php cross-site request forgery (EDB-45725)
1 week 4 days ago
A vulnerability, which was classified as problematic, has been found in School Attendance Monitoring System 1.0. Affected by this issue is some unknown functionality of the file /user/user/edit.php. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2018-18797. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2018-18799 | School Attendance Monitoring System 1.0 controller.php?action=photos cross-site request forgery (EDB-45726)
1 week 4 days ago
A vulnerability, which was classified as problematic, was found in School Attendance Monitoring System 1.0. This affects an unknown part of the file event/controller.php?action=photos. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2018-18799. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2018-18761 | SaltOS 3.1 r8126 User sql injection (EDB-45731)
1 week 4 days ago
A vulnerability was found in SaltOS 3.1 r8126 and classified as critical. Affected by this issue is some unknown functionality. The manipulation of the argument User leads to sql injection.
This vulnerability is handled as CVE-2018-18761. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2018-18763 | SaltOS 3.1 r8126 action2 sql injection (EDB-45733)
1 week 4 days ago
A vulnerability was found in SaltOS 3.1 r8126. It has been classified as critical. This affects an unknown part. The manipulation of the argument action2 leads to sql injection.
This vulnerability is uniquely identified as CVE-2018-18763. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2018-20166 | Rukovoditel 2.3.1 File Upload save Filename unrestricted upload (EDB-46011)
1 week 4 days ago
A vulnerability, which was classified as critical, was found in Rukovoditel 2.3.1. This affects an unknown part of the file index.php?module=configuration/save of the component File Upload. The manipulation as part of Filename leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2018-20166. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2018-18762 | SaltOS 3.1 r8126 information disclosure (EDB-45734)
1 week 4 days ago
A vulnerability classified as problematic was found in SaltOS 3.1 r8126. Affected by this vulnerability is an unknown functionality. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2018-18762. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2018-7841 | U.motion Builder 1.3.4 sql injection (ID 152862 / EDB-46846)
1 week 4 days ago
A vulnerability, which was classified as critical, has been found in U.motion Builder 1.3.4. Affected by this issue is some unknown functionality. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2018-7841. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Akira Ransomware targets SonicWall VPNs in likely zero-day attacks
1 week 4 days ago
Akira ransomware targets fully patched SonicWall VPNs in suspected zero-day attacks, with multiple intrusions seen in late July 2025. Arctic Wolf Labs researchers reported that Akira ransomware is exploiting SonicWall SSL VPNs in a likely zero-day attack, targeting even fully patched devices. Arctic Wolf Labs observed multiple intrusions via VPN access in late July 2025. […]
Pierluigi Paganini
10 Best HIPAA Compliance Software & Solutions Providers in 2025
1 week 4 days ago
In the rapidly evolving healthcare landscape of 2025, ensuring compliance with the Health Insurance Portability and Accountability Act (HIPAA) is more critical than ever. The increasing reliance on digital health records, telehealth, and other technological advancements has created a complex environment where data security and patient privacy are paramount. To address these challenges, a new […]
The post 10 Best HIPAA Compliance Software & Solutions Providers in 2025 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CISO Advisory
CVE-2024-26718 | Linux Kernel up to 6.1.78/6.6.17/6.7.5 dm-crypt/dm-verity tasklet_action_common memory corruption (Nessus ID 213359 / WID-SEC-2024-0773)
1 week 4 days ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.1.78/6.6.17/6.7.5. Affected by this issue is the function tasklet_action_common of the component dm-crypt/dm-verity. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2024-26718. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-26715 | Linux Kernel up to 5.15.148/6.1.78/6.6.17/6.7.5 usb dwc3_gadget_suspend null pointer dereference (WID-SEC-2024-0773)
1 week 4 days ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 5.15.148/6.1.78/6.6.17/6.7.5. This affects the function dwc3_gadget_suspend of the component usb. The manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2024-26715. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-26716 | Linux Kernel up to 6.6.17/6.7.5 USB update_port_device_state null pointer dereference (ed85777c640c/465b545d1d7e/12783c0b9e2c / WID-SEC-2024-0773)
1 week 4 days ago
A vulnerability was found in Linux Kernel up to 6.6.17/6.7.5. It has been rated as critical. Affected by this issue is the function update_port_device_state of the component USB. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2024-26716. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com