Aggregator
Akira
11 months 1 week ago
cohenido
Submit #525101: WonderCMS 3.5.9 remote code execution [Accepted]
11 months 1 week ago
Submit #525101 / VDB-303014
cc1110
The Reality Behind Security Control Failures—And How to Prevent Them
11 months 1 week ago
Most orgs only discover their security controls failed after a breach. With OnDefend's continuous validation, you can test, measure, and prove your defenses work—before attackers exploit blind spots. [...]
Sponsored by OnDefend
How an Interdiction Mindset Can Help Win War on Cyberattacks
11 months 1 week ago
The US military and law enforcement learned to outthink insurgents. It's time for cybersecurity to learn to outsmart and outmaneuver threat actors with the same framework.
Mike McNerney
Counterfeit Android devices found preloaded with Triada malware
11 months 1 week ago
A new version of the Triada trojan has been discovered preinstalled on thousands of new Android devices, allowing threat actors to steal data as soon as they are set up. [...]
Bill Toulas
Vulnerability impacting CrushFTP
11 months 1 week ago
Canadian Centre for Cyber Security
Steam возглавил рейтинг брендов-приманок для фишеров в 2025 году
11 months 1 week ago
Миллионы геймеров получают фальшивые уведомления, ведущие к краже данных.
Google Fixed Cloud Run Vulnerability Allowing Unauthorized Image Access via IAM Misuse
11 months 1 week ago
Cybersecurity researchers have disclosed details of a now-patched privilege escalation vulnerability in Google Cloud Platform (GCP) Cloud Run that could have allowed a malicious actor to access container images and even inject malicious code.
"The vulnerability could have allowed such an identity to abuse its Google Cloud Run revision edit permissions in order to pull private Google Artifact
The Hacker News
U.S. CISA adds Apache Tomcat flaw to its Known Exploited Vulnerabilities catalog
11 months 1 week ago
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apache Tomcat flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Apache Tomcat path equivalence vulnerability, tracked as CVE-2025-24813, to its Known Exploited Vulnerabilities (KEV) catalog. The Apache Tomcat vulnerability CVE-2025-24813 was recently disclosed and is being actively exploited just 30 […]
Pierluigi Paganini
Bybit Heist Fuels Record Crypto-Theft Surge, Says CertiK
11 months 1 week ago
Hackers stole $1.67bn of cryptocurrencies in the first quarter of 2025, a 303% increase
CVE-2025-3122 | WebAssembly wabt 1.0.36 binary-reader-interp.cc BeginFunctionBody null pointer dereference (Issue 2565)
11 months 1 week ago
A vulnerability classified as problematic was found in WebAssembly wabt 1.0.36. Affected by this vulnerability is the function BinaryReaderInterp::BeginFunctionBody of the file src/interp/binary-reader-interp.cc. The manipulation leads to null pointer dereference.
This vulnerability is known as CVE-2025-3122. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-3121 | PyTorch 2.6.0 torch.jit.jit_module_from_flatbuffer memory corruption (Issue 149800)
11 months 1 week ago
A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2025-3121. Local access is required to approach this attack. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-3120 | SourceCodester Apartment Visitors Management System 1.0 /add-apartment.php apartmentno sql injection
11 months 1 week ago
A vulnerability was found in SourceCodester Apartment Visitors Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /add-apartment.php. The manipulation of the argument apartmentno leads to sql injection.
The identification of this vulnerability is CVE-2025-3120. The attack may be initiated remotely. Furthermore, there is an exploit available.
Other parameters might be affected as well.
vuldb.com
CVE-2025-3119 | SourceCodester Online Tutor Portal 1.0 manage_course.php ID sql injection
11 months 1 week ago
A vulnerability was found in SourceCodester Online Tutor Portal 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /tutor/courses/manage_course.php. The manipulation of the argument ID leads to sql injection.
This vulnerability was named CVE-2025-3119. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-3118 | SourceCodester Online Tutor Portal 1.0 view_course.php ID sql injection
11 months 1 week ago
A vulnerability was found in SourceCodester Online Tutor Portal 1.0. It has been classified as critical. This affects an unknown part of the file /tutor/courses/view_course.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-3118. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #525091: https://github.com/WebAssembly/wabt wabt 1.0.36 NULL Pointer Dereference [Accepted]
11 months 1 week ago
Submit #525091 / VDB-303013
Travelers Cyber Risk Services reduces the risk of a cyberattack
11 months 1 week ago
The Travelers Companies announced Travelers Cyber Risk Services, a suite of capabilities added to all cyber liability policies designed to help lower both the risk of a cyberattack and the cost to recover from one. In addition to always-on threat monitoring and tailored alerts, key benefits of Travelers Cyber Risk Services include: Cyber Risk Dashboard: This 24/7 tool gives consumers the ability to monitor risks and track progress over time, view customized recommendations ranked by … More →
The post Travelers Cyber Risk Services reduces the risk of a cyberattack appeared first on Help Net Security.
Industry News
Submit #525049: pytorch pytorch (in torch.jit.jit_module_from_flatbuffer) torch 2.6.0 Memory Leak [Accepted]
11 months 1 week ago
Submit #525049 / VDB-303012
Default436352
Submit #524991: SourceCodester Apartment Visitors Management System 1.0 SQL Injection [Accepted]
11 months 1 week ago
Submit #524991 / VDB-303011
wanglun