Aggregator
红队视角:Gitlab已知攻击面与潜在风险
11 months 3 weeks ago
1nhann
CVE-2025-2588 | Hercules Augeas 1.14.1 src/fa.c re_case_expand re null pointer dereference (Issue 852 / Nessus ID 233483)
11 months 3 weeks ago
A vulnerability has been found in Hercules Augeas 1.14.1 and classified as problematic. This vulnerability affects the function re_case_expand of the file src/fa.c. The manipulation of the argument re leads to null pointer dereference.
This vulnerability was named CVE-2025-2588. Attacking locally is a requirement. Furthermore, there is an exploit available.
vuldb.com
Разведка США: Китай заложил "закладки" в американские энергосистемы
11 months 3 weeks ago
ATA-2025 раскрывает кибершаги на случай войны за Тайвань.
【安全圈】数据罗生门:600 万用户泄露信息被证真实,甲骨文坚称未被入侵
11 months 3 weeks ago
关键词数据泄露科技媒体 bleepingcomputer 昨日(3 月 26 日)发布博文,尽管甲骨文(Ora
【安全圈】黑客组织攻击纽约大学官网,泄露 300 万学生敏感信息
11 months 3 weeks ago
关键词黑客近日,一个自称为“Computer Niggy Exploitation”的黑客组织对美国著名高等学
【安全圈】王者荣耀崩了,官方致歉:问题已修复,补偿方案公布
11 months 3 weeks ago
关键词网络崩溃3月28日晚,“王者荣耀崩了”登上热搜,引发网友热议。
Babuk Locker 2.0 vs Seceon Platform: MITRE ATT&CK Mapping and Early-Stage Detection & Remediation
11 months 3 weeks ago
Overview of Babuk Locker 2.0 Babuk Locker 2.0 is a ransomware strain that employs double extortion, where attackers encrypt victim files and exfiltrate sensitive data for ransom. It targets organizations by exploiting RDP vulnerabilities, unpatched systems, weak credentials, and phishing attacks. MITRE ATT&CK Mapping of Babuk Locker 2.0 & Seceon’s Early Detection & Remediation MITRE
The post Babuk Locker 2.0 vs Seceon Platform: MITRE ATT&CK Mapping and Early-Stage Detection & Remediation appeared first on Seceon Inc.
The post Babuk Locker 2.0 vs Seceon Platform: MITRE ATT&CK Mapping and Early-Stage Detection & Remediation appeared first on Security Boulevard.
Chandra Shekhar Pandey
CVE-2025-2840 | DAP to Autoresponders Email Syncing Plugin up to 1.0 on WordPress phpinfo.php information disclosure
11 months 3 weeks ago
A vulnerability classified as problematic has been found in DAP to Autoresponders Email Syncing Plugin up to 1.0 on WordPress. This affects an unknown part of the file phpinfo.php. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2025-2840. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-2006 | WP Zone Inline Image Upload for BBPress Plugin up to 1.1.19 on WordPress unrestricted upload
11 months 3 weeks ago
A vulnerability classified as critical was found in WP Zone Inline Image Upload for BBPress Plugin up to 1.1.19 on WordPress. This vulnerability affects unknown code. The manipulation leads to unrestricted upload.
This vulnerability was named CVE-2025-2006. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-2249 | SoJ SoundSlides Plugin up to 1.2.2 on WordPress soj_soundslides_options_subpanel unrestricted upload
11 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in SoJ SoundSlides Plugin up to 1.2.2 on WordPress. This issue affects the function soj_soundslides_options_subpanel. The manipulation leads to unrestricted upload.
The identification of this vulnerability is CVE-2025-2249. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-2803 | So-Called Air Quotes Plugin up to 0.1 on WordPress Shortcode do_shortcode improper authentication
11 months 3 weeks ago
A vulnerability, which was classified as critical, was found in So-Called Air Quotes Plugin up to 0.1 on WordPress. Affected is the function do_shortcode of the component Shortcode Handler. The manipulation leads to improper authentication.
This vulnerability is traded as CVE-2025-2803. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-2266 | Checkout Mestres do WP for WooCommerce Plugin up to 8.7.5 on WordPress cwmpUpdateOptions access control
11 months 3 weeks ago
A vulnerability has been found in Checkout Mestres do WP for WooCommerce Plugin up to 8.7.5 on WordPress and classified as critical. Affected by this vulnerability is the function cwmpUpdateOptions. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2025-2266. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-13557 | United Themes Shortcodes Plugin up to 5.1.6 on WordPress do_shortcode code injection
11 months 3 weeks ago
A vulnerability was found in United Themes Shortcodes Plugin up to 5.1.6 on WordPress and classified as critical. Affected by this issue is the function do_shortcode. The manipulation leads to code injection.
This vulnerability is handled as CVE-2024-13557. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-11180 | xpeedstudio ElementsKit Elementor addons Plugin up to 3.4.7 on WordPress Countdown Timer Widget ekit_countdown_timer_title cross site scripting
11 months 3 weeks ago
A vulnerability was found in xpeedstudio ElementsKit Elementor addons Plugin up to 3.4.7 on WordPress. It has been classified as problematic. This affects an unknown part of the component Countdown Timer Widget. The manipulation of the argument ekit_countdown_timer_title leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-11180. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-31810 | Totolink EX200 4.0.3c.7646_B20201211 /etc/shadow.sample hard-coded password
11 months 3 weeks ago
A vulnerability classified as very critical has been found in Totolink EX200 4.0.3c.7646_B20201211. Affected is an unknown function of the file /etc/shadow.sample. The manipulation leads to use of hard-coded password.
This vulnerability is traded as CVE-2024-31810. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-3822 | Base64 Encoder Decoder Plugin up to 0.9.2 on WordPress cross site scripting
11 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Base64 Encoder Decoder Plugin up to 0.9.2 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-3822. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-27377 | Samsung Exynos 1330 slsi_nan_get_security_info_nl heap-based overflow
11 months 3 weeks ago
A vulnerability classified as critical was found in Samsung Exynos 980, Exynos 850, Exynos 1280, Exynos 1380 and Exynos 1330. Affected by this vulnerability is the function slsi_nan_get_security_info_nl. The manipulation leads to heap-based buffer overflow.
This vulnerability is known as CVE-2024-27377. An attack has to be approached locally. There is no exploit available.
vuldb.com
CVE-2024-27379 | Samsung Exynos 1330 slsi_nan_subscribe_get_nl_params heap-based overflow
11 months 3 weeks ago
A vulnerability was found in Samsung Exynos 980, Exynos 850, Exynos 1280, Exynos 1380 and Exynos 1330. It has been rated as critical. Affected by this issue is the function slsi_nan_subscribe_get_nl_params. The manipulation leads to heap-based buffer overflow.
This vulnerability is handled as CVE-2024-27379. Attacking locally is a requirement. There is no exploit available.
vuldb.com
CVE-2024-27814 | Apple watchOS up to 10.4 Contact Information information disclosure
11 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Apple watchOS up to 10.4. Affected by this issue is some unknown functionality of the component Contact Information Handler. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2024-27814. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com