Aggregator
网络安全信息与动态周报2025年第12期(3月17日-3月23日)
11 months 4 weeks ago
分享一篇文章。
【漏洞通告】Vite 访问控制错误漏洞(CVE-2025-30208)
11 months 4 weeks ago
【漏洞通告】Ingress NGINX Controller 远程代码执行漏洞(CVE-2025-1974)
11 months 4 weeks ago
Тёмная сторона DeepSeek: один неверный клик в поиске превращается в ловушку
11 months 4 weeks ago
Замаскированный троян атакует пользователей.
喜报 |恭喜本刊20位编委上榜2024“中国高被引学者” 榜单
11 months 4 weeks ago
喜报 |恭喜本刊20位编委上榜2024“中国高被引学者” 榜单
11 months 4 weeks ago
喜报 |恭喜本刊20位编委上榜2024“中国高被引学者” 榜单
11 months 4 weeks ago
喜报 |恭喜本刊20位编委上榜2024“中国高被引学者” 榜单
11 months 4 weeks ago
喜报 |恭喜本刊20位编委上榜2024“中国高被引学者” 榜单
11 months 4 weeks ago
喜报 |恭喜本刊20位编委上榜2024“中国高被引学者” 榜单
11 months 4 weeks ago
喜报 |恭喜本刊20位编委上榜2024“中国高被引学者” 榜单
11 months 4 weeks ago
CVE-2025-2685 | TablePress Plugin up to 3.0.4 on WordPress cross site scripting
11 months 4 weeks ago
A vulnerability was found in TablePress Plugin up to 3.0.4 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-2685. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-2837 | Silicon Labs Gecko OS 1.0.46 HTTP Request stack-based overflow (ZDI-24-871)
11 months 4 weeks ago
A vulnerability, which was classified as very critical, was found in Silicon Labs Gecko OS 1.0.46. Affected is an unknown function of the component HTTP Request Handler. The manipulation leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2025-2837. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-20232 | Splunk Enterprise/Cloud Platform Saved Search /app/search/search s information disclosure (SVD-2025-0304 / Nessus ID 233366)
11 months 4 weeks ago
A vulnerability was found in Splunk Enterprise and Cloud Platform. It has been rated as problematic. This issue affects some unknown processing of the file /app/search/search of the component Saved Search Handler. The manipulation of the argument s leads to information disclosure.
The identification of this vulnerability is CVE-2025-20232. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-20228 | Splunk Enterprise/Cloud Platform App Key Value Store cross-site request forgery (SVD-2025-0303 / Nessus ID 233364)
11 months 4 weeks ago
A vulnerability was found in Splunk Enterprise and Cloud Platform. It has been classified as problematic. Affected is an unknown function of the component App Key Value Store. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2025-20228. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45353 | Xiaomi Quick App Framework 1.30.2.1 origin validation
11 months 4 weeks ago
A vulnerability was found in Xiaomi Quick App Framework 1.30.2.1 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to origin validation error.
This vulnerability is handled as CVE-2024-45353. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-45354 | Xiaomi Shop Application origin validation
11 months 4 weeks ago
A vulnerability was found in Xiaomi Shop Application. It has been classified as problematic. This affects an unknown part. The manipulation leads to origin validation error.
This vulnerability is uniquely identified as CVE-2024-45354. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-45355 | Xiaomi Phone Framework missing authentication
11 months 4 weeks ago
A vulnerability was found in Xiaomi Phone Framework. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to missing authentication.
This vulnerability was named CVE-2024-45355. Attacking locally is a requirement. There is no exploit available.
vuldb.com
Advanced CoffeeLoader Malware Evades Security to Deliver Rhadamanthys Shellcode
11 months 4 weeks ago
Security researchers at Zscaler ThreatLabz have identified a new sophisticated malware family called CoffeeLoader, which emerged around September 2024. This advanced loader employs numerous techniques to bypass security solutions and evade detection while delivering second-stage payloads, particularly the Rhadamanthys stealer. CoffeeLoader utilizes a specialized packer named Armoury that leverages the GPU to execute code, hindering […]
The post Advanced CoffeeLoader Malware Evades Security to Deliver Rhadamanthys Shellcode appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Aman Mishra