Aggregator
CVE-2012-5853 | AJAX Post Search Plugin up to 1.2 on WordPress cardoza_ajax_search.php the_search_function srch_txt sql injection
CVE-2011-5286 | Social Slider Plugin up to 7.4.1 on WordPress social-slider-2/ajax.php rA sql injection (EDB-17617)
CVE-2025-26986 | Pearl Plugin up to 3.4.8 on WordPress file inclusion
CVE-2016-11018 | Huge-IT gallery-images Plugin up to 1.8.9/1.9.0 on WordPress Header huge_it_image_gallery_ajax_callback Client-Ip/X-Forwarded-For sql injection
CVE-2023-50897 | Media File Renamer Plugin up to 5.7.7 on WordPress code injection
CVE-2022-2445 | Ultimate Member Plugin up to 2.5.0 on WordPress pack path traversal
New VanHelsing ransomware targets Windows, ARM, ESXi systems
CVE-2014-8739 | Creative Contact Form Plugin up to 1.0.0/2.0.1/6.4.4 on WordPress UploadHandler.php unrestricted upload (Exploit 35057 / EDB-35057)
CVE-2025-2748 | Kentico Xperience up to 13.0.178 File Upload cross site scripting
CVE-2025-2747 | Kentico Xperience up to 13.0.178 Sync Server improper authentication
CVE-2025-2746 | Kentico Xperience up to 13.0.172 Empty SHA1 Username improper authentication
CVE-2025-30163 | Cilium up to 1.16.7/1.17.1 fromNodes/toNodes authorization (GHSA-c6pf-2v8j-96mc)
CVE-2025-30162 | Cilium up to 1.15.14/1.16.7/1.17.1 authorization (GHSA-24qp-4xx8-3jvj)
CVE-2025-2749 | Kentico Xperience up to 13.0.178 Sync Server path traversal
FBI Warns of Document Converter Tools Due to Uptick in Scams
VanHelsing
Spit Happens: 23andMe is Bankrupt — Secure Your DNA Data NOW Already
Double hell-ix: Personal genomics firm tells customers your data is safe—but few will trust the loss-making biotech pioneer.
The post Spit Happens: 23andMe is Bankrupt — Secure Your DNA Data NOW Already appeared first on Security Boulevard.
Hackers Deploy Fake Semrush Ads to Steal Google Account Credentials
In a recent cybersecurity threat, hackers have been using fake Semrush ads to target Google account credentials. This campaign involves creating malicious ads that impersonate Semrush, a popular SEO and advertising platform used by many businesses, including 40% of Fortune 500 companies. The attackers aim to exploit the trust associated with Semrush to gain access […]
The post Hackers Deploy Fake Semrush Ads to Steal Google Account Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.