Aggregator
CVE-2025-36023 | IBM Cloud Pak for Business Automation up to 24.0.0 IF005/24.0.1 IF002 authorization (EUVD-2025-23987)
Weekly Threat Landscape Digest – Week 32
This week’s cybersecurity overview reflects an evolving threat environment marked by new vulnerability disclosures, exploitation of existing weaknesses, and persistent […]
The post Weekly Threat Landscape Digest – Week 32 appeared first on HawkEye.
CVE-2025-8755 | macrozheng mall up to 1.0.3 com.macro.mall.portal.controller UmsMemberController.java detail orderId authorization (EUVD-2025-24050)
CVE-2020-9322 | Statamic Core up to 2.11.7 /users cross site scripting (EUVD-2020-30143)
CVE-2025-36119 | IBM i 7.3/7.4/7.5/7.6 Digital Certificate Manager for i authentication spoofing (EUVD-2025-23989)
Submit #624046: macrozheng mall 1.0.3 Missing Authorization [Accepted]
Submit #623902: A Java cms with SQL injection exists https://github.com/miansen/Roothub/tree/v2.5 2.5 SQL Injection [Duplicate]
CVE-2021-33096 | Intel 82599 Ethernet Controller denial of service (intel-sa-00571 / Nessus ID 245557)
CVE-2023-53120 | Linux Kernel up to 6.1.20/6.2.7 scsi memory leak (Nessus ID 245554)
CVE-2023-0136 | Google Chrome up to 108.0.5359.124 Fullscreen API Remote Code Execution (EUVD-2023-12226 / Nessus ID 245555)
CVE-2021-20292 | Linux Kernel up to 5.8 Nouveau DRM Subsystem nouveau_sgdma.c nouveau_sgdma_create_ttm use after free (Nessus ID 245558)
CVE-2021-46958 | Linux Kernel up to 5.10.35/5.11.19/5.12/5.12.2 btrfs /dev/mapper/error-test btrfs_sync_log use after free (Nessus ID 245559)
CVE-2023-2006 | Linux Kernel RxRPC race condition (Nessus ID 245560)
«Вымогатели неуязвимы?» Операция Checkmate разобрала BlackSuit по винтикам.
CVE-2023-41525 | Hospital Management System 4 patientsearch.php patient_contact sql injection
CVE-2023-41526 | Hospital Management System 4 func1.php password3 sql injection
CVE-2025-8729 | MigoXLab LMeterX 1.2.0 upload_service.py process_cert_files task_id path traversal (Issue 10)
CVE-2025-0913 | Google Go up to 1.23.9/1.24.3 File os.OpenFile symlink (Nessus ID 238043)
BSidesSF 2025: Using AI To Discover Silently Patched Vulnerabilities In Open Source
Creator/Author/Presenter: Mackenzie Jackson
Our deep appreciation to Security BSides - San Francisco and the Creators/Authors/Presenters for publishing their BSidesSF 2025 video content on YouTube. Originating from the conference’s events held at the lauded CityView / AMC Metreon - certainly a venue like no other; and via the organization's YouTube channel.
Additionally, the organization is welcoming volunteers for the BSidesSF Volunteer Force, as well as their Program Team & Operations roles. See their succinct BSidesSF 'Work With Us' page, in which, the appropriate information is to be had!
The post BSidesSF 2025: Using AI To Discover Silently Patched Vulnerabilities In Open Source appeared first on Security Boulevard.