Aggregator
CVE-2025-43862 | langgenius dify up to 0.6.11 Role-Based Access Control access control (GHSA-6pw4-jqhv-3626)
CVE-2025-32432 | Craft CMS up to 3.9.14/4.14.14/5.6.16 code injection (GHSA-f3gw-9ww9-jmc3)
CVE-2025-3645 | Moodle up to 4.1.17/4.3.11/4.4.7/4.5.3 Messaging Web Service authorization
CVE-2024-56156 | halo-dev halo up to 2.20.12 cross site scripting (GHSA-99mc-ch53-pqh9)
CVE-2025-3644 | Moodle up to 4.1.17/4.3.11/4.4.7/4.5.3 Course Section authorization
CVE-2025-28076 | EasyVirt DCScope/CO2Scope sql injection
CVE-2025-3935 | ConnectWise ScreenConnect up to 25.2.3 ASP.NET Web Forms code injection
CVE-2025-3928 | Commvault Web Server up to 11.20.216/11.28.140/11.32.88/11.36.45 on Windows/Linux Remote Code Execution
CVE-2022-4946 | Frontend Post WordPress Plugin up to 2.8.4 on WordPress Shortcode Attribute redirect
CVE-2023-2337 | ConvertKit Plugin up to 2.2.0 on WordPress Attribute cross site scripting
CVE-2023-2224 | 10Web SEO Plugin up to 1.2.6 on WordPress Setting cross site scripting
CVE-2023-2571 | Quiz Maker Plugin 6.2.0.9/6.3.9.5 on WordPress Attribute cross site scripting
CVE-2023-32766 | Gitpod 0.6.0/2022.11.2.16 Protocol cross site scripting
CVE-2023-2572 | Survey Maker Plugin up to 3.4.6 on WordPress Attribute cross site scripting
Alleged Sale of Data from an Unknown Cosmetics Store in Poland
BSidesLV24 – Ground Truth – ZERO-RULES Alert Contextualizer & Correlator
Author/Presenter: Ezz Tahoun
Our sincere appreciation to BSidesLV, and the Presenters/Authors for publishing their erudite Security BSidesLV24 content. Originating from the conference’s events located at the Tuscany Suites & Casino; and via the organizations YouTube channel.
The post BSidesLV24 – Ground Truth – ZERO-RULES Alert Contextualizer & Correlator appeared first on Security Boulevard.
ADR vs EDR and WAF | Application Security Tool Comparison | Contrast Security
New research demonstrates cyberattacks on the application layer often evade the most common tools, Endpoint Detection and Response (EDR) and web application firewalls (WAFs). Contrast Labs spent several weeks testing several attack methods to determine whether WAFs or EDR solutions stop and/or catch most damaging software attacks.
The post ADR vs EDR and WAF | Application Security Tool Comparison | Contrast Security appeared first on Security Boulevard.