Aggregator
CVE-2024-46722 | Linux Kernel up to 6.10.8 AMD GPU mc_data out-of-bounds (Nessus ID 208053 / WID-SEC-2024-2173)
CVE-2024-46723 | Linux Kernel up to 6.10.8 AMD GPU ucode out-of-bounds (Nessus ID 208053 / WID-SEC-2024-2173)
CVE-2024-46717 | Linux Kernel up to 6.1.108/6.6.49/6.10.8 mlx5e_handle_rx_cqe_mpwrq_shampo privilege escalation (Nessus ID 208099 / WID-SEC-2024-2173)
CVE-2024-46718 | Linux Kernel up to 6.10.8 usable_size assertion (bb706e92c87b/6d3581edffea / Nessus ID 212724)
CVE-2024-46719 | Linux Kernel up to 6.10.8 typec ucsi_register_altmode null pointer dereference (Nessus ID 208053 / WID-SEC-2024-2173)
CVE-2024-46720 | Linux Kernel up to 6.1.108/6.6.49/6.10.8 AMD GPU null pointer dereference (Nessus ID 208099 / WID-SEC-2024-2173)
CVE-2024-46716 | Linux Kernel up to 6.1.108/6.6.49/6.10.8 altera-msgdma msgdma_free_descriptor privilege escalation (Nessus ID 208099 / WID-SEC-2024-2173)
CVE-2024-46715 | Linux Kernel up to 6.1.108/6.6.49/6.10.8 driver iio_info null pointer dereference (Nessus ID 208099 / WID-SEC-2024-2173)
CVE-2024-46714 | Linux Kernel up to 6.10.8 AMD Display wbscl_set_scaler_filter null pointer dereference (Nessus ID 208053 / WID-SEC-2024-2173)
CVE-2025-6043 | Malcure Malware Scanner Plugin up to 16.8 on WordPress wpmr_delete_file denial of service (EUVD-2025-21581)
CVE-2025-7359 | Counter Live Visitors for WooCommerce Plugin up to 1.3.6 on WordPress wcvisitor_get_block denial of service (EUVD-2025-21584)
CVE-2025-2800 | WP Event Manager Plugin up to 3.1.50 on WordPress organizer_name cross site scripting
CVE-2025-5843 | Brandfolder Plugin up to 5.0.19 on WordPress ID cross site scripting (EUVD-2025-21583)
CVE-2025-5845 | Affiliate Reviews Plugin up to 1.0.6 on WordPress numColumns cross site scripting (EUVD-2025-21582)
CVE-2025-6747 | Avada Fusion Builder Plugin up to 3.12.1 on WordPress Shortcode fusion_map cross site scripting (EUVD-2025-21580)
CVE-2025-5284 | Master Addons Plugin up to 2.0.8.2 on WordPress cross site scripting
Vim Command Line Text Editor Vulnerability Let Attackers Overwrite Sensitive Files
A critical security vulnerability has been discovered in Vim, the popular open-source command line text editor used by millions of developers worldwide. The vulnerability, designated as CVE-2025-53906, affects the zip.vim plugin and enables attackers to overwrite arbitrary files through specially crafted zip archives. Key Takeaways1. CVE-2025-53906, Vim's zip.vim plugin is vulnerable to path traversal attacks […]
The post Vim Command Line Text Editor Vulnerability Let Attackers Overwrite Sensitive Files appeared first on Cyber Security News.
Gmail Message Exploit Triggers Code Execution in Claude, Bypassing Protections
A cybersecurity researcher has demonstrated how a carefully crafted Gmail message can trigger code execution through Claude Desktop, Anthropic’s AI assistant application, highlighting a new class of vulnerabilities in AI-powered systems that don’t require traditional software flaws. The exploit leverages the Model Context Protocol (MCP), which allows Claude to interact with various applications and services. […]
The post Gmail Message Exploit Triggers Code Execution in Claude, Bypassing Protections appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.