Aggregator
Cyera融资5.4亿美元,估值翻番,致力于人工智能数据保护
2 months ago
安全客
Belarusian hackers taunt Kaspersky over report detailing their attacks
2 months ago
A recent Kaspersky report offers a rare glimpse into the alleged arsenal of politically motivated hackers waging a digital war against authoritarian regimes in Russia and Belarus.
CVE-2025-49190 | SICK Field Analytics server-side request forgery
2 months ago
A vulnerability classified as critical was found in SICK Field Analytics. This vulnerability affects unknown code. The manipulation leads to server-side request forgery.
This vulnerability was named CVE-2025-49190. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-49188 | SICK Field Analytics URL Parameter get request method with sensitive query strings
2 months ago
A vulnerability classified as problematic has been found in SICK Field Analytics. This affects an unknown part of the component URL Parameter Handler. The manipulation leads to use of get request method with sensitive query strings.
This vulnerability is uniquely identified as CVE-2025-49188. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-49186 | SICK Field Analytics/Media Server cross site scripting (EUVD-2025-18188)
2 months ago
A vulnerability was found in SICK Field Analytics and Media Server. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-49186. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-49184 | SICK Field Analytics Setting information disclosure
2 months ago
A vulnerability was found in SICK Field Analytics. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Setting Handler. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2025-49184. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-49182 | SICK Media Server up to 1.4 authorization
2 months ago
A vulnerability was found in SICK Media Server up to 1.4. It has been classified as problematic. Affected is an unknown function. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2025-49182. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-49189 | SICK Media Server up to 1.4 cookie httponly flag (EUVD-2025-18180)
2 months ago
A vulnerability was found in SICK Media Server up to 1.4 and classified as problematic. This issue affects some unknown processing. The manipulation leads to cookie without 'httponly' flag.
The identification of this vulnerability is CVE-2025-49189. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
黑客通过恶意简历瞄准求职者
2 months ago
安全客
CVE-2025-49185 | SICK Field Analytics Dashboard Widget Transform cross site scripting
2 months ago
A vulnerability has been found in SICK Field Analytics and classified as problematic. This vulnerability affects the function Transform of the component Dashboard Widget. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-49185. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-49187 | SICK Field Analytics Failed Login observable response discrepancy
2 months ago
A vulnerability, which was classified as problematic, was found in SICK Field Analytics. This affects an unknown part of the component Failed Login Handler. The manipulation leads to observable response discrepancy.
This vulnerability is uniquely identified as CVE-2025-49187. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-49191 | SICK Field Analytics iFrame Widget ui layer
2 months ago
A vulnerability, which was classified as problematic, has been found in SICK Field Analytics. Affected by this issue is some unknown functionality of the component iFrame Widget. The manipulation leads to improper restriction of rendered ui layers.
This vulnerability is handled as CVE-2025-49191. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-9512 | GitLab Enterprise Edition up to 17.10.7/17.11.3/18.0.1 toctou (Issue 497748 / EUVD-2024-54676)
2 months ago
A vulnerability classified as problematic was found in GitLab Enterprise Edition up to 17.10.7/17.11.3/18.0.1. Affected by this vulnerability is an unknown functionality. The manipulation leads to time-of-check time-of-use.
This vulnerability is known as CVE-2024-9512. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-49183 | SICK Media Server REST API cleartext transmission
2 months ago
A vulnerability classified as problematic has been found in SICK Media Server. Affected is an unknown function of the component REST API. The manipulation leads to cleartext transmission of sensitive information.
This vulnerability is traded as CVE-2025-49183. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
微软修补被阿联酋黑客利用的零日漏洞
2 months ago
安全客
CVE-2025-49181 | SICK SICK Media Server API Endpoint authorization
2 months ago
A vulnerability was found in SICK SICK Media Server. It has been rated as critical. This issue affects some unknown processing of the component API Endpoint. The manipulation leads to missing authorization.
The identification of this vulnerability is CVE-2025-49181. The attack may be initiated remotely. There is no exploit available.
vuldb.com
Multiple GitLab Vulnerabilities Allow Attackers to Achieve Complete Account Takeover
2 months ago
A series of critical security vulnerabilities across GitLab Community Edition (CE) and Enterprise Edition (EE) platforms that could enable attackers to achieve complete account takeover and compromise entire development infrastructures. The company released emergency patch versions 18.0.2, 17.11.4, and 17.10.8 to address ten distinct security flaws, with several carrying high-severity CVSS scores above 8.0. These […]
The post Multiple GitLab Vulnerabilities Allow Attackers to Achieve Complete Account Takeover appeared first on Cyber Security News.
Guru Baran
The $200,000 Zoom call
2 months ago
A crypto CEO shared his screen. What happened next unraveled his digital life.
西门子能源紧急警报:专用 5G 核心中的关键漏洞 (CVSS 9.9) 暴露了敏感数据!
2 months ago
安全客