Aggregator
CVE-2020-7533 | Schneider Electric Modicon Quantum/ModiconPremium Legacy Communication Module credentials management (SEVD-2020-287-01)
CVE-2024-13915 | Ulefone/Krüger&Matz com.pri.factorytest up to 1.0 improper export of android application components
CVE-2024-13916 | Kruger&Matz com.pri.applock 13 query exposure of sensitive system information to an unauthorized control sphere
CVE-2024-13917 | Kruger&Matz com.pri.applock 13 com.pri.applock.LockUI improper export of android application components
CVE-2025-30507 | CyberData 011209 SIP Emergency Intercom prior 22.0.1 sql injection (icsa-25-155-01 / EUVD-2025-17582)
CVE-2025-30183 | CyberData 011209 SIP Emergency Intercom prior 22.0.1 insufficiently protected credentials (icsa-25-155-01 / EUVD-2025-17581)
CVE-2025-5901 | TOTOLINK T10 4.1.8cu.5207 POST Request /cgi-bin/cstecgi.cgi UploadCustomModule File buffer overflow (EUVD-2025-17591)
CVE-2025-5902 | TOTOLINK T10 4.1.8cu.5207 POST Request /cgi-bin/cstecgi.cgi setUpgradeFW slaveIpList buffer overflow (EUVD-2025-17589)
CVE-2025-5903 | TOTOLINK T10 4.1.8cu.5207 POST Request /cgi-bin/cstecgi.cgi setWiFiAclRules desc buffer overflow (EUVD-2025-17612)
CVE-2025-5904 | TOTOLINK T10 4.1.8cu.5207 POST Request /cgi-bin/cstecgi.cgi setWiFiMeshName device_name buffer overflow (EUVD-2025-17609)
CVE-2024-2318 | ZKTeco ZKBio Media 2.0.0_x64_2024-01-29-1028 Service Port 9999 /pro/common/download fileName path traversal (EUVD-2024-27273)
CVE-2024-6807 | SourceCodester Student Study Center Desk Management System 1.0 HTTP POST Request Users.php?f=save firstname/middlename/lastname/username cross site scripting (EUVD-2024-48012)
Unpatched Wazuh servers targeted by Mirai botnets (CVE-2025-24016)
Two Mirai botnets are exploiting a critical remote code execution vulnerability (CVE-2025-24016) in the open-source Wazuh XDR/SIEM platform, Akamai researchers have warned. What is Wazuh? Wazuh is a popular open-source security information and event management (SIEM) and extended detection and response (XDR) solution that’s widely used for host-based intrusion detection, log analysis, file integrity monitoring, and more. It’s core components are: Wazuh Manager (server component), which analyzes data and triggers alerts. Made to be installed … More →
The post Unpatched Wazuh servers targeted by Mirai botnets (CVE-2025-24016) appeared first on Help Net Security.
报名 | 美团技术沙龙第85期【AI+安全:智能技术在安全领域的应用探索】
Malicious Actors Exploit SoraAI’s Popularity & GitHub to Distribute Malware
Threat actors are leveraging the growing popularity of OpenAI’s Sora, a cutting-edge video generation model, to distribute malicious software. Disguised as a legitimate shortcut file named “SoraAI.lnk,” this information-stealing malware mimics the branding of Sora to trick users into initiating a multi-stage attack chain. Deceptive Tactics Target OpenAI’s Sora Brand First reported on VirusTotal from […]
The post Malicious Actors Exploit SoraAI’s Popularity & GitHub to Distribute Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.