Aggregator
CVE-2025-0620 | Samba up to 4.21.5 Group Membership Change improper authentication (Nessus ID 237874)
CVE-2025-5779 | code-projects Patient Record Management System 1.0 /birthing.php itr_no/comp_id sql injection
CVE-2025-5782 | PHPGurukul Employee Record Management System 1.3 /resetpassword.php newpassword sql injection
CVE-2025-5791 | users Crate on Rust privileges assignment (EUVD-2025-16945)
CVE-2025-38002 | Linux Kernel up to 6.14.7 io_uring_show_fdinfo information disclosure
CVE-2025-41646 | Kunbus Revolution Pi Webstatus up to 2.4.5 type conversion (Kunbus-2025-000000 / EUVD-2025-17316)
CVE-2025-5806 | Jenkins Gatling Plugin 136.vb_9009b_3d33a_e Content-Security-Policy protection mechanism (EUVD-2025-17299 / Nessus ID 237910)
CVE-2024-13087 | QNAP QuRouter 2.4.3.103/2.4.4.106/2.4.5.032 QHora os command injection (qsa-25-15 / EUVD-2024-54651)
CVE-2024-13088 | QNAP QuRouter 2.4.3.103/2.4.4.106/2.4.5.032/2.4.6.028 QHora improper authentication (qsa-25-15 / EUVD-2024-54652)
CVE-2024-50406 | QNAP License Center up to 1.9.48 cross site scripting (qsa-25-11 / EUVD-2024-54654)
CVE-2025-5873 | eCharge Hardy Barth Salia PLCC 2.2.0 Web UI /firmware.php media unrestricted upload (EUVD-2025-17455)
基于RPC的计划任务维权分析学习
CVE-2005-4554 | DEV DEV web management system up to 1.5 Management System openforum.php target sql injection (EDB-1387 / XFDB-23898)
Roundcube RCE: Dark web activity signals imminent attacks (CVE-2025-49113)
With an exploit for a critical Roundcube vulnerability (CVE-2025-49113) being offered for sale on underground forums and a PoC exploit having been made public, attacks exploiting the flaw are incoming and possibly already happening. According to the Shadowserver Foundation, there is no lack of possible targets: around 84,000 internet-facing installations – predominantly in Europe, Asia, and North America – are still unpatched. What is Roundcube? Roundcube is a free and open-source web-based email client that’s … More →
The post Roundcube RCE: Dark web activity signals imminent attacks (CVE-2025-49113) appeared first on Help Net Security.
微软MSRC榜首赏金猎人带你来挖洞
Seraphic Security Unveils BrowserTotal™ – Free AI-Powered Browser Security Assessment for Enterprises
Seraphic Security Unveils BrowserTotal™ – Free AI-Powered Browser Security Assessment for Enterprises
Tel Aviv, Israel, 9th June 2025, CyberNewsWire
The post Seraphic Security Unveils BrowserTotal™ – Free AI-Powered Browser Security Assessment for Enterprises appeared first on Security Boulevard.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2025-32433 Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability
-
CVE-2024-42009 RoundCube Webmail Cross-Site Scripting Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
RSA Extends Reach of Passwordless Management Platform
RSA has updated its passwordless identity management platform to add support for desktops that are connected to the Microsoft Entra ID directory service.
The post RSA Extends Reach of Passwordless Management Platform appeared first on Security Boulevard.