Aggregator
抖音电商如何用扣子 Coze 打造 AI 客服?
2 months 4 weeks ago
倒计时3天|作品征集蓄力冲刺 别错过 iPhone 16、华为 mate 70、PS5等!
2 months 4 weeks ago
抖音电商如何用扣子 Coze 打造 AI 客服?
2 months 4 weeks ago
倒计时3天|作品征集蓄力冲刺 别错过 iPhone 16、华为 mate 70、PS5等!
2 months 4 weeks ago
抖音电商如何用扣子 Coze 打造 AI 客服?
2 months 4 weeks ago
EDRKillShifter: как один хакерский инструмент объединил 4 элитных банды вымогателей
2 months 4 weeks ago
Что скрывается за неожиданным сотрудничеством конкурирующих группировок?
CVE-2025-2027 | ASUS ASCI System Analysis Service double free
2 months 4 weeks ago
A vulnerability was found in ASUS ASCI. It has been rated as problematic. This issue affects some unknown processing of the component System Analysis Service. The manipulation leads to double free.
The identification of this vulnerability is CVE-2025-2027. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-1705 | tagDiv Composer Plugin up to 5.3 on WordPress td_ajax_get_views cross-site request forgery
2 months 4 weeks ago
A vulnerability was found in tagDiv Composer Plugin up to 5.3 on WordPress. It has been declared as problematic. This vulnerability affects the function td_ajax_get_views. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2025-1705. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-2815 | quyle91 Administrator Z Plugin up to 2025.03.24 on WordPress adminz_import_backup authorization
2 months 4 weeks ago
A vulnerability was found in quyle91 Administrator Z Plugin up to 2025.03.24 on WordPress. It has been classified as problematic. This affects the function adminz_import_backup. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2025-2815. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-2578 | Booking for Appointments and Events Calendar – Amelia Plugin wpAmeliaApiCall information disclosure
2 months 4 weeks ago
A vulnerability was found in Booking for Appointments and Events Calendar – Amelia Plugin up to 1.2.19 on WordPress and classified as problematic. Affected by this issue is the function wpAmeliaApiCall. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2025-2578. The attack may be launched remotely. There is no exploit available.
vuldb.com
Nine-Year-Old npm Packages Hijacked to Exfiltrate API Keys via Obfuscated Scripts
2 months 4 weeks ago
Cybersecurity researchers have discovered several cryptocurrency packages on the npm registry that have been hijacked to siphon sensitive information such as environment variables from compromised systems.
"Some of these packages have lived on npmjs.com for over 9 years, and provide legitimate functionality to blockchain developers," Sonatype researcher Ax Sharma said. "However, [...] the latest
The Hacker News
CVE-2025-2485 | Contact Form Drag and Drop Multiple File Upload for Contact Form 7 Plugin dnd_upload_cf7_upload deserialization
2 months 4 weeks ago
A vulnerability has been found in Contact Form Drag and Drop Multiple File Upload for Contact Form 7 Plugin up to 1.3.8.7 on WordPress and classified as critical. Affected by this vulnerability is the function dnd_upload_cf7_upload. The manipulation leads to deserialization.
This vulnerability is known as CVE-2025-2485. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-2074 | webfactory Advanced Google reCAPTCHA Plugin up to 1.29 on WordPress sSearch sql injection
2 months 4 weeks ago
A vulnerability, which was classified as critical, was found in webfactory Advanced Google reCAPTCHA Plugin up to 1.29 on WordPress. Affected is an unknown function. The manipulation of the argument sSearch leads to sql injection.
This vulnerability is traded as CVE-2025-2074. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-2328 | Contact Form Drag and Drop Multiple File Upload for Contact Form 7 Plugin Path Validation dnd_remove_uploaded_files unrestricted upload
2 months 4 weeks ago
A vulnerability, which was classified as critical, has been found in Contact Form Drag and Drop Multiple File Upload for Contact Form 7 Plugin up to 1.3.8.7 on WordPress. This issue affects the function dnd_remove_uploaded_files of the component Path Validation Handler. The manipulation leads to unrestricted upload.
The identification of this vulnerability is CVE-2025-2328. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-29306 | FoxCMS 1.2.5 Case Display Page index.html privilege escalation
2 months 4 weeks ago
A vulnerability classified as critical was found in FoxCMS 1.2.5. This vulnerability affects unknown code of the file index.html of the component Case Display Page. The manipulation leads to privilege escalation.
This vulnerability was named CVE-2025-29306. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-31092 | Ninja Click to Chat Plugin up to 2.3.4 on WordPress cross site scripting
2 months 4 weeks ago
A vulnerability classified as problematic has been found in Ninja Click to Chat Plugin up to 2.3.4 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-31092. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
Akira
2 months 4 weeks ago
cohenido
CVE-2025-31335 | Shibboleth OpenSAML C++ library up to 3.3.0 XML Signature signature verification
2 months 4 weeks ago
A vulnerability was found in Shibboleth OpenSAML C++ library up to 3.3.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component XML Signature Handler. The manipulation leads to improper verification of cryptographic signature.
This vulnerability is handled as CVE-2025-31335. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-30093 | HTCondor up to 23.0.21/23.10.21/24.0.5/24.6.0 improper authentication (HTCONDOR-2025-0001)
2 months 4 weeks ago
A vulnerability was found in HTCondor up to 23.0.21/23.10.21/24.0.5/24.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper authentication.
This vulnerability is known as CVE-2025-30093. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com