Aggregator
CVE-2006-5020 | SolidState ConfigureNewUserPage.class.php base_path privileges management (EDB-2413 / XFDB-29095)
CVE-2006-5020 | SolidState ConfigureNewUserReceiptPage.class.php base_path privileges management (EDB-2413 / XFDB-29095)
Apache mod_auth_openidc Flaw Lets Unauthenticated Users Access Protected Data
A critical flaw in Apache mod_auth_openidc (versions ≤2.4.16.10) allows unauthenticated attackers to bypass authentication and access protected resources. The bug, CVE-2025-31492, patched in version 2.4.16.11, affects systems using OIDCProviderAuthRequestMethod POST without an application-level gateway or load balancer. Technical Breakdown The vulnerability stems from improper handling of authentication requests when the POST method is configured. Under specific conditions: Attackers triggering a request […]
The post Apache mod_auth_openidc Flaw Lets Unauthenticated Users Access Protected Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2024-3247 | Xpdf up to 4.05 Object Stream stack-based overflow
CVE-2024-3248 | Xpdf up to 4.05 Attachment stack-based overflow
CVE-2024-3156 | Google Chrome up to 123.0.6312.86 V8 Remote Code Execution (ID 32913)
CVE-2024-24506 | Lime Survey Community Edition 5.3.32+220817 General Setting Administrator email address cross site scripting (Exploit 51926 / EDB-51926)
CVE-2024-2322 | WooCommerce Cart Abandonment Recovery Plugin up to 1.2.26 on WordPress Email Template cross-site request forgery
CVE-2024-3158 | Google Chrome up to 123.0.6312.86 Bookmarks use after free (FEDORA-2024-4d2d73ab31)
CVE-2024-3159 | Google Chrome up to 123.0.6312.86 V8 out-of-bounds (FEDORA-2024-4d2d73ab31 / Nessus ID 227934)
CVE-2023-34423 | AYS Pro Plugins Survey Maker Plugin up to 3.6.3 on WordPress cross site scripting
PipeMagic Trojan Exploits Windows Zero-Day Vulnerability to Deploy Ransomware
Tomcat 漏洞分析(CVE-2025-24813)
OpenSSL prepares for a quantum future with 3.5.0 release
The OpenSSL Project has released version 3.5.0 of its widely used open-source cryptographic library, introducing new features and notable changes that signal its evolution toward future-ready cryptography. This feature release includes support for post-quantum cryptography (PQC), server-side QUIC, and tighter control over TLS behavior. Default behaviors reworked OpenSSL 3.5.0 makes several potentially incompatible changes to default settings. Notably, the default encryption cipher for the req, cms, and smime command-line utilities has changed from the aging … More →
The post OpenSSL prepares for a quantum future with 3.5.0 release appeared first on Help Net Security.
Index Engines CyberSense 8.10 strengthens AI-driven cyber resilience
Index Engines announced CyberSense 8.10, fully integrated with Dell PowerProtect Cyber Recovery, which provides new capabilities to enhance cyber resilience and streamline recovery from ransomware attacks. CyberSense’s highly-trained AI ensures data integrity, empowering organizations to detect corruption from cyber threats and recover with confidence. With more than 1,500 global installations, CyberSense continues to lead the industry in ransomware detection. “As ransomware attacks continue to rise, organizations must ensure they have data integrity to enable fast … More →
The post Index Engines CyberSense 8.10 strengthens AI-driven cyber resilience appeared first on Help Net Security.
CISA Warns of CentreStack's Hard-Coded MachineKey Vulnerability Enabling RCE Attacks
PCI DSS 4.0: Time to Pay Up, Securely
PCI DSS 4.0 compliance raises the regulatory bar with stricter authentication, continuous monitoring and tighter third-party oversight.
The post PCI DSS 4.0: Time to Pay Up, Securely appeared first on Security Boulevard.