Aggregator
CVE-2025-9495 | Viessmann Vitogate 2.1.3.0/3.0 Web Interface client-side enforcement of server-side security
CVE-2025-42907 | SAP BI Platform 2025/2027/ENTERPRISE 430 LogonToken server-side request forgery
CVE-2025-43806 | Liferay Portal/DXP REST API authorization
CVE-2025-43814 | Liferay Portal/DXP Password Reminder insertion of sensitive information into sent data
CVE-2025-43810 | Liferay Portal/DXP authorization
Hackers Exploit GitHub Notifications to Launch Phishing Attacks
Cybersecurity researchers have uncovered a new phishing campaign that exploits GitHub’s official notification system to deliver malicious links and credential-stealing payloads. By capitalizing on the trust that open-source contributors place in GitHub’s communication channels, cybercriminals are able to bypass traditional email filters and social engineering defenses. The campaign begins with an email that closely mimics […]
The post Hackers Exploit GitHub Notifications to Launch Phishing Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-26399 | SolarWinds Web Help Desk AjaxProxy deserialization
CVE-2025-9494 | Viessmann Vitogate 300 3.0.x /cgi-bin/vitogate.cgi popen form os command injection
CVE-2025-39872 | Linux Kernel up to 6.16.7/6.17-rc5 hsr hsr_get_port_ndev use after free
CVE-2025-39871 | Linux Kernel up to 6.6.106/6.12.47/6.16.7/6.17-rc5 dmaengine lib/refcount.c idxd_free reference count
CVE-2025-39870 | Linux Kernel up to ed2c66000aa64c0d2621864831f0d04c820a1441 dmaengine idxd_setup_wqs uninitialized pointer
CVE-2025-39869 | Linux Kernel up to 6.1.152/6.6.106/6.12.47/6.16.7/6.17-rc5 dmaengine edma_setup_from_hw memory corruption
CVE-2025-39867 | Linux Kernel up to 6.17-rc1 netfilter nft_set_pipapo null pointer dereference
CVE-2025-39874 | Linux Kernel up to 6.16.7/6.17-rc5 macsec netdevice.h denial of service
CVE-2025-39868 | Linux Kernel up to 6.16.7/6.17-rc5 erofs truncate_folio_batch_exceptionals infinite loop
CVE-2025-39873 | Linux Kernel up to 6.1.152/6.6.106/6.12.47/6.16.7/6.17-rc5 xcan_write_frame use after free
CVE-2025-59535 | dnnsoftware Dnn.Platform up to 10.0.x input validation (GHSA-wq2j-w9pm-7x2p)
Исследователь обнаружил «режима бога» в облаках Microsoft
Libraesva ESG Vulnerability Allows Attackers to Execute Malicious Commands
A critical command injection vulnerability in Libraesva ESG email security gateways has been discovered, allowing attackers to execute arbitrary commands through specially crafted compressed email attachments. The vulnerability, designated CVE-2025-59689, affects versions starting from 4.5 and has already been exploited by what appears to be a foreign state actor. Diagram showing how command injection attacks […]
The post Libraesva ESG Vulnerability Allows Attackers to Execute Malicious Commands appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.