Aggregator
CVE-2021-26087 | Fortinet FortiWLC up to 8.3.3/8.4.2/8.4.8/8.5.3/8.6.0 Web Interface cross site scripting (FG-IR-20-137)
CVE-2019-15706 | Fortinet FortiProxy/FortiOS SSL VPN Portal cross site scripting (FG-IR-19-223)
CVE-2019-17659 | Fortinet FortiSIEM 5.2.6 Firmware Image hard-coded credentials (FG-IR-19-296)
CVE-2020-29010 | Fortinet FortiOS up to 6.0.10/6.2.4 CLI information disclosure (FG-IR-20-103)
CVE-2021-22126 | Fortinet FortiWLC up to 8.2.7/8.3.3/8.4.2/8.4.8/8.5.2 Managed Access Point hard-coded password (FG-IR-20-147)
CVE-2025-27102 | obiba agate up to 3.2.x cross site scripting
CVE-2025-29786 | expr-lang expr up to 1.16.x on Go allocation of resources
CVE-2021-32584 | Fortinet FortiWLC up to 8.6.0 Web Management CGI access control (FG-IR-20-138)
Microsoft: March Windows updates mistakenly uninstall Copilot
Bedrock Security’s metadata lake technology strengthens data security
Bedrock Security is declaring an end to data security without data visibility with the launch of its metadata lake technology — a centralized repository powering the patented Bedrock Platform. It provides continuous visibility across enterprise metadata by automatically cataloging all the data that exists, where it resides, who can access it, its level of sensitivity plus more than fifty other parameters. According to the “2025 Enterprise Data Security Confidence Index” surveying 500+ security professionals, announced … More →
The post Bedrock Security’s metadata lake technology strengthens data security appeared first on Help Net Security.
CVE-2007-0466 | Telestream Flip4Mac Windows Media Components for Quicktime 2.1.0.33 memory corruption (EDB-29535 / XFDB-31914)
Kentico Xperience CMS Vulnerability Enables Remote Code Execution
In recent security research, vulnerabilities in the Kentico Xperience CMS have come to light, highlighting significant risks for users who rely on this Content Management System (CMS). Specifically, two primary issues were identified: an Authentication Bypass vulnerability and a Post-Authentication Remote Code Execution (RCE) vulnerability. These vulnerabilities, collectively forming a powerful exploit chain, allow attackers to gain full control […]
The post Kentico Xperience CMS Vulnerability Enables Remote Code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Critical RCE flaw in Apache Tomcat actively exploited in attacks
CVE-2025-2378 | PHPGurukul Medical Card Generation System 1.0 download-medical-cards.php searchdata sql injection
Red Hat security advisory (AV25-144)
Wazuh SIEM Vulnerability Enables Remote Malicious Code Execution
A critical vulnerability, identified as CVE-2025-24016, has been discovered in the Wazuh Security Information and Event Management (SIEM) platform. This vulnerability affects versions 4.4.0 to 4.9.0 and allows attackers with API access to execute arbitrary Python code remotely, potentially leading to complete system compromise. The flaw stems from the unsafe deserialization of Distributed API (DAPI) […]
The post Wazuh SIEM Vulnerability Enables Remote Malicious Code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-2401 | Immunity Debugger 1.85 memory corruption
New Akira Ransomware Decryptor Leans on Nvidia GPU Power
A software programmer developed a way to use brute force to break the encryption of the notorious Akira ransomware using GPU compute power and enabling some victims of the Linux-focused variant of the malware to regain their encrypted data without having to pay a ransom.
The post New Akira Ransomware Decryptor Leans on Nvidia GPU Power appeared first on Security Boulevard.