Aggregator
CVE-2014-6047 | phpMyFAQ up to 2.8.12 Permission Check permission (EDB-34580)
4 months 1 week ago
A vulnerability was found in phpMyFAQ up to 2.8.12. It has been rated as critical. This issue affects some unknown processing of the component Permission Check. The manipulation leads to permission issues.
The identification of this vulnerability is CVE-2014-6047. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Product Walkthrough: How Datto BCDR Delivers Unstoppable Business Continuity
4 months 1 week ago
Long gone are the days when a simple backup in a data center was enough to keep a business secure. While backups store information, they do not guarantee business continuity during a crisis. With IT disasters far too common and downtime burning through budgets, modern IT environments require solutions that go beyond storage and enable instant recovery to minimize downtime and data loss. This is
The Hacker News
APT36 атакует Windows и Android через фальшивый почтовый сервис
4 months 1 week ago
Доверие граждан к госсервисам превращается в идеальную лазейку для хакеров.
Личности раскрыты: хакеры HellCat попались на собственные инфостилеры
4 months 1 week ago
Расследование вывело на киберпреступников из Иордании и ОАЭ.
OpenAI 强化安全防线:将漏洞赏金计划最高奖励提高至10万美元
4 months 1 week ago
安全客
CVE-2025-2804 | Composer Plugin up to 5.3 on WordPress account_id/account_username cross site scripting
4 months 1 week ago
A vulnerability was found in Composer Plugin up to 5.3 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation of the argument account_id/account_username leads to cross site scripting.
This vulnerability is traded as CVE-2025-2804. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-2878 | Kentico CMS up to 13.0.178 Additional Database Installation Wizard /CMSInstall/install.aspx new database cross site scripting
4 months 1 week ago
A vulnerability was found in Kentico CMS up to 13.0.178. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /CMSInstall/install.aspx of the component Additional Database Installation Wizard. The manipulation of the argument new database leads to cross site scripting.
This vulnerability is known as CVE-2025-2878. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-2328 | Contact Form Drag and Drop Multiple File Upload for Contact Form 7 Plugin Path Validation dnd_remove_uploaded_files unrestricted upload
4 months 1 week ago
A vulnerability, which was classified as critical, has been found in Contact Form Drag and Drop Multiple File Upload for Contact Form 7 Plugin up to 1.3.8.7 on WordPress. This issue affects the function dnd_remove_uploaded_files of the component Path Validation Handler. The manipulation leads to unrestricted upload.
The identification of this vulnerability is CVE-2025-2328. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-2074 | webfactory Advanced Google reCAPTCHA Plugin up to 1.29 on WordPress sSearch sql injection
4 months 1 week ago
A vulnerability, which was classified as critical, was found in webfactory Advanced Google reCAPTCHA Plugin up to 1.29 on WordPress. Affected is an unknown function. The manipulation of the argument sSearch leads to sql injection.
This vulnerability is traded as CVE-2025-2074. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-2485 | Contact Form Drag and Drop Multiple File Upload for Contact Form 7 Plugin dnd_upload_cf7_upload deserialization
4 months 1 week ago
A vulnerability has been found in Contact Form Drag and Drop Multiple File Upload for Contact Form 7 Plugin up to 1.3.8.7 on WordPress and classified as critical. Affected by this vulnerability is the function dnd_upload_cf7_upload. The manipulation leads to deserialization.
This vulnerability is known as CVE-2025-2485. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-2578 | Booking for Appointments and Events Calendar – Amelia Plugin wpAmeliaApiCall information disclosure
4 months 1 week ago
A vulnerability was found in Booking for Appointments and Events Calendar – Amelia Plugin up to 1.2.19 on WordPress and classified as problematic. Affected by this issue is the function wpAmeliaApiCall. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2025-2578. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-1705 | tagDiv Composer Plugin up to 5.3 on WordPress td_ajax_get_views cross-site request forgery
4 months 1 week ago
A vulnerability was found in tagDiv Composer Plugin up to 5.3 on WordPress. It has been declared as problematic. This vulnerability affects the function td_ajax_get_views. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2025-1705. The attack can be initiated remotely. There is no exploit available.
vuldb.com
每周蓝军技术推送(2025.3.22-3.28)
4 months 1 week ago
关注高级攻防对抗技术热点,研究对手技术进行高级威胁模拟,研判攻击安全发展方向。
每周蓝军技术推送(2025.3.22-3.28)
4 months 1 week ago
关注高级攻防对抗技术热点,研究对手技术进行高级威胁模拟,研判攻击安全发展方向。
每周蓝军技术推送(2025.3.22-3.28)
4 months 1 week ago
关注高级攻防对抗技术热点,研究对手技术进行高级威胁模拟,研判攻击安全发展方向。
每周蓝军技术推送(2025.3.22-3.28)
4 months 1 week ago
关注高级攻防对抗技术热点,研究对手技术进行高级威胁模拟,研判攻击安全发展方向。
每周蓝军技术推送(2025.3.22-3.28)
4 months 1 week ago
关注高级攻防对抗技术热点,研究对手技术进行高级威胁模拟,研判攻击安全发展方向。
每周蓝军技术推送(2025.3.22-3.28)
4 months 1 week ago
关注高级攻防对抗技术热点,研究对手技术进行高级威胁模拟,研判攻击安全发展方向。
每周蓝军技术推送(2025.3.22-3.28)
4 months 1 week ago
关注高级攻防对抗技术热点,研究对手技术进行高级威胁模拟,研判攻击安全发展方向。