Aggregator
«Дайте рекомендацию коллеге»: фраза, с которой начинается атака на завод
4 months 1 week ago
Фишинг нового поколения атакует российскую промышленность.
CVE-2025-1658 | Autodesk Navisworks Freedom 2025 DWFX File out-of-bounds
4 months 1 week ago
A vulnerability classified as critical has been found in Autodesk Navisworks Freedom, Navisworks Simulate and Navisworks Manage 2025. This affects an unknown part of the component DWFX File Handler. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2025-1658. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-22231 | VMware Aria Operations up to 8.18 HF4 Local Privilege Escalation
4 months 1 week ago
A vulnerability was found in VMware Aria Operations up to 8.18 HF4. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to Local Privilege Escalation.
This vulnerability is handled as CVE-2025-22231. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-30354 | usebruno up to 1.39.0 cross-domain policy
4 months 1 week ago
A vulnerability was found in usebruno bruno up to 1.39.0. It has been classified as critical. Affected is an unknown function. The manipulation leads to permissive cross-domain policy with untrusted domains.
This vulnerability is traded as CVE-2025-30354. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-1659 | Autodesk Navisworks Freedom 2025 DWFX File out-of-bounds
4 months 1 week ago
A vulnerability was found in Autodesk Navisworks Freedom, Navisworks Simulate and Navisworks Manage 2025. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component DWFX File Handler. The manipulation leads to out-of-bounds read.
This vulnerability is known as CVE-2025-1659. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-31131 | yeswiki up to 4.5.1 squelette path traversal
4 months 1 week ago
A vulnerability was found in yeswiki up to 4.5.1 and classified as critical. This issue affects some unknown processing. The manipulation of the argument squelette leads to path traversal.
The identification of this vulnerability is CVE-2025-31131. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Over 1,500 PostgreSQL Servers Compromised in Fileless Cryptocurrency Mining Campaign
4 months 1 week ago
Exposed PostgreSQL instances are the target of an ongoing campaign designed to gain unauthorized access and deploy cryptocurrency miners.
Cloud security firm Wiz said the activity is a variant of an intrusion set that was first flagged by Aqua Security in August 2024 that involved the use of a malware strain dubbed PG_MEM. The campaign has been attributed to a threat actor Wiz tracks as
The Hacker News
CVE-2025-30210 | usebruno up to 1.39.0 cross site scripting (GHSA-fqxc-cxph-9vq8)
4 months 1 week ago
A vulnerability has been found in usebruno bruno up to 1.39.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to basic cross site scripting.
This vulnerability was named CVE-2025-30210. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-3085 | MongoDB Server up to 5.0.30/6.0.19/7.0.15/8.0.3 on Linux Certificate Chain improper check for certificate revocation
4 months 1 week ago
A vulnerability, which was classified as critical, was found in MongoDB Server up to 5.0.30/6.0.19/7.0.15/8.0.3 on Linux. This affects an unknown part of the component Certificate Chain Handler. The manipulation leads to improper check for certificate revocation.
This vulnerability is uniquely identified as CVE-2025-3085. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21907 | Linux Kernel up to 6.12.18/6.13.6 memory-failure unmap_poisoned_folio state issue
4 months 1 week ago
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 6.12.18/6.13.6. Affected by this issue is the function unmap_poisoned_folio of the component memory-failure. The manipulation leads to state issue.
This vulnerability is handled as CVE-2025-21907. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21935 | Linux Kernel up to 6.13.6 rapidio rio_add_net return value
4 months 1 week ago
A vulnerability classified as problematic was found in Linux Kernel up to 6.13.6. Affected by this vulnerability is the function rio_add_net of the component rapidio. The manipulation leads to unchecked return value.
This vulnerability is known as CVE-2025-21935. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-30224 | MyDumper up to 0.18.2-7 information disclosure (GHSA-r8qc-xp3g-c458)
4 months 1 week ago
A vulnerability classified as problematic has been found in MyDumper up to 0.18.2-7. Affected is an unknown function. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2025-30224. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21920 | Linux Kernel up to 6.13.6 dev_mc_add out-of-bounds
4 months 1 week ago
A vulnerability was found in Linux Kernel up to 6.13.6. It has been rated as problematic. This issue affects the function dev_mc_add. The manipulation leads to out-of-bounds read.
The identification of this vulnerability is CVE-2025-21920. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21934 | Linux Kernel up to 6.13.6 rapidio rio_add_net use after free
4 months 1 week ago
A vulnerability was found in Linux Kernel up to 6.13.6. It has been declared as critical. This vulnerability affects the function rio_add_net of the component rapidio. The manipulation leads to use after free.
This vulnerability was named CVE-2025-21934. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21933 | Linux Kernel up to 6.13.6 pgtable update_mmu_cache_range null pointer dereference
4 months 1 week ago
A vulnerability was found in Linux Kernel up to 6.13.6. It has been classified as critical. This affects the function update_mmu_cache_range of the component pgtable. The manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2025-21933. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21936 | Linux Kernel up to 6.1.130/6.6.82/6.12.18/6.13.6 Bluetooth mgmt_alloc_skb null pointer dereference
4 months 1 week ago
A vulnerability was found in Linux Kernel up to 6.1.130/6.6.82/6.12.18/6.13.6 and classified as critical. Affected by this issue is the function mgmt_alloc_skb of the component Bluetooth. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2025-21936. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Учёные создали "квантовый сэндвич" из двух невероятно редких материалов
4 months 1 week ago
Самый странный бутерброд на стыке физики и технологии.
CVE-2025-21930 | Linux Kernel up to 6.12.18/6.13.6 iwl-trans.c state issue
4 months 1 week ago
A vulnerability has been found in Linux Kernel up to 6.12.18/6.13.6 and classified as critical. Affected by this vulnerability is an unknown functionality of the file drivers/net/wireless/inel/iwlwifi/iwl-trans.c. The manipulation leads to state issue.
This vulnerability is known as CVE-2025-21930. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21928 | Linux Kernel up to 6.13.6 ishtp_hid_remove use after free
4 months 1 week ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.13.6. Affected is the function ishtp_hid_remove. The manipulation leads to use after free.
This vulnerability is traded as CVE-2025-21928. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com