Aggregator
CVE-2024-13898 | Simple Banner Plugin up to 3.0.5 on WordPress cross site scripting
CVE-2025-2075 | Uncanny Automator Plugin up to 6.3.0.2 on WordPress add_role authorization
CVE-2025-2270 | Countdown, Coming Soon, Maintenance Plugin up to 2.8.9.1 on WordPress createCdObj file inclusion
CVE-2025-32054 | JetBrains IntelliJ IDEA prior 2024.3/2024.2.4 idea.log log file
CVE-2025-31483 | miniflux up to 2.2.6 Content Security Policy /proxy/ cross site scripting (GHSA-cq88-842x-2jhp)
Submit #546223: phpgurukul.com Old Age Home Management System V1.0 SQL injection [Accepted]
CVE-2025-31126 | element-hq element-x-ios up to 25.03.7 element.json information disclosure (ID 2441)
CVE-2025-31486 | vitejs vite up to 4.5.11/5.4.16/6.0.13/6.1.3/6.2.4 information disclosure
CVE-2025-31127 | element-hq element-x-android up to 25.03.3 element.json information disclosure (ID 2441)
CVE-2023-47639 | api-platform core up to 3.2.4 JSON information exposure (GHSA-rfw5-cqjj-7v9r)
CVE-2024-22611 | OpenEMR 7.0.2 Pharmacy.class.php sql injection
Protecting Users: Prevent and Stop Cyberthreats Before They Start With Kaseya 365 User
Discover how Kaseya 365 User enhances end-user protection and prevents threats before they cause damage.
The post Protecting Users: Prevent and Stop Cyberthreats Before They Start With Kaseya 365 User appeared first on Kaseya.
The post Protecting Users: Prevent and Stop Cyberthreats Before They Start With Kaseya 365 User appeared first on Security Boulevard.
Live Webinar | How Google Does It: Making threat detection scalable and securing our own cloud
Cybersecurity Experts Slam Oracle's Handling of Big Breach
Cybersecurity experts have slammed Oracle's handling of a large data breach that it's reportedly confirming to 140,000 affected cloud infrastructure clients - but only verbally, and not in writing - following nearly two weeks of it having denied that any such breach occurred.
Cryptohack Roundup: Q1 Sees Record Hacks
This week, hack stats, Hamas crypto funds seizure, conclusion of Kraken, Consensys and Cumberland DRW lawsuits, Kentucky dropped its Coinbase suit, Trump pardoned BitMex co-founders, Lazarus's new tactics, and Crocodilus malware's crypto targets.
DeepMind Warns of AGI Risk, Calls for Urgent Safety Measures
Google DeepMind executives outlined an approach to artificial general intelligence safety, warning of "severe harm" that can "permanently destroy humanity" if safeguards are not put in place before advanced artificial intelligence systems emerge. AGI could arrive by 2030, they predict.
В шесть раз эффективнее меди: полуметаллы становятся следующим технологическим прорывом
Ivanti VPN customers targeted via unrecognized RCE vulnerability (CVE-2025-22457)
A suspected Chinese APT group has exploited CVE-2025-22457 – a buffer overflow bug that was previously thought not to be exploitable – to compromise appliances running Ivanti Connect Secure (ICS) 22.7R2.5 or earlier or Pulse Connect Secure 9.1x. The vulnerability was patched by Ivanti in ICS 22.7R2.6, released on February 11, 2025. But, apparently, the threat actor studied the patch and “uncovered through a complicated process, [that] it was possible to exploit 22.7R2.5 and earlier … More →
The post Ivanti VPN customers targeted via unrecognized RCE vulnerability (CVE-2025-22457) appeared first on Help Net Security.