Aggregator
CVE-2022-44729 | Apache Batik up to 1.16 server-side request forgery (Nessus ID 233387)
4 months 2 weeks ago
A vulnerability classified as critical has been found in Apache Batik up to 1.16. Affected is an unknown function. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2022-44729. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-27553 | Apache Commons VFS up to 2.9.x FileObject API resolveFile Scope path traversal (Nessus ID 233401)
4 months 2 weeks ago
A vulnerability was found in Apache Commons VFS up to 2.9.x. It has been classified as problematic. Affected is the function resolveFile of the component FileObject API. The manipulation of the argument Scope leads to relative path traversal.
This vulnerability is traded as CVE-2025-27553. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-30474 | Apache Commons VFS up to 2.9.x FtpFileObject information exposure (Nessus ID 233401)
4 months 2 weeks ago
A vulnerability was found in Apache Commons VFS up to 2.9.x. It has been declared as problematic. Affected by this vulnerability is the function FtpFileObject. The manipulation leads to information exposure through error message.
This vulnerability is known as CVE-2025-30474. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-58014 | Linux Kernel up to 6.1.128/6.6.77/6.12.13/6.13.2 brcmsmac wlc_phy_iqcal_gainparams_nphy out-of-bounds (Nessus ID 233410)
4 months 2 weeks ago
A vulnerability was found in Linux Kernel up to 6.1.128/6.6.77/6.12.13/6.13.2. It has been rated as problematic. Affected by this issue is the function wlc_phy_iqcal_gainparams_nphy of the component brcmsmac. The manipulation leads to out-of-bounds read.
This vulnerability is handled as CVE-2024-58014. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21780 | Linux Kernel up to 6.1.128/6.6.78/6.12.15/6.13.3/6.14-rc2 smu_sys_set_pp_table buffer overflow (Nessus ID 233410)
4 months 2 weeks ago
A vulnerability was found in Linux Kernel up to 6.1.128/6.6.78/6.12.15/6.13.3/6.14-rc2. It has been rated as critical. Affected by this issue is the function smu_sys_set_pp_table. The manipulation leads to buffer overflow.
This vulnerability is handled as CVE-2025-21780. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8176 | libexpat stack-based overflow (Nessus ID 233405)
4 months 2 weeks ago
A vulnerability was found in libexpat and classified as critical. This issue affects some unknown processing. The manipulation leads to stack-based buffer overflow.
The identification of this vulnerability is CVE-2024-8176. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2020-7676 | angular.js up to 1.7.x Regex cross site scripting (Nessus ID 233421)
4 months 2 weeks ago
A vulnerability classified as problematic has been found in angular.js up to 1.7.x. This affects an unknown part of the component Regex Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2020-7676. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-22230 | VMware Tools up to 12.5.0 on Windows authentication bypass (Nessus ID 233416)
4 months 2 weeks ago
A vulnerability classified as critical was found in VMware Tools up to 12.5.0 on Windows. Affected by this vulnerability is an unknown functionality. The manipulation leads to authentication bypass using alternate channel.
This vulnerability is known as CVE-2025-22230. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Blacklock Ransomware Infrastructure Breached, Revealing Planned Attacks
4 months 2 weeks ago
Resecurity, a prominent cybersecurity firm, has successfully exploited a vulnerability in the Data Leak Site (DLS) of Blacklock Ransomware, gaining unprecedented access to the group’s infrastructure. This breach, occurring during the winter of 2024-2025, allowed researchers to collect substantial intelligence about the ransomware group’s activities and planned attacks. Exploitation of Local File Include Vulnerability The […]
The post Blacklock Ransomware Infrastructure Breached, Revealing Planned Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Aman Mishra
CVE-2008-3652 | ipsec-tools resource management (Nessus ID 34052 / ID 117251)
4 months 2 weeks ago
A vulnerability classified as critical was found in ipsec-tools. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper resource management.
This vulnerability is known as CVE-2008-3652. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-32559 | pywin32 prior b301 ACE integer overflow (FEYE-2021-0017)
4 months 2 weeks ago
A vulnerability was found in pywin32. It has been rated as problematic. This issue affects some unknown processing of the component ACE Handler. The manipulation leads to integer overflow.
The identification of this vulnerability is CVE-2021-32559. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-45429 | VirusTotal YARA yara/libyara/libyara.c yr_set_configuration buffer overflow (Issue 1616)
4 months 2 weeks ago
A vulnerability classified as problematic has been found in VirusTotal YARA. This affects the function yr_set_configuration in the library yara/libyara/libyara.c. The manipulation leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2021-45429. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2022-4671 | PixCodes Plugin up to 2.3.6 on WordPress Shortcode cross site scripting
4 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in PixCodes Plugin up to 2.3.6 on WordPress. Affected is an unknown function of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2022-4671. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-4470 | Widgets for Google Reviews Plugin up to 9.7 on WordPress Shortcode Attribute cross site scripting
4 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in Widgets for Google Reviews Plugin up to 9.7 on WordPress. Affected is an unknown function of the component Shortcode Attribute Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2022-4470. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-4651 | Justified Gallery Plugin up to 1.7.0 on WordPress Shortcode Attribute cross site scripting
4 months 2 weeks ago
A vulnerability has been found in Justified Gallery Plugin up to 1.7.0 on WordPress and classified as problematic. This vulnerability affects unknown code of the component Shortcode Attribute Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2022-4651. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-4763 | Icon Widget Plugin up to 1.2.x on WordPress Shortcode Attribute cross site scripting
4 months 2 weeks ago
A vulnerability was found in Icon Widget Plugin up to 1.2.x on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Shortcode Attribute Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2022-4763. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-4781 | Accordion Shortcodes Plugin up to 2.4.2 on WordPress Shortcode Attribute cross site scripting
4 months 2 weeks ago
A vulnerability classified as problematic has been found in Accordion Shortcodes Plugin up to 2.4.2 on WordPress. This affects an unknown part of the component Shortcode Attribute Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2022-4781. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2009-2409 | VMware ESX Server 4.x Service Console cryptographic issues (Nessus ID 67960 / ID 216028)
4 months 2 weeks ago
A vulnerability, which was classified as critical, was found in VMware ESX Server 4.x. Affected is an unknown function of the component Service Console. The manipulation leads to cryptographic issues.
This vulnerability is traded as CVE-2009-2409. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-28810 | Zoho ManageEngine ADSelfService Plus up to 6121 Password os command injection
4 months 2 weeks ago
A vulnerability classified as critical has been found in Zoho ManageEngine ADSelfService Plus up to 6121. Affected is an unknown function. The manipulation of the argument Password leads to os command injection.
This vulnerability is traded as CVE-2022-28810. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com