Aggregator
CVE-2014-4030 | Longtailvideo Jw Player For Flash / Html5 Video Plugin up to 2.1.1 cross-site request forgery (EDB-39212 / ID 12994)
Linux flaws chain allows Root access across major distributions
DuckDuckGo’s Scam Blocker now blocks more types of scams
Online scams are getting worse and more varied. DuckDuckGo knows that, so they’ve made changes. Their built-in Scam Blocker now stops more kinds of scam sites, all without tracking you. How Scam Blocker works (Source: DuckDuckGo) “If you accidentally click a link that would take you to a scam site, DuckDuckGo’s built-in Scam Blocker will stop the page from loading and show you a warning message that allows you to navigate safely away. The DuckDuckGo … More →
The post DuckDuckGo’s Scam Blocker now blocks more types of scams appeared first on Help Net Security.
用 IRify 定位某 Admin 目录遍历及反序列化漏洞文件上传
CVE-2023-24021 | ModSecurity up to 2.9.6 Web Application Firewall access control (DLA 3283-1 / Nessus ID 239776)
CVE-2025-22241 | VMware SALT prior 3006.12/3007.4 VirtKey improper authentication (EUVD-2025-18249 / Nessus ID 240193)
CVE-2021-45005 | Artifex MuJS 1.1.3 heap-based overflow (Nessus ID 240196)
CVE-2025-4563 | Kubernetes kube-apiserver up to 1.32.5/1.33.1 NodeRestriction Admission Controller allocation of resources (Nessus ID 240194)
CVE-2025-22240 | VMware SALT prior 3006.12/3007.4 find_file permission (EUVD-2025-18250 / Nessus ID 240193)
CVE-2025-22242 | VMware SALT prior 3006.12/3007.4 pub_ret jid denial of service (EUVD-2025-18248 / Nessus ID 240193)
CVE-2023-34966 | Samba up to 4.16.10/4.17.9/4.18.4 mdssvc RPC Service sl_unpack_loop infinite loop (FEDORA-2023-bcd91bfcd3 / Nessus ID 240197)
CVE-2025-23207 | KaTeX up to 0.16.20 Mathematical Expression renderToString cross site scripting (GHSA-cg87-wmx4-v546 / Nessus ID 240201)
CVE-2024-28246 | KaTeX up to 0.16.9 URL Protocol comparison (GHSA-3wc5-fcw2-2329 / Nessus ID 240201)
一图读懂第十届“创客中国”网络安全创新创业大赛
Dover Fueling Solutions Flaw Lets Attackers Control Fueling Operations
A newly disclosed critical vulnerability in Dover Fueling Solutions’ ProGauge MagLink LX consoles has sent shockwaves through the global fuel infrastructure sector. The flaw, tracked as CVE-2025-5310, allows remote attackers to seize control of fueling operations, manipulate tank monitoring, and even deploy malware, posing a severe risk to transportation systems worldwide. Critical Flaw Exposes Global […]
The post Dover Fueling Solutions Flaw Lets Attackers Control Fueling Operations appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.