SonicWall is warning customers that threat actors are distributing a trojanized version of its NetExtender SSL VPN client used to steal VPN credentials. [...]
A vulnerability classified as problematic was found in Moodle up to 4.5.2. Affected by this vulnerability is an unknown functionality of the component REST API. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2025-32044. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Moodle. Affected by this issue is some unknown functionality of the component Grade Report Handler. The manipulation leads to permission issues.
This vulnerability is handled as CVE-2025-32045. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in PerfreeBlog 4.0.11. Affected is an unknown function of the component Backend System Settings. The manipulation of the argument website name leads to cross site scripting.
This vulnerability is traded as CVE-2025-29280. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability was found in PerfreeBlog 4.0.11. It has been classified as critical. This affects an unknown part. The manipulation leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2025-29281. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in Fastify up to 5.3.0 on Node.js. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to improper validation of specified type of input.
This vulnerability was named CVE-2025-32442. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Moodle. This issue affects some unknown processing of the component MFA Email Factor Revoke Action. The manipulation leads to improper control of resource identifiers.
The identification of this vulnerability is CVE-2025-3625. Access to the local network is required for this attack. There is no exploit available.
A vulnerability, which was classified as problematic, was found in Moodle. Affected is an unknown function of the component Multi-Factor Authentication. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2025-3627. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability has been found in Moodle and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Assignment Submission Search. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2025-3628. The attack needs to be approached within the local network. There is no exploit available.
A vulnerability was found in Moodle. It has been classified as problematic. This affects an unknown part of the component User Tours Manager. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2025-3635. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in DataEase up to 2.10.7 and classified as critical. This issue affects some unknown processing of the component Backend JDBC link Handler. The manipulation leads to authentication bypass by spoofing.
The identification of this vulnerability is CVE-2025-32966. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Moodle and classified as critical. Affected by this issue is some unknown functionality of the component MFA. The manipulation leads to improper authorization.
This vulnerability is handled as CVE-2025-3634. The attack can only be done within the local network. There is no exploit available.
A vulnerability, which was classified as critical, was found in OpenPanel 0.3.4. Affected is an unknown function of the component File Manager. The manipulation leads to path traversal.
This vulnerability is traded as CVE-2024-53582. The attack needs to be approached within the local network. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
The campaign infected devices in the US and Southeast Asia to build an operational relay box (ORB) network for use as an extensive cyber-espionage infrastructure.
Kaspersky uncovers SparkKitty, new spyware in Apple App Store & Google Play. Steals photos, targets crypto info, active since early 2024 via malicious apps.
A vulnerability was found in Sound eXchange 14.4.2. It has been declared as critical. Affected by this vulnerability is the function start_read of the file sphere.c of the component File Handler. The manipulation leads to heap-based buffer overflow.
This vulnerability is known as CVE-2021-40426. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in Microsoft Windows and classified as critical. Affected by this issue is some unknown functionality of the component WebBrowser Control. The manipulation leads to privilege escalation.
This vulnerability is handled as CVE-2022-30194. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in Microsoft Windows up to Server 2022. It has been classified as problematic. This affects an unknown part of the component Kernel. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2022-30197. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in xxyopen Novel-Plus up to 4.4.0 and classified as critical. This issue affects some unknown processing of the file PageController.java. The manipulation leads to code injection.
The identification of this vulnerability is CVE-2025-26182. The attack may be initiated remotely. There is no exploit available.
A vulnerability was found in flatpressblog flatpress 1.3. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-9699. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.