Aggregator
360与河南物流职业学院携手共建产业学院,赋能新质人才培养
7 months 3 weeks ago
安全客
Cloudflare 在 2025 年阻止了创纪录的 7.3 Tbps DDoS 攻击
7 months 3 weeks ago
安全客
Meta 在与 Scale AI 交易之前考虑收购 Perplexity
7 months 3 weeks ago
安全客
CVE-2024-4256 | Techkshetra Info Solutions Savsoft Quiz 6.0 Category Page editCategory category_name cross site scripting
7 months 3 weeks ago
A vulnerability was found in Techkshetra Info Solutions Savsoft Quiz 6.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /public/index.php/Qbank/editCategory of the component Category Page. The manipulation of the argument category_name with the input ><script>alert('XSS')</script> leads to cross site scripting.
This vulnerability is handled as CVE-2024-4256. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-21550 | Oracle Financial Services Behavior Detection Platform 8.0.8.1/8.1.2.7/8.1.2.8 improper authentication
7 months 3 weeks ago
A vulnerability classified as critical has been found in Oracle Financial Services Behavior Detection Platform 8.0.8.1/8.1.2.7/8.1.2.8. Affected is an unknown function. The manipulation leads to improper authentication.
This vulnerability is traded as CVE-2025-21550. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-1925 | Open5GS up to 2.7.2 AMF src/amf/nsmf-handler.c amf_nsmf_pdusession_handle_update_sm_context denial of service
7 months 3 weeks ago
A vulnerability classified as problematic was found in Open5GS up to 2.7.2. Affected by this vulnerability is the function amf_nsmf_pdusession_handle_update_sm_context of the file src/amf/nsmf-handler.c of the component AMF. The manipulation leads to denial of service.
This vulnerability is known as CVE-2025-1925. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-4135 | Netgear WG302v2 up to 5.2.9 ui_get_input_value host command injection
7 months 3 weeks ago
A vulnerability was found in Netgear WG302v2 up to 5.2.9 and classified as critical. Affected by this issue is the function ui_get_input_value. The manipulation of the argument host leads to command injection.
This vulnerability is handled as CVE-2025-4135. The attack may be launched remotely. There is no exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-4139 | Netgear EX6120 1.0.0.68 fwAcosCgiInbound host buffer overflow
7 months 3 weeks ago
A vulnerability classified as critical was found in Netgear EX6120 1.0.0.68. Affected by this vulnerability is the function fwAcosCgiInbound. The manipulation of the argument host leads to buffer overflow.
This vulnerability is known as CVE-2025-4139. The attack can be launched remotely. There is no exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-4043 | Milesight UG65-868M-EA prior 60.0.0.46 System Boot /etc/rc.local improper access control for volatile memory containing boot code (icsa-25-126-02)
7 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Milesight UG65-868M-EA. Affected is an unknown function of the file /etc/rc.local of the component System Boot Handler. The manipulation leads to improper access control for volatile memory containing boot code.
This vulnerability is traded as CVE-2025-4043. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-48766 | NetAlertX up to 24.10.11 components/logs.php redirect
7 months 3 weeks ago
A vulnerability was found in NetAlertX up to 24.10.11 and classified as problematic. This issue affects some unknown processing of the file components/logs.php. The manipulation leads to execution after redirect.
The identification of this vulnerability is CVE-2024-48766. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-46721 | justinas nosurf up to 1.1.x HTTP Request cross-site request forgery (GHSA-rq77-p4h8-4crw)
7 months 3 weeks ago
A vulnerability was found in justinas nosurf up to 1.1.x. It has been declared as problematic. This vulnerability affects unknown code of the component HTTP Request Handler. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2025-46721. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-4727 | Meteor up to 3.2.1 livedata_server.js Object.assign forwardedFor redos (Issue 13713 / EUVD-2025-15378)
7 months 3 weeks ago
A vulnerability was found in Meteor up to 3.2.1 and classified as problematic. This issue affects the function Object.assign of the file packages/ddp-server/livedata_server.js. The manipulation of the argument forwardedFor leads to inefficient regular expression complexity.
The identification of this vulnerability is CVE-2025-4727. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-2357 | DCMTK 3.6.9 dcmjpls JPEG-LS Decoder memory corruption (Issue 1155 / 3239a7915)
7 months 3 weeks ago
A vulnerability was found in DCMTK 3.6.9. It has been declared as critical. This vulnerability affects unknown code of the component dcmjpls JPEG-LS Decoder. The manipulation leads to memory corruption.
This vulnerability was named CVE-2025-2357. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-8523 | lmxcms up to 1.4 SQL Command Execution Module admin.php?m=Acquisi&a=testcj&lid=1 formatData data code injection
7 months 3 weeks ago
A vulnerability was found in lmxcms up to 1.4 and classified as critical. Affected by this issue is the function formatData of the file /admin.php?m=Acquisi&a=testcj&lid=1 of the component SQL Command Execution Module. The manipulation of the argument data leads to code injection.
This vulnerability is handled as CVE-2024-8523. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
Iran-linked cyberattack reportedly disrupts public services in Albania’s capital
7 months 3 weeks ago
A group associated with Iran's Islamic Revolutionary Guard Corps (IRGC) claimed an attack on the municipal website of Tirana, Albania's capital. It's the latest in a string of incidents attributed to the hackers.
Cyber Fattah Leaks Data from Saudi Games in Alleged Iranian Operation
7 months 3 weeks ago
A cyber-attack by pro-Iranian group Cyber Fattah has leaked personal information from the Saudi Games online
Nieuwe aanpak versimpelt eisen defensieopdrachten
7 months 3 weeks ago
Voor jonge innovatieve bedrijven is het vaak lastig te voldoen aan de complexe eisen van defensieopdrachten. Om dat traject te versimpelen presenteerde Defensie vandaag een nieuwe aanpak. Dat gebeurde op een groots tech-evenement op de Haagse innovatiecampus Binckhaven.
The SAVE database was already a headache for states. Now it’s fueling Trump’s voter fraud allegations.
7 months 3 weeks ago
Experts believe lawsuits are first steps in a larger plan by the White House to create new metrics that lend support to the president’s unproven claims that noncitizens are voting en masse for Democratic politicians.
The post The SAVE database was already a headache for states. Now it’s fueling Trump’s voter fraud allegations. appeared first on CyberScoop.
Greg Otto
CVE-2025-21549 | Oracle WebLogic Server 14.1.1.0.0 Core improper authentication
7 months 3 weeks ago
A vulnerability was found in Oracle WebLogic Server 14.1.1.0.0. It has been rated as critical. This issue affects some unknown processing of the component Core. The manipulation leads to improper authentication.
The identification of this vulnerability is CVE-2025-21549. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com