Aggregator
CVE-2021-47246 | Linux Kernel up to 5.4.127/5.10.45/5.12.12 mlx5_core buffer overflow
CVE-2021-47236 | Linux Kernel up to 5.12.12 cdc_eem eem_tx_fixup memory leak
CVE-2024-3081 | EasyCorp EasyAdmin up to 4.8.9 Autocomplete autocomplete.js item cross site scripting (5971/6067)
CVE-2024-13021 | SourceCodester Road Accident Map Marker 1.0 /endpoint/add-mark.php mark_name/details cross site scripting
CVE-2024-13069 | SourceCodester Multi Role Login System 1.0 /endpoint/add-user.php Name cross site scripting
Docker Registry Vulnerability Lets macOS Users Access Any Registry Without Authorization
A recently discovered vulnerability in Docker Desktop for macOS is raising concerns in the developer and security communities. The flaw, which stems from the improper application of Registry Access Management (RAM) policies under certain conditions, could allow unauthorized access to potentially malicious container images-putting organizations at risk of supply chain attacks. Vulnerability Details When organizations enforce sign-in […]
The post Docker Registry Vulnerability Lets macOS Users Access Any Registry Without Authorization appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
WhatsApp Introduces AI Tools With Promise of Full Message Secrecy
WhatsApp, the world’s largest messaging platform, has announced a major leap in privacy-preserving artificial intelligence (AI) with the introduction of its new “Private Processing” system. This technology enables users to access advanced AI features-such as message summarization and writing suggestions-while upholding WhatsApp’s core promise of end-to-end message secrecy, ensuring that not even Meta, WhatsApp, or […]
The post WhatsApp Introduces AI Tools With Promise of Full Message Secrecy appeared first on Cyber Security News.
阿里 Qwen3 来袭,安恒紧跟步伐!
阿里 Qwen3 来袭,安恒紧跟步伐!
CISA Warns SAP 0-day Vulnerability Exploited in the Wild
CISA has added a critical SAP NetWeaver vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on April 29, 2025. The zero-day flaw, tracked as CVE-2025-31324, carries a maximum CVSS score of 10.0 and has been actively exploited in the wild since at least March 2025. CVE-2025-31324: Critical SAP NetWeaver File Upload Flaw CVE-2025-31324 is an […]
The post CISA Warns SAP 0-day Vulnerability Exploited in the Wild appeared first on Cyber Security News.
Saviynt ISPM provides insights into an organization’s identity and access posture
Saviynt launched AI-powered Identity Security Posture Management (ISPM) as part of its converged Identity Cloud platform. Saviynt’s ISPM provides actionable insights into an organization’s identity and access posture, offering an intelligent starting point to prioritizing and remediating risks. “As GE HealthCare became a stand-alone company, the demands around identity security and audit readiness significantly increased. We are excited for Saviynt’s ISPM to help us shift from a reactive to a proactive approach – empowering our … More →
The post Saviynt ISPM provides insights into an organization’s identity and access posture appeared first on Help Net Security.