Aggregator
CVE-2024-56898 | Geovision GV-ASWeb up to 6.1.0.0 HTTP Request access control (EDB-52189)
8 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Geovision GV-ASWeb up to 6.1.0.0. This issue affects some unknown processing of the component HTTP Request Handler. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2024-56898. The attack can only be initiated within the local network. Furthermore, there is an exploit available.
vuldb.com
UNITED NATURAL FOODS, INC. has Filed Form 8-K Due to a Cybersecurity Incident
8 months 3 weeks ago
UNITED NATURAL FOODS, INC. has Filed Form 8-K Due to a Cybersecurity Incident
Dark Web Informer - Cyber Threat Intelligence
税务解决方案公司 Optima Tax Relief 遭勒索软件攻击,数据泄露
8 months 3 weeks ago
安全客
威胁行为者针对 Gluestack 软件包发起供应链攻击,每周有超过 95 万次的下载面临风险
8 months 3 weeks ago
安全客
Malicious npm Packages as Utilities Let Attackers Destroy Production Systems
8 months 3 weeks ago
Security researchers have uncovered a disturbing new threat in the npm ecosystem where malicious packages masquerade as legitimate utilities while harboring destructive backdoors capable of wiping entire production environments. These packages represent a significant escalation from traditional credential theft or cryptocurrency mining attacks, focusing instead on complete system destruction that could cripple business operations. The […]
The post Malicious npm Packages as Utilities Let Attackers Destroy Production Systems appeared first on Cyber Security News.
Tushar Subhra Dutta
英国法院警告称,律师可能因人工智能生成的虚假引文而面临 “严厉 ”处罚
8 months 3 weeks ago
安全客
Types of Hackers
8 months 3 weeks ago
Types of Hackers
Dark Web Informer - Cyber Threat Intelligence
CVE-2016-2781 | GNU Coreutils chroot userspec input validation (EUVD-2016-3855)
8 months 3 weeks ago
A vulnerability classified as problematic was found in GNU Coreutils. This vulnerability affects unknown code of the component chroot. The manipulation of the argument userspec leads to improper input validation.
This vulnerability was named CVE-2016-2781. Attacking locally is a requirement. There is no exploit available.
vuldb.com
CVE-2025-31052 | Fashion Theme up to 1.4.4 on WordPress deserialization (EUVD-2025-17493)
8 months 3 weeks ago
A vulnerability was found in Fashion Theme up to 1.4.4 on WordPress. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to deserialization.
This vulnerability was named CVE-2025-31052. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-31050 | Apptha Slider Gallery Plugin up to 2.5 on WordPress path traversal (EUVD-2025-17492)
8 months 3 weeks ago
A vulnerability has been found in Apptha Slider Gallery Plugin up to 2.5 on WordPress and classified as critical. This vulnerability affects unknown code. The manipulation leads to path traversal.
This vulnerability was named CVE-2025-31050. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-24188 | pcmacdon Jsish 3.5.0 /src/jsiUtils.c heap-based overflow (Issue 100 / EUVD-2024-21612)
8 months 3 weeks ago
A vulnerability was found in pcmacdon Jsish 3.5.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /src/jsiUtils.c. The manipulation leads to heap-based buffer overflow.
This vulnerability is known as CVE-2024-24188. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2024-24021 | novel-plus up to 4.3.0-RC1 /novel/userFeedback/list offset/limit/sort sql injection (EUVD-2024-21447)
8 months 3 weeks ago
A vulnerability classified as critical was found in novel-plus up to 4.3.0-RC1. This vulnerability affects unknown code of the file /novel/userFeedback/list. The manipulation of the argument offset/limit/sort leads to sql injection.
This vulnerability was named CVE-2024-24021. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2025-32291 | SUMO Affiliates Pro Plugin up to 10.7.0 on WordPress unrestricted upload (EUVD-2025-17476)
8 months 3 weeks ago
A vulnerability was found in SUMO Affiliates Pro Plugin up to 10.7.0 on WordPress. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to unrestricted upload.
The identification of this vulnerability is CVE-2025-32291. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-24304 | Mailjet Module up to 3.5.0 on PrestaShop information disclosure (EUVD-2024-21726)
8 months 3 weeks ago
A vulnerability classified as problematic has been found in Mailjet Module up to 3.5.0 on PrestaShop. Affected is an unknown function. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-24304. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-5054 | Canonical apport information disclosure (EUVD-2025-16511)
8 months 3 weeks ago
A vulnerability has been found in Canonical apport and classified as problematic. This vulnerability affects unknown code. The manipulation leads to information disclosure.
This vulnerability was named CVE-2025-5054. Local access is required to approach this attack. Furthermore, there is an exploit available.
vuldb.com
Jenkins Gatling 插件中未修补的 XSS 漏洞会给用户带来风险 (CVE-2025-5806)
8 months 3 weeks ago
安全客
新的 Mirai 僵尸网络变种通过 CVE-2024-3721 瞄准 DVR 系统
8 months 3 weeks ago
安全客
自 2025 年初以来,恶意浏览器扩展程序感染了拉丁美洲 700 多名用户
8 months 3 weeks ago
安全客
Limited Canva Creator Data Exposed Via AI Chatbot Database
8 months 3 weeks ago
A Chroma database operated by Russian AI chatbot startup My Jedai was found exposed online, leaking survey responses…
Waqas