A high-severity security flaw has been disclosed in ServiceNow's platform that, if successfully exploited, could result in data exposure and exfiltration.
The vulnerability, tracked as CVE-2025-3648 (CVSS score: 8.2), has been described as a case of data inference in Now Platform through conditional access control list (ACL) rules. It has been codenamed Count(er) Strike.
"A vulnerability has
A vulnerability classified as problematic has been found in jQuery up to 1.8.1. This affects the function jQuery(strInput). The manipulation as part of String leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2012-6708. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in OnionShare up to 1.3.1. Affected by this issue is the function debug_mode of the file web/web.py. The manipulation leads to improper input validation.
This vulnerability is handled as CVE-2018-19960. Local access is required to approach this attack. There is no exploit available.
A vulnerability classified as problematic has been found in OnionShare 100. This affects an unknown part of the component File Upload Handler. The manipulation leads to resource consumption.
This vulnerability is uniquely identified as CVE-2022-21689. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in mySCADA myPRO Manager up to 1.3. This issue affects some unknown processing of the component Administrative Web Interface. The manipulation leads to missing authentication.
The identification of this vulnerability is CVE-2025-24865. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Linux Kernel up to 5.15.139/6.1.63/6.5.12/6.6.2 and classified as problematic. Affected by this vulnerability is the function skb_reserve of the component atl1c. The manipulation leads to allocation of resources.
This vulnerability is known as CVE-2023-52834. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in lmfit asteval up to 1.0.5 and classified as critical. Affected by this issue is the function str. The manipulation leads to format string.
This vulnerability is handled as CVE-2025-24359. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in yrutschle sslh up to 2.2.1. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to link following.
The identification of this vulnerability is CVE-2025-52936. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. This affects an unknown part of the component Push Configuration Section. The manipulation of the argument Configuration Name leads to cross site scripting. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is uniquely identified as CVE-2024-6344. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
The vendor explains, that "[s]ince ZKBio CVSecurity v5000 has been withdrawn from the market, we recommend upgrading to ZKBio CVSecurity V6600 6.1.3_R or above".
OpenAI 准备发布一款 AI 驱动的 Web 浏览器,挑战支配着浏览器市场的 Google Chrome。浏览器预计将在数周内发布,它旨在利用 AI 从根本上改变消费者浏览 Web 的方式。它将让 OpenAI 直接获取 Google 成功的基石:用户数据。Chrome 是 Alphabet 广告业务的支柱,Chrome 提供用户信息以帮助 Alphabet 更有效定向广告使其更有利可图,它还为 Google 提供了一种默认将搜索流量路由到自家引擎的方法。Google Chrome 用户数多达 30 亿,而 OpenAI ChatGPT 的周活跃用户为 5 亿,它的浏览器是基于 Google 开源的 Chromium。