Aggregator
CVE-2025-41242 | VMware Spring Framework up to 5.3.43/6.0.29/6.1.21/6.2.9 Servlet Container path traversal
Announcing the Cloudflare Browser Developer Program
How Evolving RATs Are Redefining Enterprise Security Threats
Internet-wide Vulnerability Enables Giant DDoS Attacks
CVE-2019-12415 | Oracle Insurance Rules Palette 10.2.0/10.2.4/11.0.2/11.1.0/11.2.0 Architecture xml external entity reference (WID-SEC-2025-0143)
CVE-2019-12415 | Oracle Communications Diameter Signaling Router up to 8.2.2 IDIH information disclosure (WID-SEC-2025-0143)
CVE-2019-12415 | Oracle Banking Payments 14.1.x/14.2.x/14.3.x/14.4.0 Core xml external entity reference (WID-SEC-2025-0143)
CVE-2019-12415 | Oracle FLEXCUBE Private Banking 12.0.0/12.1.0 Core xml external entity reference (WID-SEC-2025-0143)
CVE-2019-12415 | Oracle WebCenter Portal 12.2.1.3.0/12.2.1.4.0 Security Framework xml external entity reference (WID-SEC-2025-0143)
CVE-2019-12415 | Oracle Insurance Policy Administration J2EE 11.0.2/11.1.0/11.2.0 Architecture xml external entity reference (WID-SEC-2025-0143)
CVE-2019-12415 | Oracle Big Data Discovery 1.6 Studio xml external entity reference (WID-SEC-2025-0143)
CVE-2019-12415 | Oracle Enterprise Manager Base Platform 12.1.0.5/13.3.0.0/13.4.0.0 Application Service Level Mgmt xml external entity reference (WID-SEC-2025-0143)
CVE-2025-43733 | Liferay Portal/DXP Document View Usages Page Name cross site scripting
CVE-2025-43732 | Liferay Portal/DXP groupId authorization
Linux Kernel Netfilter Vulnerability Let Attackers Escalate Privileges
A critical vulnerability in the Linux kernel’s netfilter ipset subsystem has been discovered that allows local attackers to escalate privileges to root-level access. The flaw, identified in the bitmap:ip implementation within the ipset framework, stems from insufficient range validation when processing CIDR notation in IP address ranges. This missing bounds check enables attackers to trigger […]
The post Linux Kernel Netfilter Vulnerability Let Attackers Escalate Privileges appeared first on Cyber Security News.
X-VPN’s August Update Lets Mobile Users Choose Servers in 26 Regions with Military-Grade AES-256 Encryption
San Francisco, CA – August 12, 2025 — Addressing the growing demand for data privacy in financial workflows, X-VPN has rolled out an update to its mobile application, now offering free users the ability to manually choose from 26 server regions globally. In addition, the previously paywalled Kill Switch feature is now unlocked for all […]
The post X-VPN’s August Update Lets Mobile Users Choose Servers in 26 Regions with Military-Grade AES-256 Encryption appeared first on Cyber Security News.