Aggregator
Colt Telecommunications Struggles in Wake of Cyber Incident
3 days 1 hour ago
The UK telco said it temporarily took some systems offline as a "protective" measure in its investigation.
Kristina Beek
10 Best Free Data Recovery Software 2025
3 days 1 hour ago
Free data recovery software or tools are among the most essential tools, playing a crucial role in our lives. Although you can find dozens of them nowadays, their importance remains significant. Losing our data from a device due to failure of the device, an attack by ransomware or accidentally erasing of data can become a […]
The post 10 Best Free Data Recovery Software 2025 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Kaaviya
Google Chrome security advisory (AV25-520)
3 days 1 hour ago
Canadian Centre for Cyber Security
Гиперядра: начало разгадки одной из самых странных тайн ядерной физики?
3 days 1 hour ago
Физики построили карту из ничего — и доказали, что пустота управляет Вселенной.
From Awareness to Action: Building Lasting Cybersecurity Habits
3 days 1 hour ago
Every October, organizations revisit the same cybersecurity routines. "Security is everyone’s responsibility,” makes the rounds. However, if awareness alone were enough, we would not see so many security incidents linked to human behavior.
CVE-2024-6233 | Check Point ZoneAlarm Extreme Security prior 4.2.712 link following (ZDI-24-1036)
3 days 1 hour ago
A vulnerability was found in Check Point ZoneAlarm Extreme Security. It has been classified as critical. This vulnerability affects unknown code. The manipulation leads to link following.
This vulnerability was named CVE-2024-6233. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6260 | Malwarebytes Antimalware link following (ZDI-24-1195)
3 days 1 hour ago
A vulnerability identified as critical has been detected in Malwarebytes Antimalware. Affected by this issue is some unknown functionality. The manipulation leads to link following.
This vulnerability is handled as CVE-2024-6260. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52304 | aio-libs aiohttp up to 3.10.10 request smuggling (Nessus ID 211948)
3 days 1 hour ago
A vulnerability was found in aio-libs aiohttp up to 3.10.10. It has been rated as problematic. Affected is an unknown function. The manipulation leads to http request smuggling.
This vulnerability is traded as CVE-2024-52304. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41779 | IBM Engineering Systems Design Rhapsody 7.0.2/7.0.3 Request toctou (Nessus ID 214595)
3 days 1 hour ago
A vulnerability classified as critical has been found in IBM Engineering Systems Design Rhapsody 7.0.2/7.0.3. This vulnerability affects unknown code of the component Request Handler. The manipulation leads to time-of-check time-of-use.
This vulnerability was named CVE-2024-41779. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52877 | Insyde InsydeH2O up to 05.70.49 VariableRuntimeDxe Driver buffer overflow
3 days 1 hour ago
A vulnerability labeled as critical has been found in Insyde InsydeH2O up to 05.70.49. This issue affects some unknown processing of the component VariableRuntimeDxe Driver. The manipulation leads to buffer overflow.
The identification of this vulnerability is CVE-2024-52877. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52879 | Insyde InsydeH2O up to 05.70.49 VariableRuntimeDxe Driver SmmUpdateVariablePropertySmi comparison
3 days 1 hour ago
A vulnerability marked as critical has been reported in Insyde InsydeH2O up to 05.70.49. Affected is the function SmmUpdateVariablePropertySmi of the component VariableRuntimeDxe Driver. The manipulation leads to incorrect comparison.
This vulnerability is traded as CVE-2024-52879. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52878 | Insyde InsydeH2O up to 05.70.49 VariableRuntimeDxe Driver VariableServicesSetVariable buffer overflow
3 days 1 hour ago
A vulnerability described as critical has been identified in Insyde InsydeH2O up to 05.70.49. Affected by this vulnerability is the function VariableServicesSetVariable of the component VariableRuntimeDxe Driver. The manipulation leads to buffer overflow.
This vulnerability is known as CVE-2024-52878. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-8803 | Open5GS up to 2.7.5 AMF src/amf/gmm-sm.c gmm_state_de_registered/gmm_state_exception denial of service (Issue 3948 / EUVD-2025-24085)
3 days 1 hour ago
A vulnerability was found in Open5GS up to 2.7.5. It has been classified as problematic. Affected is the function gmm_state_de_registered/gmm_state_exception of the file src/amf/gmm-sm.c of the component AMF. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2025-8803. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-3480 | MicroDicom Web DICOM Viewer cleartext transmission (EUVD-2025-16102)
3 days 1 hour ago
A vulnerability marked as problematic has been reported in MicroDicom Web DICOM Viewer. Affected by this issue is some unknown functionality. The manipulation leads to cleartext transmission of sensitive information.
This vulnerability is handled as CVE-2025-3480. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41781 | IBM PowerVM Hypervisor up to FW950.90/FW1030.60/FW1050.20/FW1060.10 HMC exposure of sensitive system information to an unauthorized control sphere
3 days 1 hour ago
A vulnerability classified as problematic was found in IBM PowerVM Hypervisor up to FW950.90/FW1030.60/FW1050.20/FW1060.10. This issue affects some unknown processing of the component HMC. The manipulation leads to exposure of sensitive system information to an unauthorized control sphere.
The identification of this vulnerability is CVE-2024-41781. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-27847 | ESPEC North America Web Controller 3 up to 3.3.7 /api/v4/auth/ privilege escalation (EUVD-2025-24832)
3 days 1 hour ago
A vulnerability, which was classified as problematic, was found in ESPEC North America Web Controller 3 up to 3.3.7. This affects an unknown part of the file /api/v4/auth/. The manipulation leads to privilege escalation.
This vulnerability is uniquely identified as CVE-2025-27847. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-27846 | ESPEC North America Web Controller 3 up to 3.3.7 GRUB Local Privilege Escalation (EUVD-2025-24833)
3 days 1 hour ago
A vulnerability was found in ESPEC North America Web Controller 3 up to 3.3.7 and classified as problematic. This issue affects some unknown processing of the component GRUB. The manipulation leads to Local Privilege Escalation.
The identification of this vulnerability is CVE-2025-27846. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-9008 | itsourcecode Online Tour and Travel Management System 1.0 /admin/sms_setting.php uname sql injection (EUVD-2025-24981)
3 days 1 hour ago
A vulnerability described as critical has been identified in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/sms_setting.php. The manipulation of the argument uname leads to sql injection.
The identification of this vulnerability is CVE-2025-9008. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-7688 | Add User Meta Plugin up to 1.0.1 on WordPress Setting cross-site request forgery (EUVD-2025-25003)
3 days 1 hour ago
A vulnerability labeled as problematic has been found in Add User Meta Plugin up to 1.0.1 on WordPress. This affects an unknown part of the component Setting Handler. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2025-7688. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com