Aggregator
Water Saci黑客组织利用AI工具,针对WhatsApp Web用户发起攻击
1 month 2 weeks ago
安全客
GlassWorm恶意攻击活动再现:以24个伪装成流行开发工具的恶意扩展为载体进行传播
1 month 2 weeks ago
安全客
恶意Rust软件包“evm-units”使加密货币开发者面临隐秘攻击风险
1 month 2 weeks ago
安全客
WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts
1 month 2 weeks ago
A critical security flaw impacting a WordPress plugin known as King Addons for Elementor has come under active exploitation in the wild.
The vulnerability, CVE-2025-8489 (CVSS score: 9.8), is a case of privilege escalation that allows unauthenticated attackers to grant themselves administrative privileges by simply specifying the administrator user role during registration.
It affects versions
The Hacker News
CVE-2025-11379 | WebP Express Plugin up to 0.25.9 on WordPress information disclosure
1 month 2 weeks ago
A vulnerability categorized as problematic has been discovered in WebP Express Plugin up to 0.25.9 on WordPress. This affects an unknown function. The manipulation results in information disclosure.
This vulnerability was named CVE-2025-11379. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2025-66288 | Parallels Toolbox CleanDrive link following (ZDI-25-1015)
1 month 2 weeks ago
A vulnerability was found in Parallels Toolbox. It has been rated as critical. The impacted element is an unknown function of the component CleanDrive. The manipulation leads to link following.
This vulnerability is uniquely identified as CVE-2025-66288. Local access is required to approach this attack. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-13392 | Synology DiskStation DS925+ SYNOPAMSSO::samlAuth improper authentication (ZDI-25-1040)
1 month 2 weeks ago
A vulnerability was found in Synology DiskStation DS925+. It has been declared as critical. The affected element is the function SYNOPAMSSO::samlAuth. Executing manipulation can lead to improper authentication.
This vulnerability is handled as CVE-2025-13392. The attack can only be done within the local network. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Google expands Android scam protection feature to Chase, Cash App in U.S.
1 month 2 weeks ago
Google is expanding support for its Android's in-call scam protection to multiple banks and financial applications in the United States. [...]
Bill Toulas
Android expands pilot for in-call scam protection for financial apps
1 month 2 weeks ago
Edward Fernandez
CVE-2025-12686 | Synology BeeStation Plus auth_info stack-based overflow (ZDI-25-1039)
1 month 2 weeks ago
A vulnerability was found in Synology BeeStation Plus. It has been classified as critical. Impacted is an unknown function. Performing manipulation of the argument auth_info results in stack-based buffer overflow.
This vulnerability is known as CVE-2025-12686. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-11727 | Omnichannel for WooCommerce Plugin up to 1.3.65 on WordPress sync cross site scripting
1 month 2 weeks ago
A vulnerability was found in Omnichannel for WooCommerce Plugin up to 1.3.65 on WordPress and classified as problematic. This issue affects the function sync. Such manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-11727. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-55076 | Plugin Alliance Installation Manager 1.4.0 InstallationHelper Service system Local Privilege Escalation
1 month 2 weeks ago
A vulnerability has been found in Plugin Alliance Installation Manager 1.4.0 and classified as critical. This vulnerability affects the function system of the component InstallationHelper Service. This manipulation causes Local Privilege Escalation.
This vulnerability appears as CVE-2025-55076. The attack requires local access. There is no available exploit.
vuldb.com
CVE-2025-13751 | OpenVPN up to 2.7_rc2 on Windows Interactive Service Agent allocation of resources
1 month 2 weeks ago
A vulnerability, which was classified as problematic, was found in OpenVPN up to 2.7_rc2 on Windows. This affects an unknown part of the component Interactive Service Agent. The manipulation results in allocation of resources.
This vulnerability is reported as CVE-2025-13751. The attack requires a local approach. No exploit exists.
vuldb.com
CVE-2024-32642 | MasaCMS up to 7.2.7/7.3.12/7.4.5 Password Reset origin validation
1 month 2 weeks ago
A vulnerability, which was classified as critical, has been found in MasaCMS up to 7.2.7/7.3.12/7.4.5. Affected by this issue is some unknown functionality of the component Password Reset Handler. The manipulation leads to origin validation error.
This vulnerability is documented as CVE-2024-32642. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-65843 | Aquarius Desktop 3.0.069 on macOS ~/Library/Logs/Aquarius information disclosure
1 month 2 weeks ago
A vulnerability classified as problematic was found in Aquarius Desktop 3.0.069 on macOS. Affected by this vulnerability is an unknown functionality in the library ~/Library/Logs/Aquarius. Executing manipulation can lead to information disclosure.
This vulnerability is registered as CVE-2025-65843. The attack needs to be launched locally. No exploit is available.
vuldb.com
CVE-2025-13492 | HP Image Assistant up to 5.3.2 race condition
1 month 2 weeks ago
A vulnerability classified as critical has been found in HP Image Assistant up to 5.3.2. Affected is an unknown function. Performing manipulation results in race condition enabling link following.
This vulnerability is cataloged as CVE-2025-13492. The attack must be initiated from a local position. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-32641 | MasaCMS up to 7.2.7/7.3.12/7.4.5 addParam criteria code injection
1 month 2 weeks ago
A vulnerability described as critical has been identified in MasaCMS up to 7.2.7/7.3.12/7.4.5. This impacts the function addParam. Such manipulation of the argument criteria leads to code injection.
This vulnerability is listed as CVE-2024-32641. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-62686 | Plugin Alliance Installation Manager 1.4.0 on macOS InstallationHelper Service DYLD_INSERT_LIBRARIES injection
1 month 2 weeks ago
A vulnerability marked as problematic has been reported in Plugin Alliance Installation Manager 1.4.0 on macOS. This affects an unknown function of the component InstallationHelper Service. This manipulation of the argument DYLD_INSERT_LIBRARIES causes injection.
This vulnerability is tracked as CVE-2025-62686. The attack is restricted to local execution. No exploit exists.
vuldb.com
Конец эпохи дорогих ракет ПВО: первый боевой лазер в истории сбивает дроны за центы вместо сотен тысяч долларов
1 month 2 weeks ago
Израиль развертывает Iron Beam — технологию, которая поражает цели за секунды без участия человека.