Editors from Dark Reading, Cybersecurity Dive, and TechTarget Search Security break down the depressing state of cybersecurity awareness campaigns and how organizations can overcome basic struggles with password hygiene and phishing attacks.
A vulnerability was found in JetBrains ReSharper 2019.2. It has been rated as problematic. This impacts an unknown function of the component DPA Collector. This manipulation causes improper verification of cryptographic signature.
This vulnerability is handled as CVE-2025-64456. It is possible to launch the attack on the local host. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability was found in Fortinet FortiWeb up to 7.0.11/7.2.11/7.4.8/7.6.4. It has been classified as critical. This vulnerability affects unknown code of the component HTTP/CLI. Performing manipulation results in os command injection.
This vulnerability is identified as CVE-2025-58034. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability was found in HCL Connections 8.0. It has been classified as problematic. The affected element is an unknown function. The manipulation leads to insertion of sensitive information into sent data.
This vulnerability is referenced as CVE-2025-52639. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability was found in LibreNMS up to 25.10.x. It has been classified as critical. This issue affects some unknown processing of the file /ajax_output.php. The manipulation of the argument Hostname leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-65093. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability described as problematic has been identified in LibreNMS up to 25.10.x. Affected by this vulnerability is an unknown functionality of the file /maps/nodeimage of the component HTTP Response Handler. The manipulation of the argument Image Name results in cross site scripting.
This vulnerability is cataloged as CVE-2025-65013. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability classified as critical was found in DedeBIZ up to 6.3.2. The impacted element is an unknown function of the file /admin/archives_add.php. Such manipulation of the argument flags[] leads to sql injection.
This vulnerability is documented as CVE-2025-12927. The attack can be executed remotely. Additionally, an exploit exists.
A vulnerability was found in Linux Kernel up to 6.6.93/6.12.33/6.15.2 and classified as critical. This vulnerability affects the function phy_detach. The manipulation results in null pointer dereference.
This vulnerability is cataloged as CVE-2025-38149. The attack must originate from the local network. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in DedeBIZ up to 6.3.2. Affected by this vulnerability is an unknown functionality of the file /admin/spec_add.php. This manipulation of the argument flags[] causes sql injection.
This vulnerability is tracked as CVE-2025-12861. The attack is possible to be carried out remotely. Moreover, an exploit is present.
A vulnerability labeled as critical has been found in Apple watchOS. Affected by this vulnerability is an unknown functionality of the component Web Handler. Such manipulation leads to memory corruption.
This vulnerability is documented as CVE-2025-43343. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
A vulnerability was found in Samsung WLAN AP WEA453e. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the component Tech Support Diagnostic. This manipulation of the argument command1/command2 causes os command injection.
This vulnerability appears as CVE-2025-34068. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability categorized as very critical has been discovered in Hikvision HikCentral. Impacted is an unknown function of the file /bic/ssoService/v1/applyCT of the component Fastjson Library. The manipulation results in deserialization.
This vulnerability is identified as CVE-2025-34067. The attack can be executed remotely. There is not any exploit available.
A vulnerability classified as critical was found in Zhejiang Dahua Smart Cloud Gateway Registration Management Platform. This issue affects some unknown processing of the file /index.php/User/doLogin. The manipulation of the argument Username results in sql injection.
This vulnerability was named CVE-2025-34059. The attack may be performed from remote. In addition, an exploit is available.
A vulnerability classified as critical was found in Google Chrome. Impacted is an unknown function of the component Skia. Executing manipulation can lead to out-of-bounds write.
The identification of this vulnerability is CVE-2024-9123. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability categorized as problematic has been discovered in Google Chrome. This impacts an unknown function of the component Mojo. Executing manipulation can lead to improper validation of specified quantity in input.
This vulnerability is tracked as CVE-2024-9369. The attack is only possible within the local network. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Google Chrome. This issue affects some unknown processing of the component V8. Executing manipulation can lead to type confusion.
This vulnerability appears as CVE-2024-9602. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
A vulnerability labeled as problematic has been found in NEC RakurakuMusen Start EX. Affected by this issue is some unknown functionality. The manipulation results in uncontrolled search path.
This vulnerability is identified as CVE-2025-12852. The attack is only possible with local access. There is not any exploit available.
A vulnerability labeled as critical has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/admin_product.php. Executing manipulation of the argument product_image can lead to unrestricted upload.
The identification of this vulnerability is CVE-2025-13423. The attack may be launched remotely. Furthermore, there is an exploit available.