Aggregator
Hunters
9 months 2 weeks ago
cohenido
警报拉响!新型 SVG 文件钓鱼攻击激增,传统防护体系濒临崩溃
9 months 2 weeks ago
安全客
M&S Shuts Down Online Orders Amid Ongoing Cyber Incident
9 months 2 weeks ago
British retailer M&S continues to tackle a cyber incident with online orders now paused for customers
【复现】金蝶天燕应用服务器IIOP远程代码执行漏洞风险通告
9 months 2 weeks ago
【复现】金蝶天燕应用服务器IIOP远程代码执行漏洞风险通告
9 months 2 weeks ago
CVE-2024-57375 | Andamiro Pump It Up up to 2.08.3 initialization of resource
9 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Andamiro Pump It Up up to 2.08.3. This issue affects some unknown processing. The manipulation leads to incorrect initialization of resource. This vulnerability only affects products that are no longer supported by the maintainer.
The identification of this vulnerability is CVE-2024-57375. It is possible to launch the attack on the physical device. There is no exploit available.
vuldb.com
CVE-2023-0342 | MongoDB Ops Manager up to 5.0.20/6.0.11 Diagnostics Archive exposure of sensitive system information to an unauthorized control sphere
9 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in MongoDB Ops Manager up to 5.0.20/6.0.11. This affects an unknown part of the component Diagnostics Archive. The manipulation leads to exposure of sensitive system information to an unauthorized control sphere.
This vulnerability is uniquely identified as CVE-2023-0342. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-3184 | SourceCodester Sales Tracker Management System 1.0 Users.php?f=save firstname/middlename/lastname/username cross site scripting (ID 172908 / EDB-51513)
9 months 2 weeks ago
A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /classes/Users.php?f=save. The manipulation of the argument firstname/middlename/lastname/username leads to cross site scripting.
This vulnerability is handled as CVE-2023-3184. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2023-34856 | D-Link DI-7500G-CI 19.05.29A HTML File /auth_pic.cgi HTML injection
9 months 2 weeks ago
A vulnerability classified as problematic has been found in D-Link DI-7500G-CI 19.05.29A. Affected is an unknown function of the file /auth_pic.cgi of the component HTML File Handler. The manipulation leads to HTML injection.
This vulnerability is traded as CVE-2023-34856. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2023-23913 | actionview Gem on Ruby rails-ujs cross site scripting
9 months 2 weeks ago
A vulnerability was found in actionview Gem on Ruby. It has been classified as problematic. Affected is an unknown function of the component rails-ujs. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2023-23913. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Kubernetes 集群安全漏洞遭利用,算力资源面临严重危机
9 months 2 weeks ago
安全客
CVE-2025-28354 | Entrust Printer Manager Systm up to D3.18.4-3 POST Request path traversal
9 months 2 weeks ago
A vulnerability classified as critical was found in Entrust Printer Manager Systm up to D3.18.4-3. This vulnerability affects unknown code of the component POST Request Handler. The manipulation leads to path traversal.
This vulnerability was named CVE-2025-28354. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2005-1782 | BookReview add_booklist.htm node cross site scripting (EDB-25731 / Nessus ID 18375)
9 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in BookReview. Affected by this issue is some unknown functionality of the file add_booklist.htm. The manipulation of the argument node leads to basic cross site scripting.
This vulnerability is handled as CVE-2005-1782. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Windows "inetpub" security fix can be abused to block future updates
9 months 2 weeks ago
A recent Windows security update that creates an 'inetpub' folder has introduced a new weakness allowing attackers to prevent the installation of future updates. [...]
Lawrence Abrams
CVE-2007-1717 | PHP up to 4.0.0 mail memory corruption (EDB-29784 / Nessus ID 25340)
9 months 2 weeks ago
A vulnerability was found in PHP up to 4.0.0. It has been classified as critical. This affects the function mail. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2007-1717. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Baltimore City Public Schools data breach affects over 31,000 people
9 months 2 weeks ago
Baltimore City Public Schools notified tens of thousands of employees and students of a data breach following an incident in February when unknown attackers hacked into its network. [...]
Sergiu Gatlan
North Korean Hackers Spread Malware via Fake Crypto Firms and Job Interview Lures
9 months 2 weeks ago
North Korea-linked threat actors behind the Contagious Interview have set up front companies as a way to distribute malware during the fake hiring process.
"In this new campaign, the threat actor group is using three front companies in the cryptocurrency consulting industry – BlockNovas LLC (blocknovas[.] com), Angeloper Agency (angeloper[.]com), and SoftGlide LLC (softglide[.]co) – to spread
The Hacker News
Russian Hackers Attempting to Sabotage The Digital Control System of a Dutch Public Service
9 months 2 weeks ago
In a concerning development that marks a significant escalation in cyber warfare tactics, Russian hackers have been detected attempting to infiltrate and sabotage the digital control system of a critical Dutch public service. The attack, identified in 2024, represents the first known cyber sabotage attempt against Dutch infrastructure, setting a dangerous precedent for future operations. […]
The post Russian Hackers Attempting to Sabotage The Digital Control System of a Dutch Public Service appeared first on Cyber Security News.
Tushar Subhra Dutta
Akira
9 months 2 weeks ago
cohenido