Aggregator
CVE-2024-7840 | Progress Telerik Reporting up to 18.2.24.806 Hyperlink command injection (Nessus ID 208748)
CVE-2024-8048 | Progress Telerik Reporting up to 18.2.24.806 externally-controlled input to select classes or code (Nessus ID 208748)
CVE-2024-47815 | miraheze IncidentReporting Special:IncidentReports Page LocalSettings.php cross site scripting (43896a4)
CVE-2024-43610 | Microsoft Copilot Studio information disclosure
Operation Sea Elephant Attacking Organizations to Steal Research Details
A sophisticated cyber espionage campaign dubbed “Operation Sea Elephant” has been discovered targeting scientific research organizations, with a particular focus on ocean-related studies. The operation, attributed to a threat actor group known as CNC with South Asian origins, aims to steal valuable research data to ensure regional dominance in the Indian Ocean. The CNC group […]
The post Operation Sea Elephant Attacking Organizations to Steal Research Details appeared first on Cyber Security News.
CVE-2024-58081 | Linux Kernel up to 6.12.13/6.13.2 pm_genpd_init null pointer dereference (Nessus ID 232268)
CVE-2023-31439 | systemd 253 log file (Nessus ID 232270)
CVE-2024-58063 | Linux Kernel up to 6.1.128/6.6.75/6.12.12/6.13.1 rtlwifi pci_set_drvdata memory leak (Nessus ID 232274)
CVE-2025-21831 | Linux Kernel up to 6.6.77/6.12.13/6.13.2 PCI Privilege Escalation (Nessus ID 232276)
CVE-2021-46828 | libtirpc up to 1.3.2 svc_run file descriptor consumption (DLA 3071-1 / Nessus ID 232282)
Critical Vulnerabilities in DrayTek Routers Exposes Devices to RCE Attack
A series of critical vulnerabilities in DrayTek Vigor routers widely deployed in small office/home office (SOHO) environments have been uncovered, exposing devices to remote code execution (RCE), denial-of-service (DoS) attacks, and credential theft. The flaws discovered during firmware reverse-engineering efforts highlight systemic security weaknesses in routers that act as gateways between local networks and the […]
The post Critical Vulnerabilities in DrayTek Routers Exposes Devices to RCE Attack appeared first on Cyber Security News.
牛品推荐 | 一站式守护大模型安全的恒脑智盾
Multiple Jenkins Vulnerability Let Attackers Expose Secrets
Jenkins, the widely adopted open-source automation server central to CI/CD pipelines, has disclosed four critical security vulnerabilities enabling unauthorized secret disclosure, cross-site request forgery (CSRF), and open redirect attacks. These flaws, patched in versions 2.500 (weekly) and 2.492.2 (LTS), affect earlier releases, including Jenkins 2.499 and LTS 2.492.1. Potential impacts range from credential theft to […]
The post Multiple Jenkins Vulnerability Let Attackers Expose Secrets appeared first on Cyber Security News.