A vulnerability classified as critical has been found in Nvidia GPU Display Driver, vGPU Driver and Cloud Gaming Driver up to 13.9/16.3 on Windows. This affects an unknown part of the component User Mode Layer. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2024-0071. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Poporon Pz-LinkCard Plugin up to 2.5.1 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-0672. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in Poporon Pz-LinkCard Plugin up to 2.5.1 on WordPress and classified as problematic. Affected by this issue is some unknown functionality of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-0673. The attack may be launched remotely. There is no exploit available.
A vulnerability, which was classified as problematic, has been found in realmag777 BEAR Plugin up to 1.1.4.2 on WordPress. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-30200. The attack may be initiated remotely. There is no exploit available.
A vulnerability classified as problematic has been found in Archetyped Favicon Rotator Plugin up to 1.2.10 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-28001. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in Galacticomm Worldgroup Lite Personal Server up to 3.20 and classified as very critical. Affected by this issue is some unknown functionality of the component HTTP GET Request Handler. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2002-0335. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability classified as critical was found in Microsoft Windows. This vulnerability affects unknown code in the library upnphost.dll. The manipulation leads to sensitive data storage in improperly locked memory.
This vulnerability was named CVE-2025-26665. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in Microsoft Windows. It has been classified as critical. This affects an unknown part of the component LDAP Client. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2025-26670. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as critical has been found in Adobe ColdFusion up to 2021.18/2023.12/2025.0. Affected is an unknown function. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2025-30289. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Microsoft Windows. It has been rated as critical. Affected by this issue is some unknown functionality of the component Lightweight Directory Access Protocol. The manipulation leads to use after free.
This vulnerability is handled as CVE-2025-26663. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability has been found in Microsoft Excel and classified as critical. This vulnerability affects unknown code. The manipulation leads to use after free.
This vulnerability was named CVE-2025-27750. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
Senior Technology, Cybersecurity Officials Removed From Interior Department The U.S. Department of Interior has reportedly removed several key cybersecurity and technology officials from their posts following a reported dispute with staffers from the Department of Government Efficiency over its access to government systems and sensitive federal data.
HHS Cites Security Risk Analysis Failures in Hack That Affected Nearly 300,000 A medical imaging practice with offices in New York and Connecticut has agreed to pay $350,000 to federal regulators and implement a corrective action plan to settle potential HIPAA violations uncovered in an investigation of a 2020 hacking incident that affected nearly 300,000 people.
Laboratory Services Cooperative Says 1.6 Million Patients, Workers, Others Affected A laboratory that provides medical testing services to Planned Parenthood is notifying 1.6 million patients, workers and those who paid for healthcare on behalf of another person that their sensitive personal and health information was accessed or removed in an October 2024 hacking incident.
Domain Controllers Commandeered to Distribute Malware, Warns Microsoft Ransomware hackers are hitting up Active Directory domain controllers to boost privileges within compromised networks, warns Microsoft. Nearly eight out of every 10 human-operated cyberattacks involves a breached domain controller. Securing the servers is a challenge.