Aggregator
Russian hackers attack Western military mission using malicious drive
10 months ago
The Russian state-backed hacking group Gamaredon (aka "Shuckworm") has been targeting a military mission of a Western country in Ukraine in attacks likely deployed from removable drives. [...]
Bill Toulas
CVE-2007-6039 | PHP 5.2.4 ngettext classname input validation (EDB-30760 / Nessus ID 32123)
10 months ago
A vulnerability, which was classified as problematic, was found in PHP 5.2.4. This affects the function ngettext. The manipulation of the argument classname leads to improper input validation.
This vulnerability is uniquely identified as CVE-2007-6039. The attack needs to be approached locally. Furthermore, there is an exploit available.
vuldb.com
CVE-2023-41848 | Majeed Raza Carousel Slider Plugin up to 2.2.2 on WordPress authorization
10 months ago
A vulnerability, which was classified as problematic, has been found in Majeed Raza Carousel Slider Plugin up to 2.2.2 on WordPress. This issue affects some unknown processing. The manipulation leads to missing authorization.
The identification of this vulnerability is CVE-2023-41848. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-25678 | Tenda i12 1.0.0.10(3805) formSetCfm funcpara1 buffer overflow
10 months ago
A vulnerability classified as critical has been found in Tenda i12 1.0.0.10(3805). This affects the function formSetCfm. The manipulation of the argument funcpara1 leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2025-25678. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-25676 | Tenda i12 1.0.0.10 Parameter formwrlSSIDset list buffer overflow
10 months ago
A vulnerability classified as critical was found in Tenda i12 1.0.0.10. This vulnerability affects the function formwrlSSIDset of the component Parameter Handler. The manipulation of the argument list leads to buffer overflow.
This vulnerability was named CVE-2025-25676. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-25507 | Tenda AC6 15.03.05.16 formexeCommand cmdinput code injection
10 months ago
A vulnerability classified as critical has been found in Tenda AC6 15.03.05.16. This affects the function formexeCommand. The manipulation of the argument cmdinput leads to code injection.
This vulnerability is uniquely identified as CVE-2025-25507. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-25505 | Tenda AC6 15.03.05.16 sub_452A4 buffer overflow
10 months ago
A vulnerability, which was classified as critical, has been found in Tenda AC6 15.03.05.16. This issue affects the function sub_452A4. The manipulation leads to buffer overflow.
The identification of this vulnerability is CVE-2025-25505. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-4372 | Carousel Slider Plugin up to 2.2.10 on WordPress cross site scripting
10 months ago
A vulnerability classified as problematic was found in Carousel Slider Plugin up to 2.2.10 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-4372. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6529 | Ultimate Classified Listings Plugin up to 1.3 on WordPress cross site scripting
10 months ago
A vulnerability was found in Ultimate Classified Listings Plugin up to 1.3 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-6529. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-0995 | Google Chrome up to 133.0.6943.53 V8 use after free (Nessus ID 216177)
10 months ago
A vulnerability, which was classified as critical, was found in Google Chrome. Affected is an unknown function of the component V8. The manipulation leads to use after free.
This vulnerability is traded as CVE-2025-0995. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-0996 | Google Chrome 2025-01-23 Browser UI homoglyph (Nessus ID 216177)
10 months ago
A vulnerability has been found in Google Chrome 2025-01-23 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Browser UI. The manipulation leads to insufficient visual distinction of homoglyphs presented to user.
This vulnerability is known as CVE-2025-0996. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Incomplete Patch in NVIDIA Toolkit Leaves CVE-2024-0132 Open to Container Escapes
10 months ago
Cybersecurity researchers have detailed a case of an incomplete patch for a previously addressed security flaw impacting the NVIDIA Container Toolkit that, if successfully exploited, could put sensitive data at risk.
The original vulnerability CVE-2024-0132 (CVSS score: 9.0) is a Time-of-Check Time-of-Use (TOCTOU) vulnerability that could lead to a container escape attack and allow for
The Hacker News
INC
10 months ago
cohenido
Making Super Slurper 5x faster with Workers, Durable Objects, and Queues
10 months ago
We re-architected Super Slurper from the ground up using our Developer Platform — leveraging Cloudflare Workers, Durable Objects, and Queues — and improved transfer speeds by up to 5x.
Connor Maddox
CVE-2024-30449 | Booking Activities Plugin up to 1.15.19 on WordPress cross site scripting
10 months ago
A vulnerability was found in Booking Activities Plugin up to 1.15.19 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-30449. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-30450 | Step-Byte-Service OpenStreetMap for Gutenberg and WPBakery Page Builder Plugin cross site scripting
10 months ago
A vulnerability was found in Step-Byte-Service OpenStreetMap for Gutenberg and WPBakery Page Builder Plugin up to 1.1.1 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-30450. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-30447 | Creative Solutions Creative Image Slider Plugin up to 2.1.3 on WordPress cross site scripting
10 months ago
A vulnerability classified as problematic has been found in Creative Solutions Creative Image Slider Plugin up to 2.1.3 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-30447. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-30452 | PluginOps Landing Page Builder Plugin up to 1.5.1.7 on WordPress cross site scripting
10 months ago
A vulnerability classified as problematic was found in PluginOps Landing Page Builder Plugin up to 1.5.1.7 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-30452. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-30451 | Infinitum Forum Geo Controller Plugin up to 8.6.4 on WordPress cross site scripting
10 months ago
A vulnerability, which was classified as problematic, was found in Infinitum Forum Geo Controller Plugin up to 8.6.4 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-30451. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com