Aggregator
CISA Flags Craft CMS Vulnerability CVE-2025-23209 Amid Active Attacks
FreeBuf周报 | 马斯克DOGE网站数据库存在漏洞;OpenSSH曝高危漏洞
CISA Issues Seven ICS Advisories Highlighting Critical Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released seven Industrial Control Systems (ICS) advisories on February 20, 2025, addressing critical vulnerabilities in products from ABB, Siemens, Mitsubishi Electric, and other industrial technology providers. These advisories underscore escalating risks to operational technology (OT) environments, where flaws in safety controllers, human-machine interfaces (HMIs), and protocol analyzers […]
The post CISA Issues Seven ICS Advisories Highlighting Critical Vulnerabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-1536 | Raisecom Multi-Service Intelligent Gateway up to 20250208 Request Parameter vpn_template_style.php stylenum os command injection
CVE-2025-1535 | Baiyi Cloud Asset Management System 8.142.100.161 admin.ticket.close.php ticket_id sql injection
Submit #497021: Raisecom Technology Co., Ltd. Raisecom Multi-Service Intelligent Gateway vpn_template_style.php Command Injection [Accepted]
CVE-2025-25957 | XunRuiCMS up to 4.6.3 cross site scripting
CVE-2025-25674 | Tenda AC10 15.03.06.23 Setting form_fast_setting_wifi_set ssid buffer overflow
CVE-2025-25662 | Tenda O4 1.0.0.10(2936) /goform/setMacFilterList SafeSetMacFilter remark buffer overflow
CVE-2025-27088 | oxyno-zeta s3-proxy up to 4.17.x Request.URL.Path cross site scripting (GHSA-pp9m-qf39-hxjc)
CVE-2025-25676 | Tenda i12 1.0.0.10 Parameter formwrlSSIDset list buffer overflow
CVE-2025-25678 | Tenda i12 1.0.0.10(3805) formSetCfm funcpara1 buffer overflow
CVE-2025-25668 | Tenda AC8V4 16.03.34.06 sub_47D878 shareSpeed stack-based overflow
CVE-2025-25667 | Tenda AC8V4 16.03.34.06 get_parentControl_list_Info urls stack-based overflow
Submit #496969: Hunan Zhonghe Baiyi Information Technology Co., Ltd. Baiyi Cloud Asset Management System /wuser/admin.ticket.close.php SQL Injection [Accepted]
CVE-2025-25679 | Tenda i12 1.0.0.10(3805) formWifiMacFilterSet index buffer overflow
CVE-2025-25664 | Tenda AC8V4 16.03.34.06 sub_49E098 shareSpeed stack-based overflow
CVE-2025-25960 | phpcmsv9 9.6.3 Menu Interface cross site scripting
Pegasus Spyware Now Targeting Business Executives and Financial Sector Professionals
The once-shadowy realm of Pegasus spyware has breached new frontiers, with forensic analyses revealing a stark pivot from targeting journalists and activists to infiltrating the private sector. In December 2024, mobile security firm iVerify detected 11 new Pegasus infections among 18,000 scanned devices—a 1.5 per 1,000 incidence rate—exposing finance, real estate, and logistics executives to […]
The post Pegasus Spyware Now Targeting Business Executives and Financial Sector Professionals appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.