Aggregator
CVE-2025-59340 | HubSpot jinjava up to 2.8.0 Jinja Template mapper.getTypeFactory.constructFromCanonical special elements used in a template engine (GHSA-m49c-g9wr-hv6v)
CVE-2025-46813 | Discourse up to 82d84af6b0efbd9fa2aeec3e91ce7be1a768511b information disclosure (GHSA-v3h7-c287-pfg9)
CVE-2025-55602 | D-Link DIR-619L 2.06B01 formSysCmd submit-url buffer overflow
CVE-2025-55606 | Tenda AX3 16.03.12.10_CN fromAdvSetMacMtuWan serverName buffer overflow
CVE-2025-55599 | D-Link DIR-619L 2.06B01 formWlanSetup f_wds_wepKey buffer overflow
CVE-2025-55603 | Tenda AX3 16.03.12.10_CN fromSetSysTime ntpServer buffer overflow
CVE-2025-55605 | Tenda AX3 16.03.12.10_CN saveParentControlInfo deviceName buffer overflow
CVE-2025-55611 | D-Link DIR-619L 2.06B01 formLanguageChange nextPage buffer overflow
CVE-2025-48062 | Discourse up to 3.4.3/3.5.0.beta4/3.5.0.beta5-dev Email Body topic_title cross site scripting (EUVD-2025-17465)
Submit #661275: GNU Binutils 2.45 Out-of-Bounds Read [Accepted]
Prep is Underway, But 2026 FIFA World Cup Poses Significant Cyber Challenges
Microsoft releases the final Windows 10 22H2 preview update
Microsoft отключила израильскую разведку за массовое прослушивание палестинцев
GitLab High-Severity Vulnerabilities Let Attackers Crash Instances
GitLab has disclosed multiple high-severity Denial-of-Service (DoS) vulnerabilities that could allow unauthenticated attackers to crash self-managed GitLab instances. These flaws impact Community Edition (CE) and Enterprise Edition (EE) versions prior to 18.4.1, 18.3.3, and 18.2.7, and exploit both HTTP endpoints and GraphQL APIs. Administrators must upgrade immediately to prevent service interruptions and potential data loss. […]
The post GitLab High-Severity Vulnerabilities Let Attackers Crash Instances appeared first on Cyber Security News.
加拿大新不伦瑞克大学 | IoT-PRIDS:利用数据包表示进行物联网入侵检测
CVE-2025-11080 | zhuimengshaonian wisdom-education up to 1.0.4 ExamInfoController.java selectStudentExamInfoList subjectId improper authorization (EUVD-2025-31441)
Singapore Threatens Meta With Fines Over Facebook Impersonation Scams
Fortra GoAnywhere Vulnerability Exploited as 0-Day Before Patch
A critical, perfect 10.0 CVSS score vulnerability in Fortra’s GoAnywhere Managed File Transfer (MFT) solution was actively exploited as a zero-day at least a week before the company released a patch. The vulnerability, tracked as CVE-2025-10035, is a command injection flaw that allows for unauthenticated remote code execution. Security firm watchTowr reported credible evidence of […]
The post Fortra GoAnywhere Vulnerability Exploited as 0-Day Before Patch appeared first on Cyber Security News.
New Variant of The XCSSET Malware Attacking macOS App Developers
The macOS threat landscape has witnessed a significant escalation with the discovery of a new variant of the XCSSET malware targeting app developers. First observed in late September 2025, this variant builds upon earlier versions by introducing enhanced stealth techniques, expanded exfiltration capabilities, and robust persistence mechanisms. Attackers continue to leverage infected Xcode projects—the cornerstone […]
The post New Variant of The XCSSET Malware Attacking macOS App Developers appeared first on Cyber Security News.