Aggregator
零信任安全架构:从理论到实践
8 months 3 weeks ago
dewei吴彦祖
PJobRAT Android Malware Masquerades as Dating and Messaging Apps to Target Military Personnel
8 months 3 weeks ago
PJobRAT, an Android Remote Access Trojan (RAT) first identified in 2019, has resurfaced in a new campaign targeting users in Taiwan. Initially, PJobRAT was known for targeting Indian military personnel by disguising itself as dating and instant messaging apps. The latest iteration of this malware has evolved, now masquerading as apps like ‘SangaalLite’ and ‘CChat’, […]
The post PJobRAT Android Malware Masquerades as Dating and Messaging Apps to Target Military Personnel appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Aman Mishra
SYLHET GANG-SG Targeted the Website of Hartsfield-Jackson Atlanta International Airport
8 months 3 weeks ago
SYLHET GANG-SG Targeted the Website of Hartsfield-Jackson Atlanta International Airport
Dark Web Informer - Cyber Threat Intelligence
Phishing-as-a-service operation uses DNS-over-HTTPS for evasion
8 months 3 weeks ago
A newly discovered phishing-as-a-service (PhaaS) operation that researchers call Morphing Meerkat, has been using the DNS over HTTPS (DoH) protocol to evade detection. [...]
Bill Toulas
Биология против мифов: 76 способов, которыми беременность и роды меняют тело человека
8 months 3 weeks ago
Данные 300 000 родов показывают, как важнейшие биологические показатели изменяются при вынашивании и рождении ребенка.
CVE-2025-1781 | W3C CSS Validator prior 20250226 XML xml external entity reference (GHSA-745m-xmq6-g6x7)
8 months 3 weeks ago
A vulnerability was found in W3C CSS Validator and classified as critical. Affected by this issue is some unknown functionality of the component XML Handler. The manipulation leads to xml external entity reference.
This vulnerability is handled as CVE-2025-1781. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-31010 | ReichertBrothers SimplyRETS Real Estate IDX Plugin up to 3.0.3 on WordPress cross-site request forgery
8 months 3 weeks ago
A vulnerability has been found in ReichertBrothers SimplyRETS Real Estate IDX Plugin up to 3.0.3 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2025-31010. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-2901 | Red Hat JBoss Enterprise Application Platform Management Console cross site scripting
8 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Red Hat JBoss Enterprise Application Platform and JBoss Enterprise Application Platform Expansion Pack. Affected is an unknown function of the component Management Console. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-2901. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-54291 | PluginPass Plugin up to 0.9.10 on WordPress path traversal
8 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in PluginPass Plugin up to 0.9.10 on WordPress. This issue affects some unknown processing. The manipulation leads to path traversal.
The identification of this vulnerability is CVE-2024-54291. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-30371 | Metabase GeoJson Endpoint link following (GHSA-8xf9-9jc8-qp98)
8 months 3 weeks ago
A vulnerability classified as problematic was found in Metabase. This vulnerability affects unknown code of the component GeoJson Endpoint. The manipulation leads to link following.
This vulnerability was named CVE-2025-30371. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-28221 | Tenda W6_S up to 1.0.0.4_510 HTTP POST Request set_local_time Time buffer overflow
8 months 3 weeks ago
A vulnerability classified as critical has been found in Tenda W6_S up to 1.0.0.4_510. This affects the function set_local_time of the component HTTP POST Request Handler. The manipulation of the argument Time leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2025-28221. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-39311 | Publify up to 10.0.0 on Rails cross site scripting (GHSA-8fm5-gg2f-f66q)
8 months 3 weeks ago
A vulnerability was found in Publify up to 10.0.0 on Rails. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-39311. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-2877 | Red Hat Ansible Automation Platform 2 Event-Driven Ansible debug messages revealing unnecessary information
8 months 3 weeks ago
A vulnerability was found in Red Hat Ansible Automation Platform 2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Event-Driven Ansible. The manipulation leads to debug messages revealing unnecessary information.
This vulnerability is known as CVE-2025-2877. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-29928 | goauthentik prior 2024.12.4/2025.2.3 Web Interface/API session fixiation (GHSA-p6p8-f853-9g2p)
8 months 3 weeks ago
A vulnerability was found in goauthentik authentik. It has been classified as critical. Affected is an unknown function of the component Web Interface/API. The manipulation leads to session fixiation.
This vulnerability is traded as CVE-2025-29928. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-2713 | Google gVisor 2018-08-22/2018-08-23/2018-11-01/20241028.0 runsc privileges management
8 months 3 weeks ago
A vulnerability was found in Google gVisor 2018-08-22/2018-08-23/2018-11-01/20241028.0 and classified as problematic. This issue affects some unknown processing of the component runsc. The manipulation leads to improper privilege management.
The identification of this vulnerability is CVE-2025-2713. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-30211 | erlang otp up to 27.3.0 memory allocation (GHSA-vvr3-fjhh-cfwc)
8 months 3 weeks ago
A vulnerability has been found in erlang otp up to 27.3.0 and classified as critical. This vulnerability affects unknown code. The manipulation leads to uncontrolled memory allocation.
This vulnerability was named CVE-2025-30211. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-28220 | Tenda W6_S up to 1.0.0.4_510 POST Request setcfm funcpara1 buffer overflow
8 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Tenda W6_S up to 1.0.0.4_510. This affects the function setcfm of the component POST Request Handler. The manipulation of the argument funcpara1 leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2025-28220. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-28219 | Netgear DC112A up to 1.0.0.64 HTTP POST Request usb_adv.cgi deviceName os command injection
8 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Netgear DC112A up to 1.0.0.64. Affected by this issue is some unknown functionality of the file usb_adv.cgi of the component HTTP POST Request Handler. The manipulation of the argument deviceName leads to os command injection.
This vulnerability is handled as CVE-2025-28219. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-30372 | Emlog Pro up to 2.5.8 search_controller.php sql injection (GHSA-w6xc-r6x5-m77c)
8 months 3 weeks ago
A vulnerability classified as critical was found in Emlog Pro up to 2.5.8. Affected by this vulnerability is an unknown functionality of the file search_controller.php. The manipulation leads to sql injection.
This vulnerability is known as CVE-2025-30372. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com