Aggregator
零售巨头 Ahold Delhaize 称数据泄露波及约 220 万人
9 months 2 weeks ago
安全客
GIFTEDCROOK恶意软件演变:从浏览器窃取者到情报收集工具
9 months 2 weeks ago
安全客
CVE-2025-45872 | ZrLog 3.1.5 downloadUrl server-side request forgery (EUVD-2025-19617)
9 months 2 weeks ago
A vulnerability has been found in ZrLog 3.1.5 and classified as critical. This vulnerability affects unknown code. The manipulation of the argument downloadUrl leads to server-side request forgery.
This vulnerability was named CVE-2025-45872. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-37097 | HPE Insight Remote Support up to 7.15.0.646 denial of service (EUVD-2025-19614)
9 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in HPE Insight Remote Support up to 7.15.0.646. This affects an unknown part. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2025-37097. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Stealthy WordPress Malware Deliver Windows Trojan via PHP Backdoor
9 months 2 weeks ago
A sophisticated multi-stage malware campaign has been discovered targeting WordPress websites, employing an intricate infection chain that delivers Windows trojans to unsuspecting visitors while maintaining complete invisibility to standard security checks. The malware represents a significant evolution in web-based attack techniques, combining PHP backdoors with advanced evasion mechanisms to establish persistent access to victim systems. […]
The post Stealthy WordPress Malware Deliver Windows Trojan via PHP Backdoor appeared first on Cyber Security News.
Tushar Subhra Dutta
Chrome Zero-Day, 'FoxyWallet' Firefox Attacks Threaten Browsers
9 months 2 weeks ago
Separate threats to popular browsers highlight the growing security risk for enterprises presented by the original gateway to the Web, which remains an integral tool for corporate users.
Elizabeth Montalbano, Contributing Writer
New Report Uncovers Major Overlaps in Cybercrime and State-Sponsored Espionage
9 months 2 weeks ago
Proofpoint has identified similarities between the tactics of a pro-Russian cyber espionage group and a cybercriminal gang
Militaire hulp voor politie
9 months 2 weeks ago
Sinds vandaag draait het Tactisch Coördinatiecentrum Politie Militaire Dreiging (TCCP-MD). Dit landelijke centrum helpt de politie voor te bereiden op grootschalige crises als gevolg van militaire dreiging. Denk aan sabotage, digitale aanvallen of verspreiding van nepnieuws die de samenleving kunnen ontregelen. Het TCCP-MD kijkt verder dan de eerste 72 uur na een incident. Het centrum richt zich op langdurige situaties, waarin de politie maanden of jaren actief moet blijven.
International Criminal Court hit by new 'sophisticated' cyberattack
9 months 2 weeks ago
On Monday, the International Criminal Court (ICC) announced that it's investigating a new "sophisticated" cyberattack that targeted its systems last week. [...]
Sergiu Gatlan
CVE-2024-46657 | Artifex MuPDF 1.24.9 PDF File /tools/pdfextract.c memory corruption (Nessus ID 213550)
9 months 2 weeks ago
A vulnerability has been found in Artifex MuPDF 1.24.9 and classified as critical. This vulnerability affects unknown code of the file /tools/pdfextract.c of the component PDF File Handler. The manipulation leads to memory corruption.
This vulnerability was named CVE-2024-46657. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-50930 | Silicon Labs Z-Wave Series 500 6.84.0 permissions
9 months 2 weeks ago
A vulnerability was found in Silicon Labs Z-Wave Series 500 6.84.0. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to preservation of permissions.
The identification of this vulnerability is CVE-2024-50930. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2025-6835 | code-projects Library System 1.0 /student-issue-book.php reg sql injection (EUVD-2025-19465)
9 months 2 weeks ago
A vulnerability was found in code-projects Library System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /student-issue-book.php. The manipulation of the argument reg leads to sql injection.
The identification of this vulnerability is CVE-2025-6835. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6848 | code-projects Simple Forum 1.0 /forum1.php File unrestricted upload
9 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in code-projects Simple Forum 1.0. This issue affects some unknown processing of the file /forum1.php. The manipulation of the argument File leads to unrestricted upload.
The identification of this vulnerability is CVE-2025-6848. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6860 | SourceCodester Best Salon Management System 1.0 staff_commision.php fromdate/todate sql injection (EUVD-2025-19483)
9 months 2 weeks ago
A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /panel/staff_commision.php. The manipulation of the argument fromdate/todate leads to sql injection.
This vulnerability was named CVE-2025-6860. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6861 | SourceCodester Best Salon Management System 1.0 /panel/add_plan.php plan_name/description/duration_days/price sql injection (EUVD-2025-19485)
9 months 2 weeks ago
A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /panel/add_plan.php. The manipulation of the argument plan_name/description/duration_days/price leads to sql injection.
The identification of this vulnerability is CVE-2025-6861. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6863 | PHPGurukul Local Services Search Engine Management System 2.1 edit-category-detail.php editid sql injection (EUVD-2025-19486)
9 months 2 weeks ago
A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. Affected by this vulnerability is an unknown functionality of the file /admin/edit-category-detail.php. The manipulation of the argument editid leads to sql injection.
This vulnerability is known as CVE-2025-6863. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6862 | SourceCodester Best Salon Management System 1.0 /panel/edit_plan.php editid sql injection (EUVD-2025-19487)
9 months 2 weeks ago
A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/edit_plan.php. The manipulation of the argument editid leads to sql injection.
This vulnerability is traded as CVE-2025-6862. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6822 | code-projects Inventory Management System 1.0 removeProduct.php productId sql injection (EUVD-2025-19455)
9 months 2 weeks ago
A vulnerability was found in code-projects Inventory Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /php_action/removeProduct.php. The manipulation of the argument productId leads to sql injection.
This vulnerability was named CVE-2025-6822. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6823 | code-projects Inventory Management System 1.0 editProduct.php editProductName sql injection (EUVD-2025-19457)
9 months 2 weeks ago
A vulnerability was found in code-projects Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /php_action/editProduct.php. The manipulation of the argument editProductName leads to sql injection.
The identification of this vulnerability is CVE-2025-6823. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com