Aggregator
CVE-2023-7151 | WooCommerce Product Enquiry Plugin up to 3.1 on WordPress page cross site scripting
CVE-2024-0238 | EventON Plugin up to 2.2.6/4.5.4 on WordPress AJAX Action authorization
CVE-2024-0405 | Burst Statistics Really Simple Plugin up to 1.5.3 on WordPress sql injection
CVE-2023-52069 | kalcaddle kodbox 1.49.04 URL Parameter cross site scripting
CVE-2023-46952 | ABO.CMS 5.9.3 HTTP Header Referer cross site scripting
CVE-2025-32102
CVE-2024-29269
M8.2 级太阳耀斑引发 G4 级地磁风暴
CVE-2007-4552 | Agares Media Arcadem 2.0.1 index.php blockpage sql injection (EDB-4326 / BID-25418)
Preinstalled Apps on Ulefone, Krüger&Matz Phones Let Any App Reset Device, Steal PIN
Preinstalled Android Apps Found Leaking PINs and Executing Malicious Commands
On May 30, 2025, CERT Polska coordinated the public disclosure of three significant security vulnerabilities affecting preinstalled Android applications on smartphones from Ulefone and Krüger&Matz. These flaws, tracked as CVE-2024-13915, CVE-2024-13916, and CVE-2024-13917, expose users to risks ranging from unauthorized device resets to theft of sensitive PIN codes and privilege escalation by malicious applications. Technical […]
The post Preinstalled Android Apps Found Leaking PINs and Executing Malicious Commands appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Prioritizing Vulnerabilities in a Sea of Alerts
According to recent industry analysis, cybersecurity professionals are overwhelmed by a flood of security alerts. Organizations process an average of 569,354 alerts annually, yet only 2-5% require immediate action, highlighting the importance of prioritizing vulnerabilities. This overwhelming volume of notifications has created a critical challenge for security teams worldwide. They must now navigate massive amounts […]
The post Prioritizing Vulnerabilities in a Sea of Alerts appeared first on Cyber Security News.
New Linux Vulnerabilities Expose Password Hashes via Core Dumps
CVE-2024-28123 | Wasmi 128 Host out-of-bounds write
CVE-2023-50726 | argocd up to 2.8.11/2.9.0/2.9.7/2.10.0/2.10.2 privileges management (GHSA-g623-jcgg-mhmm)
CVE-2025-5447 | Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 /goform/ssid1MACFilter apselect_%d/newap_text_%d os command injection
Threat Actors Using ClickFix Technique to Deliver EddieStealer Malware
Cybersecurity researchers have identified a sophisticated new malware campaign leveraging the deceptive ClickFix technique to distribute EddieStealer, a dangerous information-stealing malware built using the Rust programming language. This emerging threat represents a significant evolution in social engineering tactics, exploiting user trust through fake CAPTCHA verification systems to trick victims into executing malicious commands. The attack […]
The post Threat Actors Using ClickFix Technique to Deliver EddieStealer Malware appeared first on Cyber Security News.