A vulnerability has been found in linjiashop up to 0.9 and classified as critical. This vulnerability affects unknown code. The manipulation leads to improper access controls.
This vulnerability was named CVE-2025-52101. The attack needs to be done within the local network. There is no exploit available.
A vulnerability was found in Xinference up to 1.3.x. It has been rated as critical. Affected by this issue is some unknown functionality of the component Web GUI. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2025-45424. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Lucee 5.x/6.x. It has been classified as critical. This affects an unknown part of the file /lucee/admin/web.cfm. The manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2025-34074. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability classified as problematic has been found in Delinea Secret Server up to 11.7.48. Affected is an unknown function of the component Distributed Engine. The manipulation leads to authorization bypass.
This vulnerability is traded as CVE-2025-6942. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Google Chrome 127.x/128.x and classified as problematic. Affected by this vulnerability is an unknown functionality of the component AppBound Cookie Encryption. The manipulation leads to information exposure through discrepancy.
This vulnerability is known as CVE-2025-34091. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Google Chrome 127.x/128.x. It has been declared as problematic. This vulnerability affects unknown code of the component Inter-Process Communication. The manipulation leads to untrusted search path.
This vulnerability was named CVE-2025-34090. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
Cybersecurity Awareness Programs Need Focus on Human Risk and Changing Behaviors Thanks to Cybersecurity Awareness Month, everyone knows security is a priority, but what are we doing differently to change the culture? If our goal is to reduce risk - and not just to meet regulatory expectations - then we need to focus on behavior, not just boxes on a checklist.
23andMe's Ex-CEO Anne Wojcicki Made Privacy Pledge With Successful Bid of $305M A bankruptcy court gave the green light for TTAM Research Institute - a firm launched by 23andMe's co-founder and former CEO Anne Wojcicki - to buy 23andMe for $305 million. TTAM has promised to uphold the consumer genetics testing firm's current privacy policies and implement more data safeguards.
Google’s Mandiant Warns About Remote Attacks Disrupting Grid Stability Vulnerabilities in networked devices programmed to instantaneously trip power grid substation circuit breakers could be the means hackers use to cause the next blackout, warn researchers. There are "systemic patterns across substations, utilities and industrial sites worldwide," Mandiant warned.