Carol Steele, the county’s administrator, said they hired cybersecurity experts to help with the recovery and notified the FBI’s Cyber Crimes Division as well as the Cyber Fusion Center of the Virginia State Police.
China-linked group Houken hit French govt, telecom, media, finance and transport sectors using Ivanti CSA zero-days, says France’s ANSSI. France’s cyber agency ANSSI revealed that a Chinese hacking group used Ivanti CSA zero-days to target government, telecom, media, finance, and transport sectors. The campaign, active since September 2024, is linked to the Houken intrusion set, […]
A vulnerability has been found in minidlna and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2013-2739. The attack can be launched remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as critical, was found in ai-inference-server. Affected is an unknown function of the file /invocations of the component API Inference Endpoint. The manipulation leads to improper authentication.
This vulnerability is traded as CVE-2025-6920. The attack needs to be done within the local network. There is no exploit available.
A vulnerability classified as critical has been found in AVTECH IP Camera, DVR and NVR. This affects an unknown part of the file PwdGrp.cgi of the component System Command Handler. The manipulation of the argument pwd/grp leads to os command injection.
This vulnerability is uniquely identified as CVE-2025-34056. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as problematic, was found in AVTECH IP Camera, DVR and NVR. This affects an unknown part of the component Web Interface. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2025-34050. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability was found in AVTECH IP Camera, DVR and NVR. It has been rated as critical. Affected by this issue is some unknown functionality of the file adcommand.cgi. The manipulation of the argument strCmd leads to os command injection.
This vulnerability is handled as CVE-2025-34055. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability was found in Campcodes Employee Management System 1.0. It has been classified as critical. This affects an unknown part of the file /changepassemp.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-6956. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as critical, was found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affected is an unknown function of the file /boafrm/formParentControl of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow.
This vulnerability is traded as CVE-2025-6953. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
A vulnerability has been found in Campcodes Employee Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /applyleave.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is known as CVE-2025-6954. The attack can be launched remotely. Furthermore, there is an exploit available.
A vulnerability was found in Hikvision Streaming Media Management Server 2.3.5. It has been classified as critical. Affected is an unknown function of the file /systemLog/downFile.php. The manipulation of the argument fileName leads to weak password requirements.
This vulnerability is traded as CVE-2025-34058. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability classified as critical has been found in AVTECH DVR. Affected is an unknown function of the file /cgi-bin/nobody/Search.cgi?action=cgi_query. The manipulation of the argument queryb64str leads to server-side request forgery.
This vulnerability is traded as CVE-2025-34051. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Campcodes Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /process/aprocess.php. The manipulation of the argument mailuid leads to sql injection.
This vulnerability is handled as CVE-2025-6955. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability classified as critical was found in AVTECH IP Camera, DVR and NVR. Affected by this vulnerability is the function strstr. The manipulation leads to authentication bypass by spoofing.
This vulnerability is known as CVE-2025-34053. The attack can be launched remotely. Furthermore, there is an exploit available.
A vulnerability has been found in AVTECH DVR and classified as critical. Affected by this vulnerability is an unknown functionality of the file Search.cgi?action=cgi_query. The manipulation of the argument queryb64str leads to os command injection.
This vulnerability is known as CVE-2025-34054. The attack can be launched remotely. Furthermore, there is an exploit available.