Aggregator
Как освоить программирование с нуля: от первого кода до первой зарплаты
11 months ago
Пошаговое руководство для тех, кто начинает без опыта.
微信3.9版本RCE漏洞,OneSEC紧急缓解、检测方法
11 months ago
支持检测和自动响应
Ваш компьютер тормозит? Проверьте, не майнит ли он крипту для хакеров
11 months ago
Когда вентиляторы работают на максимум, а задач нет — пора бить тревогу.
CVE-2025-7655 | Live Stream Badger Plugin up to 1.4.3 on WordPress Shortcode livestream cross site scripting (EUVD-2025-21946)
11 months ago
A vulnerability classified as problematic was found in Live Stream Badger Plugin up to 1.4.3 on WordPress. This vulnerability affects the function livestream of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-7655. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-7395 | wolfSSL up to 5.8.0 Server Certificate Domain certificate validation (EUVD-2025-21936)
11 months ago
A vulnerability, which was classified as critical, has been found in wolfSSL up to 5.8.0. Affected by this issue is some unknown functionality of the component Server Certificate Domain Handler. The manipulation leads to improper certificate validation.
This vulnerability is handled as CVE-2025-7395. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-7394 | wolfSSL up to 5.8.0 RAND_poll random values (EUVD-2025-21938)
11 months ago
A vulnerability, which was classified as problematic, was found in wolfSSL up to 5.8.0. This affects the function RAND_poll. The manipulation leads to insufficiently random values.
This vulnerability is uniquely identified as CVE-2025-7394. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-7396 | wolfSSL 5.8.0 Curve25519 information exposure (EUVD-2025-21941)
11 months ago
A vulnerability was found in wolfSSL 5.8.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Curve25519 Handler. The manipulation leads to information exposure through discrepancy.
This vulnerability is known as CVE-2025-7396. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-52924 | One Identity OneLogin 6.1.5 SQL Connection X-RequestId sql injection (EUVD-2025-21947)
11 months ago
A vulnerability was found in One Identity OneLogin 6.1.5. It has been rated as critical. Affected by this issue is some unknown functionality of the component SQL Connection Handler. The manipulation of the argument X-RequestId leads to sql injection.
This vulnerability is handled as CVE-2025-52924. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-7669 | Avishi WP PayPal Payment Button Plugin up to 2.0 on WordPress Setting index.php cross-site request forgery (EUVD-2025-21942)
11 months ago
A vulnerability was found in Avishi WP PayPal Payment Button Plugin up to 2.0 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality of the file avishi-wp-paypal-payment-button/index.php of the component Setting Handler. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2025-7669. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-7658 | Temporarily Hidden Content Plugin up to 1.0.6 on WordPress Shortcode temphc-start cross site scripting (EUVD-2025-21944)
11 months ago
A vulnerability classified as problematic has been found in Temporarily Hidden Content Plugin up to 1.0.6 on WordPress. This affects the function temphc-start of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-7658. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-7653 | EPay Payments Plugin up to 0.1 on WordPress Shortcode epay cross site scripting (EUVD-2025-21943)
11 months ago
A vulnerability, which was classified as problematic, was found in EPay Payments Plugin up to 0.1 on WordPress. Affected is the function epay of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-7653. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-7697 | Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin verify_field_val code injection (EUVD-2025-21948)
11 months ago
A vulnerability was found in Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin up to 1.1.1 on WordPress. It has been declared as critical. Affected by this vulnerability is the function verify_field_val. The manipulation leads to code injection.
This vulnerability is known as CVE-2025-7697. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-7696 | Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin verify_field_val code injection (EUVD-2025-21949)
11 months ago
A vulnerability was found in Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin up to 1.2.3 on WordPress. It has been rated as critical. Affected by this issue is the function verify_field_val. The manipulation leads to code injection.
This vulnerability is handled as CVE-2025-7696. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-50708 | Perplexity AI GPT-4 2.51.0 Shared Chat URL information disclosure (EUVD-2025-21932)
11 months ago
A vulnerability was found in Perplexity AI GPT-4 2.51.0. It has been classified as problematic. Affected is an unknown function of the component Shared Chat URL Handler. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2025-50708. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-7661 | Partnerský Systém Martinus Plugin up to 1.7.1 on WordPress Shortcode martinus cross site scripting (EUVD-2025-21945)
11 months ago
A vulnerability, which was classified as problematic, has been found in Partnerský Systém Martinus Plugin up to 1.7.1 on WordPress. This issue affects the function martinus of the component Shortcode Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-7661. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-32819 | SonicWall SMA100 SSLVPN file access (SNWLID-2025-0011 / EUVD-2025-13910)
11 months ago
A vulnerability was found in SonicWall SMA100 and classified as problematic. Affected by this issue is some unknown functionality of the component SSLVPN. The manipulation leads to files or directories accessible.
This vulnerability is handled as CVE-2025-32819. The attack may be launched remotely. There is no exploit available.
vuldb.com
New QR Code Attack Via PDFs Evades Detection Systems and Harvest Credentials
11 months ago
A sophisticated phishing campaign dubbed “Scanception” has emerged as a significant threat to enterprise security, leveraging QR codes embedded in PDF attachments to bypass traditional email security measures and harvest user credentials. The attack represents a concerning evolution in social engineering tactics, specifically targeting the growing reliance on mobile devices for quick access to digital […]
The post New QR Code Attack Via PDFs Evades Detection Systems and Harvest Credentials appeared first on Cyber Security News.
Tushar Subhra Dutta
【0719】重保演习每日情报汇总
11 months ago
一年一度的“大考”火热进行中,攻防演练期间本公众号会每日更新当天鲜活情报和热点漏洞,欢迎大家对我们进行收藏和关注!
【0719】重保演习每日情报汇总
11 months ago
当前环境异常,需完成验证后方可继续访问。