Aggregator
唯一安全厂商!360安全智能体获权威机构推荐稳居行业第一选择
1 hour 44 minutes hence
安全客
Microsoft 警告:Node.js 恶意广告肆虐,加密交易用户信息安全告急
1 hour 38 minutes hence
安全客
黑客利用 MMC 脚本发动攻击,部署 MysterySnail RAT 威胁系统安全
1 hour 24 minutes hence
安全客
CVE-2025-32422
1 hour 32 minutes ago
Currently trending CVE - Hype Score: 22
CVE-2025-31200
1 hour 32 minutes ago
Currently trending CVE - Hype Score: 25 - A memory corruption issue was addressed with improved bounds checking. This issue is fixed in tvOS 18.4.1, visionOS 2.4.1, iOS iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1. Processing an audio stream in a maliciously crafted media file may result in code execution. Apple ...
CVE-2025-31201
1 hour 32 minutes ago
Currently trending CVE - Hype Score: 24 - This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 18.4.1, visionOS 2.4.1, iOS iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware ...
CVE-2025-32433
1 hour 32 minutes ago
Currently trending CVE - Hype Score: 65 - Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, ...
CVE-2025-24054
1 hour 32 minutes ago
Currently trending CVE - Hype Score: 49 - External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-29471
1 hour 32 minutes ago
Currently trending CVE - Hype Score: 1 - Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code via a payload into the Email field.
CVE-2025-29809
1 hour 32 minutes ago
Currently trending CVE - Hype Score: 27 - Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature locally.
CVE-2025-21299
1 hour 32 minutes ago
Currently trending CVE - Hype Score: 27 - Windows Kerberos Security Feature Bypass Vulnerability
CVE-2025-24859
1 hour 32 minutes ago
Currently trending CVE - Hype Score: 1 - A session management vulnerability exists in Apache Roller before version 6.1.5 where active user sessions are not properly invalidated after password changes. When a user's password is changed, either by the user themselves or by an administrator, existing sessions remain ...
CVE-2025-27840
1 hour 32 minutes ago
Currently trending CVE - Hype Score: 43 - Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory).
Palo Alto Networks 披露复杂网络钓鱼攻击链 Cascading Shadows,企业数据安全岌岌可危
1 hour 32 minutes ago
安全客
CVE-2025-20236:Cisco Webex 应用程序会议链接漏洞可致远程代码执行
2 hours 3 minutes ago
安全客
Erlang/OTP SSH 高危漏洞 CVE-2025-32433:无需认证即可远程执行代码
2 hours 30 minutes ago
安全客
CVE-2024-0614 | Events Manager Plugin up to 6.4.6.4 on WordPress Setting cross site scripting (ID 3042128)
2 hours 33 minutes ago
A vulnerability was found in Events Manager Plugin up to 6.4.6.4 on WordPress and classified as problematic. This issue affects some unknown processing of the component Setting Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-0614. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-1977 | Restaurant Solutions Plugin 1.0.0 on WordPress cross site scripting
2 hours 33 minutes ago
A vulnerability was found in Restaurant Solutions Plugin 1.0.0 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-1977. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-1976 | Marketing Optimizer Plugin up to 20200925 on WordPress cross-site request forgery
2 hours 33 minutes ago
A vulnerability was found in Marketing Optimizer Plugin up to 20200925 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2024-1976. The attack can be launched remotely. There is no exploit available.
vuldb.com