Aggregator
CVE-2025-20029
CVE-2024-58043 | Huawei HarmonyOS/EMUI Window Module logic error
CVE-2024-58050 | Huawei HarmonyOS 5.0.0 HDC Module information disclosure
CVE-2024-58049 | Huawei HarmonyOS 5.0.0 Media Library Module information disclosure
CVE-2024-58048 | Huawei HarmonyOS 5.0.0 Multi-Thread race condition
CVE-2024-58047 | Huawei HarmonyOS 5.0.0 information disclosure
CVE-2024-48248 | NAKIVO Backup & Replication Director prior 11.0.0.88174 /c/router absolute path traversal
最新黑产技术曝光,只需19分钟即可劫持AI大模型
BigAnt Server 0-day Vulnerability Let Attackers Execute Malicious Code Via File Uploads
A critical zero-day vulnerability in BigAntSoft’s BigAnt Server (CVE-2025-0364) allows unauthenticated attackers to execute arbitrary code on affected systems through a chain of SaaS registration abuses and PHP file uploads. The flaw, discovered by VulnCheck researchers during an analysis of a misrated CVSS score for CVE-2024-54761, impacts all versions ≤5.6.06 of the Windows-based enterprise chat […]
The post BigAnt Server 0-day Vulnerability Let Attackers Execute Malicious Code Via File Uploads appeared first on Cyber Security News.
信息安全漏洞月报(2025年2月)
信息安全漏洞月报(2025年2月)
BigAnt Server 0-Day Vulnerability Lets Attackers Run Malicious Code Remotely
A critical vulnerability in BigAntSoft’s enterprise chat server software has exposed ~50 internet-facing systems to unauthenticated remote code execution attacks. Designated CVE-2025-0364, this exploit chain enables attackers to bypass authentication protocols, create administrative accounts, and execute malicious PHP code on vulnerable servers running BigAnt Server v5.6.06 and earlier. CVE-2025-0364: Authentication Bypass to PHP Code Execution The […]
The post BigAnt Server 0-Day Vulnerability Lets Attackers Run Malicious Code Remotely appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.