Aggregator
Experts Detect Multi-Layer Redirect Tactic Used to Steal Microsoft 365 Login Credentials
8 months 4 weeks ago
Cybersecurity researchers have disclosed details of a new phishing campaign that conceals malicious payloads by abusing link wrapping services from Proofpoint and Intermedia to bypass defenses.
"Link wrapping is designed by vendors like Proofpoint to protect users by routing all clicked URLs through a scanning service, allowing them to block known malicious destinations at the moment of click,"
The Hacker News
火山引擎作为「AI 原生」基础设施,变得更强了
8 months 4 weeks ago
火山引擎的 AI 基础设施,正在以月为单位快速进化。
17.98 万的乐道 L90,有多少蔚来的诚意,就有多少李斌的「求生欲」
8 months 4 weeks ago
毕其功于一役,乐道 L90 是李斌的「终极一战」。
Android Malware Targets Banking Users Through Discord Channels
8 months 4 weeks ago
The DoubleTrouble Android banking Trojan has evolved, using Discord for delivery and introducing several new features
CVE-2025-50460 | ms-swift up to 3.6.3 PyYAML deserialization
8 months 4 weeks ago
A vulnerability classified as critical has been found in ms-swift up to 3.6.3. Affected is an unknown function of the component PyYAML Handler. The manipulation leads to deserialization.
This vulnerability is traded as CVE-2025-50460. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CISA unveils free Thorium malware analysis platform
8 months 4 weeks ago
The goal of Thorium is to enable cyber defenders to bring automation to their existing analysis through simple tool integration and event-driven triggers, CISA said, adding that it is built to support cybersecurity teams across mission functions.
CVE-2025-5947 | Service Finder Bookings Plugin up to 6.0 on WordPress User Switch Cookie service_finder_switch_back improper authentication
8 months 4 weeks ago
A vulnerability was found in Service Finder Bookings Plugin up to 6.0 on WordPress. It has been rated as critical. This issue affects the function service_finder_switch_back of the component User Switch Cookie Handler. The manipulation leads to improper authentication.
The identification of this vulnerability is CVE-2025-5947. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-5954 | Service Finder SMS System Plugin up to 2.0.0 on WordPress aonesms_fn_savedata_after_signup privileges management
8 months 4 weeks ago
A vulnerability was found in Service Finder SMS System Plugin up to 2.0.0 on WordPress. It has been declared as critical. This vulnerability affects the function aonesms_fn_savedata_after_signup. The manipulation leads to improper privilege management.
This vulnerability was named CVE-2025-5954. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-34328 | Sielox AnyWare 2.1.2 redirect
8 months 4 weeks ago
A vulnerability was found in Sielox AnyWare 2.1.2. It has been classified as problematic. This affects an unknown part. The manipulation leads to open redirect.
This vulnerability is uniquely identified as CVE-2024-34328. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-51569 | LB-LINK BL-CPE300M 01.01.02P42U14_06 Web Interface goform_get_cmd_process cmd cross site scripting
8 months 4 weeks ago
A vulnerability was found in LB-LINK BL-CPE300M 01.01.02P42U14_06 and classified as problematic. Affected by this issue is some unknown functionality of the file /goform/goform_get_cmd_process of the component Web Interface. The manipulation of the argument cmd leads to cross site scripting.
This vulnerability is handled as CVE-2025-51569. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-29557 | ExaGrid EX10 up to 7.0.1.P08 MailConfiguration API Endpoint access control
8 months 4 weeks ago
A vulnerability has been found in ExaGrid EX10 up to 7.0.1.P08 and classified as critical. Affected by this vulnerability is an unknown functionality of the component MailConfiguration API Endpoint. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2025-29557. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2014-125125 | A10 AX Loadbalancer up to 2.6.1-GR1-P5/2.7.0 /xml/downloads filename path traversal (EDB-31261)
8 months 4 weeks ago
A vulnerability, which was classified as critical, was found in A10 AX Loadbalancer up to 2.6.1-GR1-P5/2.7.0. Affected is an unknown function of the file /xml/downloads. The manipulation of the argument filename leads to path traversal.
This vulnerability is traded as CVE-2014-125125. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2013-10042 | freeFTPd up to 1.0.10 PASS Command stack-based overflow (EDB-27747)
8 months 4 weeks ago
A vulnerability, which was classified as critical, has been found in freeFTPd up to 1.0.10. This issue affects some unknown processing of the component PASS Command Handler. The manipulation leads to stack-based buffer overflow.
The identification of this vulnerability is CVE-2013-10042. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2013-10039 | GestioIP IPAM up to up to 3.0 ip_checkhost.cgi ip os command injection
8 months 4 weeks ago
A vulnerability classified as critical was found in GestioIP IPAM up to up to 3.0. This vulnerability affects unknown code of the file ip_checkhost.cgi. The manipulation of the argument ip leads to os command injection.
This vulnerability was named CVE-2013-10039. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2013-10036 | Beetel Teletech Connection Manager PCW_BTLINDV1.0.0B04 NetConfig.ini Username stack-based overflow (EUVD-2013-7259 / EDB-28969)
8 months 4 weeks ago
A vulnerability classified as critical has been found in Beetel Teletech Connection Manager PCW_BTLINDV1.0.0B04. This affects an unknown part of the file NetConfig.ini. The manipulation of the argument Username leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2013-10036. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-50849 | CS Cart up to 4.18.3 company_id resource injection
8 months 4 weeks ago
A vulnerability was found in CS Cart up to 4.18.3. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument company_id leads to improper control of resource identifiers.
This vulnerability is handled as CVE-2025-50849. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2013-10034 | Kaseya KServer prior 6.3.0.2 uploadImage.asp filename unrestricted upload (EUVD-2013-7256 / EDB-29675)
8 months 4 weeks ago
A vulnerability was found in Kaseya KServer. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file uploadImage.asp. The manipulation of the argument filename leads to unrestricted upload.
This vulnerability is known as CVE-2013-10034. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-52203 | DevaslanPHP project-management 1.2.4 Ticket Name cross site scripting
8 months 4 weeks ago
A vulnerability was found in DevaslanPHP project-management 1.2.4. It has been classified as problematic. Affected is an unknown function. The manipulation of the argument Ticket Name leads to cross site scripting.
This vulnerability is traded as CVE-2025-52203. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2013-10040 | ClipBucket up to 2.6 ofc_upload_image.php unrestricted upload (EUVD-2013-7258)
8 months 4 weeks ago
A vulnerability was found in ClipBucket up to 2.6 and classified as critical. This issue affects some unknown processing of the file /admin_area/charts/ofc-library/ofc_upload_image.php. The manipulation leads to unrestricted upload.
The identification of this vulnerability is CVE-2013-10040. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com