Aggregator
CVE-2025-53631 | DogukanUrker flaskBlog up to 2.8.1 POST Request /createpost cross site scripting
CVE-2025-9052 | projectworlds Travel Management System 1.0 /updatepackage.php s1 sql injection
CVE-2025-9053 | projectworlds Travel Management System 1.0 /updatesubcategory.php t1/s1 sql injection
CVE-2025-36120 | IBM Storage Virtualize 8.4/8.5/8.6/8.7 SSH Session authorization (EUVD-2025-25123)
CVE-2024-49827 | IBM Concert Software up to 1.1.0 exposure of sensitive information due to incompatible policies
CVE-2025-27909 | IBM Concert Software up to 1.1.0 Trusted Domain cross-domain policy
CVE-2025-33090 | IBM Concert Software up to 1.1.0 redos
CVE-2025-33100 | IBM Concert Software up to 1.1.0 hard-coded credentials
CVE-2025-1759 | IBM Concert Software up to 1.1.0 heap inspection
CVE-2025-8362 | GoogleTag Manager up to 1.9.x on Drupal cross site scripting (trib-2025-094)
CVE-2025-8675 | AI SEO Link Advisor up to 1.0.5 on Drupal server-side request forgery (sa-contrib-2025-095)
CVE-2025-54989 | FirebirdSQL Firebird up to 3.0.12/4.0.5/5.0.2 XDR Message null pointer dereference (ID 8554 / WID-SEC-2025-1857)
CVE-2025-9017 | PHPGurukul Zoo Management System 2.1 add-foreigner-ticket.php visitorname cross site scripting (EUVD-2025-24990)
Qilin
You must login to view this content
AI gives ransomware gangs a deadly upgrade
Ransomware continues to be the major threat to large and medium-sized businesses, with numerous ransomware gangs abusing AI for automation, according to Acronis. Ransomware gangs maintain pressure on victims From January to June 2025, the number of publicly reported ransomware victims jumped 70% compared to the same period in both 2023 and 2024. February stood out as the worst month, with 955 reported cases. Cl0p alone was responsible for 335 of those cases, a 300% … More →
The post AI gives ransomware gangs a deadly upgrade appeared first on Help Net Security.
ApacheTomcat存在远程代码执行漏洞(CVE-2024-56337)
CSOP 2025 | 走进北京大学,聚焦高校网络安全新实战
Windows Docker Desktop Vulnerability Allows Full Host Compromise
A critical vulnerability in Docker Desktop for Windows has been discovered that allows any container to achieve full host system compromise through a simple Server-Side Request Forgery (SSRF) attack. The flaw, designated CVE-2025-9074, was patched in Docker Desktop version 4.44.3 released in August 2025. CVE Details CVE ID CVE-2025-9074 CVSS Score Critical (Estimated 9.0+) Affected […]
The post Windows Docker Desktop Vulnerability Allows Full Host Compromise appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.