Aggregator
EU law to protect journalists from spyware takes effect
10 months 1 week ago
Critics from press freedom groups say member states have not taken steps to give the law any teeth.
CVE-2025-54090 | Apache HTTP Server 2.4.64 RewriteCond incorrect check of function return value (EUVD-2025-22448 / Nessus ID 242629)
10 months 1 week ago
A vulnerability classified as problematic has been found in Apache HTTP Server 2.4.64. This affects an unknown part of the component RewriteCond Handler. The manipulation leads to incorrect check of function return value.
This vulnerability is uniquely identified as CVE-2025-54090. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-8579 | Google Chrome up to 138.0.7204.183 Picture in Picture ui layer (ID 407791 / Nessus ID 245584)
10 months 1 week ago
A vulnerability, which was classified as problematic, was found in Google Chrome. This affects an unknown part of the component Picture in Picture. The manipulation leads to improper restriction of rendered ui layers.
This vulnerability is uniquely identified as CVE-2025-8579. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-8580 | Google Chrome up to 138.0.7204.183 Filesystems ui layer (ID 411544 / Nessus ID 245584)
10 months 1 week ago
A vulnerability has been found in Google Chrome and classified as problematic. This vulnerability affects unknown code of the component Filesystems. The manipulation leads to improper restriction of rendered ui layers.
This vulnerability was named CVE-2025-8580. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-8578 | Google Chrome up to 138.0.7204.183 Cast use after free (ID 423387 / Nessus ID 245584)
10 months 1 week ago
A vulnerability, which was classified as critical, has been found in Google Chrome. Affected by this issue is some unknown functionality of the component Cast. The manipulation leads to use after free.
This vulnerability is handled as CVE-2025-8578. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-9322 | Statamic Core up to 2.11.7 /users cross site scripting (EUVD-2020-30143)
10 months 1 week ago
A vulnerability has been found in Statamic Core up to 2.11.7 and classified as problematic. This vulnerability affects unknown code of the file /users. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2020-9322. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-8730 | Belkin F9K1009/F9K1010 2.00.04/2.00.09 Web Interface hard-coded credentials (EUVD-2025-23988)
10 months 1 week ago
A vulnerability was found in Belkin F9K1009 and F9K1010 2.00.04/2.00.09 and classified as critical. Affected by this issue is some unknown functionality of the component Web Interface. The manipulation leads to hard-coded credentials.
This vulnerability is handled as CVE-2025-8730. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
Survey Sees Drop in Cybersecurity Spending Growth Rates
10 months 1 week ago
A survey of 587 CISOs published this week finds security budget growth dropped to 4%, down from 8% in 2024, with more than half reporting flat or shrinking budgets. Conducted by IANS Research and Artico Search, an executive search firm, the survey also finds security budgets as a percentage of IT spending declined from 11.9%..
The post Survey Sees Drop in Cybersecurity Spending Growth Rates appeared first on Security Boulevard.
Michael Vizard
CVE-2025-54787 | SuiteCRM up to 7.14.6 improper authorization (GHSA-8r72-224q-g9fv / EUVD-2025-23952)
10 months 1 week ago
A vulnerability was found in SuiteCRM up to 7.14.6. It has been classified as critical. This affects an unknown part. The manipulation leads to improper authorization.
This vulnerability is uniquely identified as CVE-2025-54787. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
AI Tools Fuel Brazilian Phishing Scam While Efimer Trojan Steals Crypto from 5,000 Victims
10 months 1 week ago
Cybersecurity researchers are drawing attention to a new campaign that's using legitimate generative artificial intelligence (AI)-powered website building tools like DeepSite AI and BlackBox AI to create replica phishing pages mimicking Brazilian government agencies as part of a financially motivated campaign.
The activity involves the creation of lookalike sites imitating Brazil's State
The Hacker News
CVE-2019-9790 | Mozilla Firefox/Firefox ESR/Thunderbird DOM use after free (RHSA-2019:0966 / Nessus ID 245548)
10 months 1 week ago
A vulnerability classified as critical was found in Mozilla Firefox, Firefox ESR and Thunderbird. Affected by this vulnerability is an unknown functionality of the component DOM Handler. The manipulation leads to use after free.
This vulnerability is known as CVE-2019-9790. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-47440 | Linux Kernel up to 5.14.13 encx24j600 devm_regmap_init_encx24j600 null pointer dereference (Nessus ID 245546)
10 months 1 week ago
A vulnerability has been found in Linux Kernel up to 5.14.13 and classified as critical. Affected by this vulnerability is the function devm_regmap_init_encx24j600 of the component encx24j600. The manipulation leads to null pointer dereference.
This vulnerability is known as CVE-2021-47440. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-2440 | Oracle MySQL Server up to 8.0.25 DML denial of service (Nessus ID 245553)
10 months 1 week ago
A vulnerability classified as critical was found in Oracle MySQL Server up to 8.0.25. Affected by this vulnerability is an unknown functionality of the component DML. The manipulation leads to denial of service.
This vulnerability is known as CVE-2021-2440. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Microsoft: An organization without a response plan will be hit harder by a security incident
10 months 1 week ago
Security leaders shared advice gleaned from customer engagements, and reinforced the importance of planning and following fundamentals for defense.
The post Microsoft: An organization without a response plan will be hit harder by a security incident appeared first on CyberScoop.
Matt Kapko
JavaSecLab 综合Java漏洞平台搭建
10 months 1 week ago
一、介绍 JavaSecLab是一款综合型Java漏洞平台,提供相关漏洞缺陷代码、修复代码、漏洞场景、审计S
860K Compromised in Columbia University Data Breach
10 months 1 week ago
While no data has yet to be misused, the university doesn't rule out the possibility of that occurring in the future, prompting it to warn affected individuals to remain vigilant in the wake of the breach.
Kristina Beek
CVE-2024-49138 | Microsoft Windows up to Server 2025 Common Log File System Driver heap-based overflow (EDB-52270 / Nessus ID 212240)
10 months 1 week ago
A vulnerability was found in Microsoft Windows and classified as critical. Affected by this issue is some unknown functionality of the component Common Log File System Driver. The manipulation leads to heap-based buffer overflow.
This vulnerability is handled as CVE-2024-49138. An attack has to be approached locally. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-38193 | Microsoft Windows up to Server 2022 23H2 Ancillary Function Driver for WinSock use after free (EDB-52284)
10 months 1 week ago
A vulnerability was found in Microsoft Windows. It has been rated as critical. Affected by this issue is some unknown functionality of the component Ancillary Function Driver for WinSock. The manipulation leads to use after free.
This vulnerability is handled as CVE-2024-38193. The attack needs to be approached locally. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-23346 | materialsproject pymatgen prior 2024.2.20 from_transformation_str command injection (EDB-52205)
10 months 1 week ago
A vulnerability was found in materialsproject pymatgen. It has been rated as critical. Affected by this issue is the function from_transformation_str. The manipulation leads to command injection.
This vulnerability is handled as CVE-2024-23346. The attack needs to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com