Cybersecurity News
Aggregated daily from 10 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
WordPress OrderConvo 14 - Path Traversal
Drupal Core 10.5.5 - Error-Based SQL Injection
YAMCS yamcs-core 5.12.7 - LDAP Injection
YAMCS yamcs-core 5.12.7 - User Enumeration
YAMCS yamcs-core 5.12.7 - No Rate Limiting
Notepad++ 8.9.6 - Arbitrary Code Execution
strongSwan 5.9.13 - DoS
strongSwan 5.9.13 - libsimaka EAP-SIM/AKA heap buffer overflow
CubeCart < 6.7.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)
Wing FTP Server 8.1.3 - Authenticated Remote Code Execution
MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution
Linux Kernel - Local Privilege Escalation
ZTE H298A / H108N - Unauthenticated Credential Exposure
ZTE ZXHN H188A V6 - Authentication Bypass
ZTE Routers - Unauthenticated Denial of Service
ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion
Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution
Langflow 1.3.0 - Remote Code Execution
Prodigy Commerce 3.3.0 - Local File Inclusion
MikroORM 7.0.13 - SQL Injection
Microsoft - NTLMv2 Hash Capture
New guidance explains how to design Zero Trust Network Access architectures aligned with zero trust principles and not built on old trust assumptions.
OpenCATS 0.9.7.4 - SQL Injection
Realtek rtl819x - Local Privilege
MeiG Smart FORGE_SLT711 - OS Command Injection
scramble - Remote Code Execution
EspoCRM 9.3.3 - SSRF
Casdoor 3.54.1 - Arbitrary File Write via Path Traversal
Linux Kernel - Local Privilege Escalation
Grav CMS 2.0.0-beta.2 - Remote Code Execution