Russian Cybercrime Groups Exploiting 7-Zip Flaw to Bypass Windows MotW Protections
Russian Cybercrime Groups Exploiting 7-Zip Flaw to Bypass Windows MotW Protections Vulnerability / Cyber Espionage A recently patched security vulnerability in the 7-Zip archiver tool was exploited in the wild to deliver the SmokeLoader malware. The flaw, CVE-2025-0411 (CVSS score: … Read more Published Date: Feb 04, 2025 (3 hours, 54 minutes ago) Vulnerabilities has been mentioned […]
CVE-2025-24860 – Apache Cassandra Incorrect Authorization Vulnerability Allows Unauthorized Access
The following table lists the changes that have been made to the CVE-2025-24860 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 04, 2025 Action […]
CVE-2025-0890 – Zyxel Telnet Default Credentials Vulnerability
The following table lists the changes that have been made to the CVE-2025-0890 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 04, 2025 Action […]
CVE-2024-27137 – Apache Cassandra RMI Registry Man-in-the-Middle Authentication Bypass
The following table lists the changes that have been made to the CVE-2024-27137 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 04, 2025 Action […]
Vulnerability in authentik software
Vulnerability in authentik software CVE ID CVE-2024-11623 Publication date 04 February 2025 Vendor goauthentik Product authentik Vulnerable versions All before 2024.10.4 Vulnerability type (CWE) Improper Neutralization of Input During W … Read more Published Date: Feb 04, 2025 (5 hours, 22 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2024-11623
CVE-2025-23015 – Apache Cassandra Privilege Escalation Vulnerability
Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cassandra cluster via unsafe actions to a system resource. Operators granting data MODIFY permission on all keyspaces on affected versions should review data access rules for potential breaches. This issue […]
CVE-2024-13733 – SKT Blocks Vulnerable to Stored Cross-Site Scripting in WordPress Page Builder
CVE ID : CVE-2024-13733 Published : Feb. 4, 2025, 10:15 a.m. | 42 minutes ago Description : The SKT Blocks – Gutenberg based Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s skt-blocks/post-carousel block in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping on […]
CVE-2024-40890 – Zyxel VMG4325-B10A Command Injection Vulnerability
The following table lists the changes that have been made to the CVE-2024-40890 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 04, 2025 Action […]
CVE-2024-40891 – Zyxel Legacy DSL CPE Zyxel VMG4325-B10A Command Injection Vulnerability
The following table lists the changes that have been made to the CVE-2024-40891 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 04, 2025 Action […]
CVE-2024-13529 – SocialV BuddyPress Theme Unauthenticated File Download Vulnerability
CVE ID : CVE-2024-13529 Published : Feb. 4, 2025, 10:15 a.m. | 42 minutes ago Description : The SocialV – Social Network and Community BuddyPress Theme theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ‘socialv_send_download_file’ function in all versions up to, and including, 2.0.15. This makes […]