Rsync Vulnerabilities Let Hackers Gain Full Control of Servers – PoC Released
Rsync Vulnerabilities Let Hackers Gain Full Control of Servers – PoC Released Critical vulnerabilities in the Rsync file synchronization tool enable attackers to execute arbitrary code on vulnerable servers, exfiltrate sensitive data, and bypass critical security controls. The … Read more Published Date: Feb 26, 2025 (1 hour, 46 minutes ago) Vulnerabilities has been mentioned in this […]
Exploits and vulnerabilities in Q4 2024
Exploits and vulnerabilities in Q4 2024 Q4 2024 saw fewer published exploits for Windows and Linux compared to the first three quarters. Although the number of registered vulnerabilities continued to rise, the total number of Proof of Conce … Read more Published Date: Feb 26, 2025 (1 hour, 54 minutes ago) Vulnerabilities has been mentioned in this […]
WordPress Plugin Vulnerability Exposes Millions of Websites to Script Injection Attacks
WordPress Plugin Vulnerability Exposes Millions of Websites to Script Injection Attacks A critical security vulnerability in the Essential Addons for Elementor plugin (CVE-2025-24752) has put over two million WordPress websites at risk of cross-site scripting (XSS) attacks. The vulnerabi … Read more Published Date: Feb 26, 2025 (2 hours, 51 minutes ago) Vulnerabilities has been mentioned in […]
2850+ Ivanti Connect Secure Devices Vulnerable to Remote Code Execution Attacks
2850+ Ivanti Connect Secure Devices Vulnerable to Remote Code Execution Attacks A critical vulnerability, CVE-2025-22467, in Ivanti Connect Secure (ICS) devices has left approximately 2,850 instances worldwide unpatched and vulnerable to remote code execution (RCE) attacks. This … Read more Published Date: Feb 26, 2025 (1 hour, 54 minutes ago) Vulnerabilities has been mentioned in this article.
CISA Warns of Microsoft Partner Center Access Control Vulnerability Exploited in Wild
CISA Warns of Microsoft Partner Center Access Control Vulnerability Exploited in Wild The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent advisory on February 25, 2025, confirming that threat actors are actively exploiting a critical privilege escalation v … Read more Published Date: Feb 26, 2025 (48 minutes ago) Vulnerabilities has been mentioned in […]
CISA Adds Microsoft and Zimbra Flaws to KEV Catalog Amid Active Exploitation
CISA Adds Microsoft and Zimbra Flaws to KEV Catalog Amid Active Exploitation Enterprise Security / Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday placed two security flaws impacting Microsoft Partner Center and Synacor Zimbra Collabor … Read more Published Date: Feb 26, 2025 (3 hours, 20 minutes ago) Vulnerabilities has been mentioned in this […]
CVE-2024-12084 & CVE-2024-12085: Rsync Flaws Allow Hackers to Take Over Servers, PoC Published
CVE-2024-12084 & CVE-2024-12085: Rsync Flaws Allow Hackers to Take Over Servers, PoC Published A set of high-risk vulnerabilities has been disclosed in Rsync, the widely used file synchronization and data transfer tool. Security researchers Simon Scannell, Pedro Gallegos, and Jasiel Spelman fro … Read more Published Date: Feb 26, 2025 (3 hours, 20 minutes ago) Vulnerabilities has […]
SoaPy: A New Tool for Stealthy Active Directory Enumeration via ADWS
SoaPy: A New Tool for Stealthy Active Directory Enumeration via ADWS Enumeration of service accounts using SoaPy | Image: IBMIBM X-Force Research has introduced SoaPy, a new Python-based tool designed for stealthy Active Directory (AD) enumeration using Active Director … Read more Published Date: Feb 26, 2025 (3 hours, 26 minutes ago) Vulnerabilities has been mentioned in […]
CISA Flags Actively Exploited Zimbra (CVE-2023-34192) and Microsoft (CVE-2024-49035) Vulnerabilities
CISA Flags Actively Exploited Zimbra (CVE-2023-34192) and Microsoft (CVE-2024-49035) Vulnerabilities The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning, adding two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. This move underscores the ur … Read more Published Date: Feb 26, 2025 (3 hours, 29 minutes ago) Vulnerabilities has been mentioned in this article. […]
CVE-2025-24752: Massive WordPress Plugin Vulnerability Exposes Millions to XSS Attacks
CVE-2025-24752: Massive WordPress Plugin Vulnerability Exposes Millions to XSS Attacks A high-severity security flaw has been discovered in the widely used WordPress plugin, Essential Addons for Elementor, putting over two million websites at risk. The vulnerability, tracked as CVE-2025 … Read more Published Date: Feb 26, 2025 (3 hours, 47 minutes ago) Vulnerabilities has been mentioned in this […]