New Android RAT Dubbed “AndroRAT” Attacking to Steal Pattern, PIN & Passcodes
New Android RAT Dubbed “AndroRAT” Attacking to Steal Pattern, PIN & Passcodes A newly identified variant of the Android Remote Access Tool (RAT), AndroRAT, has emerged as a critical cybersecurity threat, leveraging sophisticated techniques to steal device unlock patterns, PINs, … Read more Published Date: Mar 04, 2025 (3 hours, 9 minutes ago) Vulnerabilities has been mentioned […]
CVE-2025-22226 – VMware HGFS Out-of-Bounds Read Information Disclosure
The following table lists the changes that have been made to the CVE-2025-22226 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 04, 2025 Action […]
CVE-2025-22225 – VMware ESXi Kernel Privilege Escalation Vulnerability
The following table lists the changes that have been made to the CVE-2025-22225 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 04, 2025 Action […]
CVE-2025-22224 – VMware ESXi/Workstation TOCTOU Out-of-Bounds Write RCE
The following table lists the changes that have been made to the CVE-2025-22224 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 04, 2025 Action […]
VMware ESXi Vulnerabilities Exploited in Wild to Execute Malicious Code
VMware ESXi Vulnerabilities Exploited in Wild to Execute Malicious Code VMware has issued a critical security advisory (VMSA-2025-0004) warning of active exploitation of three vulnerabilities in its ESXi, Workstation, and Fusion products. These flaws, CVE-2025-22224, CVE- … Read more Published Date: Mar 04, 2025 (3 hours, 30 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-22226 […]
Google fixes Android zero-day exploited by Serbian authorities
Google fixes Android zero-day exploited by Serbian authorities Google has released patches for 43 vulnerabilities in Android’s March 2025 security update, including two zero-days exploited in targeted attacks. Serbian authorities have used one of the zero-days, a … Read more Published Date: Mar 04, 2025 (3 hours, 51 minutes ago) Vulnerabilities has been mentioned in this article. […]
CVE-2025-22224, CVE-2025-22225, CVE-2025-22226: Critical VMware Vulnerabilities Exploited
CVE-2025-22224, CVE-2025-22225, CVE-2025-22226: Critical VMware Vulnerabilities Exploited Broadcom, the parent company of VMware, has released a critical security advisory (VMSA-2025-0004) detailing multiple vulnerabilities affecting VMware ESXi, Workstation, and Fusion. The advisory warns … Read more Published Date: Mar 04, 2025 (4 hours, 8 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-22226 CVE-2025-22225 CVE-2025-22224 CVE-2024-38814
CVE-2025-0958 – WordPress Auction Plugin Unauthorized Functionality Access
CVE ID : CVE-2025-0958 Published : March 4, 2025, 10:15 a.m. | 1 hour, 9 minutes ago Description : The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized access to functionality in all versions up to, and including, 4.2.9. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary […]
CVE-2025-0370 – “WordPress Shortcodes Ultimate Stored Cross-Site Scripting”
CVE ID : CVE-2025-0370 Published : March 4, 2025, 10:15 a.m. | 1 hour, 9 minutes ago Description : The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘src’ parameter in all versions up to, and including, 7.3.3 due to insufficient input sanitization and output escaping. This makes […]
CISA Warns of Windows Win32k Vulnerability Exploited to Run Arbitrary code
CISA Warns of Windows Win32k Vulnerability Exploited to Run Arbitrary code The Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory regarding CVE-2018-8639, a privilege escalation vulnerability in the Microsoft Windows Win32k component, which threat … Read more Published Date: Mar 04, 2025 (3 hours, 14 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2024-50302 […]