CrushFTP HTTPS Port Vulnerability Leads to Unauthorized Access
CrushFTP HTTPS Port Vulnerability Leads to Unauthorized Access Two critical vulnerabilities have been identified in widely used software: CrushFTP and Next.js. CrushFTP, a file transfer solution, contains a vulnerability allowing unauthorized access through stand … Read more Published Date: Mar 26, 2025 (2 hours, 25 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-29927
Operation ForumTroll – APT Hackers Exploit Google Chrome Zero-Day To Bypass Sandbox Protections
Operation ForumTroll – APT Hackers Exploit Google Chrome Zero-Day To Bypass Sandbox Protections In mid-March 2025, cybersecurity researchers uncovered “Operation ForumTroll,” targeting Russian media outlets and educational institutions. Victims are infected by clicking phishing links disguised a … Read more Published Date: Mar 26, 2025 (2 hours, 26 minutes ago) Vulnerabilities has been mentioned in this article.
CVE-2025-24808 – Discourse Race Condition in Group DM User Addition
The following table lists the changes that have been made to the CVE-2025-24808 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 26, 2025 Action […]
CVE-2025-23203 – Icinga Director Unauthenticated Information Disclosure and Configuration Manipulation Vulnerability
Icinga Director is an Icinga config deployment tool. A Security vulnerability has been found starting in version 1.0.0 and prior to 1.10.3 and 1.11.3 on several director endpoints of REST API. To reproduce this vulnerability an authenticated user with permission to access the Director is required (plus api access with regard to the api endpoints). […]
CVE-2024-45351 – Xiaomi Game Center Code Execution Vulnerability
The following table lists the changes that have been made to the CVE-2024-45351 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 26, 2025 Action […]
CVE-2022-39163 – IBM Cognos Controller Client-Side Desync Cross-Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2022-39163 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 26, 2025 Action […]
CVE-2025-21377 NTLM Flaw Detailed out
CVE-2025-21377 NTLM Flaw Detailed out CVE-2025-21377 is a security vulnerability in Microsoft Windows that stems from weaknesses in the implementation of the NTLM (NT LAN Manager) authentication protocol. This vulnerability exposes critic … Read more Published Date: Mar 26, 2025 (2 hours, 48 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-22230 CVE-2025-21377 CVE-2025-21298
GitLab Alert: Patch Now! XSS & Privilege Escalation Risks
GitLab Alert: Patch Now! XSS & Privilege Escalation Risks GitLab has issued a security advisory, urging all users of self-managed GitLab Community Edition (CE) and Enterprise Edition (EE) to immediately upgrade to the latest versions: 17.10.1, 17.9.3, or 17. … Read more Published Date: Mar 26, 2025 (2 hours, 49 minutes ago) Vulnerabilities has been mentioned in […]
EncryptHub Exploits Windows Zero-Day to Deploy Rhadamanthys and StealC Malware
EncryptHub Exploits Windows Zero-Day to Deploy Rhadamanthys and StealC Malware Windows Security / Vulnerability The threat actor known as EncryptHub exploited a recently-patched security vulnerability in Microsoft Windows as a zero-day to deliver a wide range of malware families … Read more Published Date: Mar 26, 2025 (2 hours, 58 minutes ago) Vulnerabilities has been mentioned in […]
Critical NetApp SnapCenter Server Vulnerability Let Attackers Become an Admin User
Critical NetApp SnapCenter Server Vulnerability Let Attackers Become an Admin User A high-severity security vulnerability discovered in NetApp SnapCenter could allow authenticated users to gain administrative privileges on remote systems, posing significant risks to organizational d … Read more Published Date: Mar 26, 2025 (3 hours, 21 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-26512