TVT DVRs Under Siege: Massive Exploitation Attempts Expose Critical Flaw

TVT DVRs Under Siege: Massive Exploitation Attempts Expose Critical Flaw A significant surge in malicious cyber activity has been detected, raising alarms for organizations utilizing TVT NVMS9000 DVRs. GreyNoise intelligence reports “a significant spike 3 times that of typ … Read more Published Date: Apr 08, 2025 (3 hours, 53 minutes ago) Vulnerabilities has been mentioned in […]

CVE-2025-3391 – Hailey888 Oa_System Cross-Site Scripting Vulnerability

The following table lists the changes that have been made to the CVE-2025-3391 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 08, 2025 Action […]

Top 5 VPN Vulnerabilities in 2025

Top 5 VPN Vulnerabilities in 2025 I. Executive SummaryThe reliance on Virtual Private Networks (VPNs) has grown significantly as organizations embrace remote work and individuals seek enhanced online privacy and security. However, thi … Read more Published Date: Apr 08, 2025 (2 hours, 41 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-20654 CVE-2025-30401 CVE-2025-27520 CVE-2025-2244 […]

WhatsApp for Windows Spoofing Vulnerability: Execute Code Risk (CVE-2025-30401)

WhatsApp for Windows Spoofing Vulnerability: Execute Code Risk (CVE-2025-30401) A security advisory from Facebook details a spoofing vulnerability in WhatsApp for Windows, highlighting a potential risk where malicious actors could trick users into executing arbitrary code. The vu … Read more Published Date: Apr 08, 2025 (2 hours, 56 minutes ago) Vulnerabilities has been mentioned in this […]

CVE-2025-27520: Critical BentoML Flaw Allows Full Remote Code Execution, Exploit Available

CVE-2025-27520: Critical BentoML Flaw Allows Full Remote Code Execution, Exploit Available A severe security vulnerability has been identified in BentoML, a Python library used for building online serving systems optimized for AI applications and model inference. The vulnerability, tracked … Read more Published Date: Apr 08, 2025 (3 hours, 1 minute ago) Vulnerabilities has been mentioned in […]

CVE-2024-11859: ToddyCat Group Hides Malware in ESET’s Scanner to Bypass Security

CVE-2024-11859: ToddyCat Group Hides Malware in ESET’s Scanner to Bypass Security Advanced Persistent Threat (APT) groups are constantly evolving their techniques to evade detection. Kaspersky Labs has recently uncovered a sophisticated method employed by the ToddyCat group: hiding … Read more Published Date: Apr 08, 2025 (3 hours, 2 minutes ago) Vulnerabilities has been mentioned in this […]

Pexip Issues Urgent Security Update to Address Critical Vulnerabilities

Pexip Issues Urgent Security Update to Address Critical Vulnerabilities Pexip, a leading provider of self-hosted video conferencing platforms, has released a security bulletin detailing critical vulnerabilities in its Infinity platform.Critical Heap-Based Buffer OverflowA … Read more Published Date: Apr 08, 2025 (3 hours, 9 minutes ago) Vulnerabilities has been mentioned in this article.

PoC Released for CVE-2025-3155: Yelp Flaw Can Expose SSH Keys on Ubuntu Systems

PoC Released for CVE-2025-3155: Yelp Flaw Can Expose SSH Keys on Ubuntu Systems A security vulnerability, identified as CVE-2025-3155, has been discovered in Yelp, the GNOME user help application that comes pre-installed on Ubuntu desktop. The vulnerability involves the way Yelp … Read more Published Date: Apr 08, 2025 (3 hours, 17 minutes ago) Vulnerabilities has been […]

CVE-2025-3389 – Hailey888 Oa_system Cross-Site Scripting Vulnerability

The following table lists the changes that have been made to the CVE-2025-3389 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 08, 2025 Action […]

CVE-2025-3390 – “Hailey888 OA System Backend DaymanageController Cross-Site Scripting Vulnerability”

The following table lists the changes that have been made to the CVE-2025-3390 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 08, 2025 Action […]