24h | 7d | 30d

Overview

  • Oracle Corporation
  • Oracle Java SE

15 Jul 2025
Published
18 Jul 2025
Updated

CVSS v3.1
MEDIUM (5.9)
EPSS
0.03%

KEV

Description

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u451, 8u451-perf and 11.0.27; Oracle GraalVM Enterprise Edition: 21.3.14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).

Statistics

  • 1 Post
  • 3 Interactions

Fediverse

Profile picture
CVE-2025-30761:A vulnerability in JDK's Nashorn Allows for Arbitrary Code Execution

https://seclists.org/oss-sec/2025/q3/43

Ooooh I love this! Can't wait to see the details....

#Java #JavaScript
  • 1
  • 2
  • 14 hours ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 1 Interaction

Fediverse

Profile picture

Go hack more Ubiquiti shit.

community.ui.com/releases/Secu

sev:CRIT 9.8 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with access to UniFi Access management network.

cve.org/CVERecord?id=CVE-2025-

  • 1
  • 0
  • 11 hours ago

Overview

  • Microsoft
  • Windows 10 Version 1809

08 Apr 2025
Published
04 Jun 2025
Updated

CVSS v3.1
HIGH (7.8)
EPSS
2.69%

Description

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Statistics

  • 1 Post
  • 1 Interaction

Fediverse

Profile picture
[RSS] My `Blind Date` with CVE-2025-29824

Another Windows CLFS exploit

https://starlabs.sg/blog/2025/07-my-blind-date-with-cve-2025-29824/
  • 0
  • 1
  • 20 hours ago

Overview

  • WP Swings
  • WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet

18 Jul 2025
Published
18 Jul 2025
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.15%

KEV

Description

The WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ced_rnx_order_exchange_attach_files' function in all versions up to, and including, 3.2.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

Statistics

  • 1 Post

Fediverse

Profile picture

🚨 CVE-2025-6222: CRITICAL vuln (CVSS 9.8) in WP Swings WooCommerce Refund plugin allows unauthenticated file uploads, risking RCE. All versions up to 3.2.6 affected. Disable plugin ASAP. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 22 hours ago

Overview

  • Lenovo
  • PC Manager

17 Jul 2025
Published
17 Jul 2025
Updated

CVSS v4.0
HIGH (8.4)
EPSS
0.01%

KEV

Description

A buffer overflow vulnerability was reported in the Lenovo Protection Driver, prior to version 5.1.1110.4231, used in Lenovo PC Manager, Lenovo Browser, and Lenovo App Store could allow a local attacker with elevated privileges to execute arbitrary code.

Statistics

  • 1 Post

Fediverse

Profile picture

Critical Lenovo Driver Flaw Exposes Millions: CVE-2025-4657 Enables Full System Takeover

A Dangerous Threat Hiding in Plain Sight In July 2025, security researchers uncovered a critical buffer overflow vulnerability—CVE-2025-4657—embedded in Lenovo’s lrtp.sys Protection Driver, used widely in Lenovo PC Manager, Browser, and App Store utilities. This vulnerability, if exploited, allows attackers with local access to gain full system privileges on millions of Lenovo…

undercodenews.com/critical-len

  • 0
  • 0
  • 15 hours ago

Overview

  • LoginPress
  • LoginPress Pro

18 Jul 2025
Published
18 Jul 2025
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.14%

KEV

Description

The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.0.1. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.

Statistics

  • 1 Post

Fediverse

Profile picture

🔥 CRITICAL vuln: LoginPress Pro (all versions ≤5.0.1) lets attackers bypass auth with social login token, gaining admin access (CVE-2025-7444, CVSS 9.8). No fix yet—monitor for suspicious logins! radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 20 hours ago

Overview

  • aaroncampbell
  • Attachment Manager

18 Jul 2025
Published
18 Jul 2025
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
0.97%

KEV

Description

The Attachment Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handle_actions() function in all versions up to, and including, 2.1.2. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

Statistics

  • 1 Post

Fediverse

Profile picture

🚨 CRITICAL: CVE-2025-7643 in Attachment Manager for WordPress (all versions ≤2.1.2) enables unauthenticated attackers to delete arbitrary files, risking RCE. Immediate action: remove plugin, restrict file perms, watch logs. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 23 hours ago

Overview

  • Microsoft
  • Microsoft Purview

18 Jul 2025
Published
18 Jul 2025
Updated

CVSS v3.1
HIGH (8.7)
EPSS
Pending

KEV

Description

Permissive list of allowed inputs in Microsoft Purview allows an authorized attacker to elevate privileges over a network.

Statistics

  • 1 Post

Fediverse

Profile picture

There was also an EoP in Purview. Also not exploited, no action required.

msrc.microsoft.com/update-guid

  • 0
  • 0
  • 12 hours ago

Overview

  • Apache Software Foundation
  • Apache HTTP Server

05 Oct 2021
Published
04 Feb 2025
Updated

CVSS
Pending
EPSS
94.40%

Description

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.

Statistics

  • 1 Post

Fediverse

Profile picture

En las últimas 24 horas, Sophos ha presentado soluciones innovadoras de ciberseguridad, mientras que ha aumentado la actividad maliciosa relacionada con ClickFix y un nuevo malware en Microsoft Teams. Además, se detectó un ataque en Apache para minar criptomonedas y una grave filtración de datos en una agencia de adopciones. Google también iniciará acciones legales contra la botnet BadBox 2.0. Descubre estos y más detalles en el siguiente listado de noticias sobre seguridad informática:

🗞️ ÚLTIMAS NOTICIAS EN SEGURIDAD INFORMÁTICA 🔒
====| 🔥 LO QUE DEBES SABER HOY 18/07/25 📆 |====

```
🔒 CIBERSEGURIDAD COMO SERVICIO OFRECIDA | SOPHOS
Sophos presenta un enfoque innovador para mejorar la ciberseguridad de las organizaciones mediante un amplio portafolio de productos y servicios avanzados. Descubre cómo pueden protegerte a ti y a tu negocio. 👉 djar.co/zHuU

🔍 REDIRECTORES EN NUEVAS CAMPAÑAS DE CLICKFIX
Evidenciamos un aumento en tres campañas ClickFix que han estado distribuyendo malware como NetSupport RAT, Latrodectus y Lumma Stealer. Comprender estas amenazas es esencial para fortalecer tu defensa. 👉 djar.co/I2oQc3

📞 MALWARE MATABUCHUS ATACA LLAMADAS DE MICROSOFT TEAMS
Un nuevo método de ataque ha surgido donde el cargador de malware Matanbuchus se distribuye a través de ingeniería social durante llamadas en Microsoft Teams, haciéndose pasar por soporte técnico. Infórmate sobre cómo protegerte. 👉 djar.co/ghy3Ju

💻 HACKERS EXPLOTAN VULNERABILIDAD EN APACHE PARA INSTALAR MINERO DE CRIPTOMONEDAS
Se descubre un ataque que utiliza la vulnerabilidad CVE-2021-41773 en Apache HTTP Server para instalar un minero de criptomonedas en sitios web comprometidos. No te pierdas los detalles y las acciones a tomar. 👉 djar.co/kUKSGh

📂 AGENCIA DE ADOPCIONES FILTRA MÁS DE UN MILLÓN DE REGISTROS
Una filtración masiva expone 1,115,061 registros que contienen información sensible de niños y familias adoptivas. Este incidente resalta la importancia de asegurar la privacidad de los datos personales. Infórmate sobre el caso. 👉 djar.co/jPt7

⚖️ GOOGLE DEMANDA DESARTICULAR LA BOTNET BADBOX 2.0 INFECTANDO 10 MILLONES DE DISPOSITIVOS
Google ha tomado acción legal contra los responsables de la botnet Android BadBox 2.0, señalando fraudes publicitarios a gran escala. Conoce más sobre esta lucha contra cibercriminales. 👉 djar.co/pHg8L
```

  • 0
  • 0
  • 18 hours ago

Overview

  • Pending

01 Aug 2023
Published
23 Oct 2024
Updated

CVSS
Pending
EPSS
26.00%

KEV

Description

Greenshot 1.2.10 and below allows arbitrary code execution because .NET content is insecurely deserialized when a .greenshot file is opened.

Statistics

  • 1 Post

Fediverse

Profile picture

Greenshot sollten sich alle anschauen, die öfters Screenshots unter Windows oder macOS machen.

deskmodder.de/blog/2025/07/18/

  • 0
  • 0
  • 23 hours ago
Showing 11 to 20 of 38 CVEs