CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-20188

Description: A vulnerability in the Out-of-Band Access Point (AP) Image Download feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system. This vulnerability is due to the presence of a hard-coded JSON Web Token (JWT) on an affected system. An attacker could exploit this vulnerability by sending crafted HTTPS requests to the AP image download interface. A successful exploit could allow the attacker to upload files, perform path traversal, and execute arbitrary commands with root privileges.  Note: For exploitation to be successful, the Out-of-Band AP Image Download feature must be enabled on the device. It is not enabled by default. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-file-uplpd-rHZG9UfC This advisory is part of the May 2025 release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: May 2025 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication. Security Impact Rating: Critical CVE: CVE-2025-20188

EPSS Score: 3.8%

Source: Cisco Security Advisory
May 7th, 2025 (about 2 months ago)

CVE-2025-20140

Description: A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent wireless attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper memory management. An attacker could exploit this vulnerability by sending a series of IPv6 network requests from an associated wireless IPv6 client to an affected device. To associate a client to a device, an attacker may first need to authenticate to the network, or associate freely in the case of a configured open network. A successful exploit could allow the attacker to cause the wncd process to consume available memory and eventually cause the device to stop responding, resulting in a DoS condition. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-wncd-p6Gvt6HL This advisory is part of the May 2025 release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: May 2025 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication. Security Impact Rating: High CVE: CVE-2025-20140

EPSS Score: 0.02%

Source: Cisco Security Advisory
May 7th, 2025 (about 2 months ago)
Description: Pat McFadden, the most senior minister in Britain’s Cabinet Office, told the CYBERUK conference that Beijing had “the sophistication, the scale and the seriousness” to pose an exceptional national security challenge.
Source: The Record
May 7th, 2025 (about 2 months ago)
Description: Cyber chief Richard Horne said intelligence agencies were seeing the hacking threat from Russia manifesting “on the streets of the UK."
Source: The Record
May 7th, 2025 (about 2 months ago)
Description: A one-paragraph advisory from CISA warns of attempts by “unsophisticated cyber actor(s)” to disrupt industrial technology, particularly in the energy industry.
Source: The Record
May 7th, 2025 (about 2 months ago)
Description: Alleged Sale of Crypto Traders Data from France
Source: DarkWebInformer
May 7th, 2025 (about 2 months ago)

CVE-2025-29448

Description: A business logic vulnerability in Easy Appointments v1.5.1 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

EPSS Score: 0.06%

Source: CVE
May 7th, 2025 (about 2 months ago)
Description: Alleged Sale of Trader Data from Canada and Italy
Source: DarkWebInformer
May 7th, 2025 (about 2 months ago)
Description: Quick Post: These short-form updates provide fast, digestible summaries of breaches, DDoS attacks, and defacements—ideal when full details aren't yet available. Because having a reliable source and critical data when you need it matters. × 💡 Subscribe to DarkWebInformer.com for Unmatched Cyber Threat Intelligence 💡
Source: DarkWebInformer
May 7th, 2025 (about 2 months ago)
Description: Nickelodeon’s cartoon character tells kids why it’s cool to be a kind of toxic male that comes from the darkest corners of the manosphere.
Source: 404 Media
May 7th, 2025 (about 2 months ago)