![]() |
Description: Hunk Companion Plugin 1.9.0 - Unauthenticated Plugin Installation
April 18th, 2025 (1 day ago)
|
![]() |
Description: Tatsu 3.3.11 - Unauthenticated RCE
April 18th, 2025 (1 day ago)
|
![]() |
Description: Apache Commons Text 1.10.0 - Remote Code Execution
April 18th, 2025 (1 day ago)
|
![]() |
Description: Langflow 1.3.0 - Remote Code Execution (RCE)
April 18th, 2025 (1 day ago)
|
![]() |
Description: Ahead of a key hearing in the U.S. government's antitrust case against Google, Mozilla CEO Laura Chambers has warned that some proposed remedies could unintentionally damage Firefox and the broader ecosystem of independent browsers. The hearing, scheduled for April 21, 2025, follows the DOJ's 2020 lawsuit accusing Google of illegally maintaining its monopoly in the …
The post Mozilla Fears Firefox Fallout from Google Search Antitrust Case appeared first on CyberInsider.
April 18th, 2025 (1 day ago)
|
![]() |
April 18th, 2025 (1 day ago)
|
![]() |
Description: Microsoft has announced that support for Office 2016 and Office 2019 will officially end on October 14, 2025, prompting organizations to begin planning their migration to Microsoft 365 Apps. The company emphasizes that continuing to use these legacy versions after the deadline could result in missing critical security updates and experiencing connectivity issues with Microsoft …
The post Microsoft Sets October 2025 Deadline to Replace Office 2016 and 2019 appeared first on CyberInsider.
April 18th, 2025 (1 day ago)
|
CVE-2025-3785 |
Description: A vulnerability has been found in D-Link DWR-M961 1.1.36 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formStaticDHCP of the component Authorization Interface. The manipulation of the argument Hostname leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.1.49 is able to address this issue. It is recommended to upgrade the affected component. In D-Link DWR-M961 1.1.36 wurde eine kritische Schwachstelle gefunden. Dabei geht es um eine nicht genauer bekannte Funktion der Datei /boafrm/formStaticDHCP der Komponente Authorization Interface. Mittels Manipulieren des Arguments Hostname mit unbekannten Daten kann eine stack-based buffer overflow-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung. Ein Aktualisieren auf die Version 1.1.49 vermag dieses Problem zu lösen. Als bestmögliche Massnahme wird das Einspielen eines Upgrades empfohlen.
CVSS: HIGH (8.7) EPSS Score: 0.05%
April 18th, 2025 (1 day ago)
|
CVE-2025-3056 |
Download Manager <= 3.3.12 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
Description: The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
CVSS: MEDIUM (5.4) EPSS Score: 0.03%
April 18th, 2025 (1 day ago)
|
CVE-2025-2492 |
Description: An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted request, potentially leading to unauthorized execution of functions.
Refer to the 'ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.
CVSS: CRITICAL (9.2) EPSS Score: 0.1%
April 18th, 2025 (1 day ago)
|