Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

Description: This week, our Year in Review spotlight is on ransomware—where low-profile tactics led to high-impact consequences. Download our 2 page ransomware summary, or watch our 55 second video.
Source: Cisco Talos Blog
April 15th, 2025 (about 1 hour ago)

CVE-2025-2083

Description: The Logo Carousel Gutenberg Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sliderId’ parameter in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS: MEDIUM (6.4)

Source: CVE
April 15th, 2025 (about 1 hour ago)
Description: The North Korea-linked threat actor assessed to be behind the massive Bybit hack in February 2025 has been linked to a malicious campaign that targets developers to deliver new stealer malware under the guise of a coding assignment. The activity has been attributed by Palo Alto Networks Unit 42 to a hacking group it tracks as Slow Pisces, which is also known as Jade Sleet, PUKCHONG,
Source: TheHackerNews
April 15th, 2025 (about 1 hour ago)
Description: Oregon Department of Environmental Quality They think their data hasn't been stolen. They're sorely mistaken.Over 2.5 terabytes of unique data. (SQL, employee data and more)We are waiting for your suggestions.
Source: Ransomware.live
April 15th, 2025 (about 1 hour ago)
Description: Founded in 1958 in the Buffalo, NY by the Sisters of Mercy, Trocaire College is a private, career-oriented Catholic college that strives to empower students toward personal enrichment, dignity and self-worth through education. A career-oriented institution, Trocaire offers bachelor's degrees, associate degrees and certificate and workforce development programs in healthcare, business, hospitality and technology. Recognizing the individual needs of a diverse student body, Trocaire College provides life learning and development within a community-based environment, preparing students for service in the universal community. ===> Phone Number: (716) 826-1200 Revenue: $24.6 Million Industry: Education Employees: 217 Data: 310gb
Source: Ransomware.live
April 15th, 2025 (about 1 hour ago)
Description: ​​​​Newhotel Cloud is a comprehensive, cloud-based Property Management System (PMS) developed by Newhotel Software to streamline hotel operations of...
Source: Ransomware.live
April 15th, 2025 (about 1 hour ago)

CVE-2025-3579

Description: In versions prior to Aidex 1.7, an authenticated malicious user, taking advantage of an open registry, could execute unauthorised commands within the system. This includes executing operating system (Unix) commands, interacting with internal services such as PHP or MySQL, and even invoking native functions of the framework used, such as Laravel or Symfony. This execution is achieved by Prompt Injection attacks through the /api//message endpoint, manipulating the content of the ‘content’ parameter.

CVSS: CRITICAL (9.3)

Source: CVE
April 15th, 2025 (about 2 hours ago)

CVE-2025-3578

Description: A malicious, authenticated user in Aidex, versions prior to 1.7, could list credentials of other users, create or modify existing users in the application, list credentials of users in production or development environments. In addition, it would be possible to cause bugs that would result in the exfiltration of sensitive information, such as details about the software or internal system paths. These actions could be carried out through the misuse of LLM Prompt (chatbot) technology, via the /api//message endpoint, by manipulating the contents of the ‘content’ parameter.

CVSS: CRITICAL (9.3)

Source: CVE
April 15th, 2025 (about 2 hours ago)

CVE-2025-3575

Description: Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive information from others users via "idUsuario" parameter in "/helper/Familia/establecerUsuarioSeleccion" endpoint.

CVSS: HIGH (8.7)

Source: CVE
April 15th, 2025 (about 2 hours ago)

CVE-2025-3574

Description: Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive information from others users via "idUsuario" parameter in "/helper/Familia/obtenerFamiliaUsuario" endpoint.

CVSS: HIGH (8.7)

Source: CVE
April 15th, 2025 (about 2 hours ago)