CVE/vulnerability
Salesforce Applications Vulnerability Could Allow Full Account Takeover
A critical vulnerability has been discovered in Salesforce applications that could potentially allow a full account takeover.The vulnerability, uncovered during a penetration testing exercise, hinges on misconfigurations within...
CVE/vulnerability
TP-Link HomeShield Function Vulnerability Let Attackers Inject Malicious Commands
A significant vulnerability has been identified in TP-Link's HomeShield function, affecting a range of their devices, including the Archer, Deco, and Tapo series routers....
CVE/vulnerability
HPE IceWall Flaw Let Attackers cause Unauthorized Data Modification
Hewlett Packard Enterprise (HPE) has issued an urgent security bulletin addressing a critical vulnerability in its IceWall product line.Identified as CVE-2024-11856, this flaw...
Apple
Apple Safari JavaScriptCore Remote Code Execution Flaw Exploited in the Wild
A critical vulnerability identified as CVE-2024-44308 has been actively exploited in the wild, affecting multiple versions of Apple Safari across iOS, visionOS, and macOS...
CVE/vulnerability
MediaTek Processor Vulnerabilities Let Attackers Escalate Privileges
Several vulnerabilities affecting MediaTek processors have been identified, potentially allowing attackers to escalate privileges on affected devices.These vulnerabilities span multiple components, including video...
CVE/vulnerability
Zyxel Firewall Vulnerability Actively Exploited in Attacks
Zyxel has announced awareness of active exploitation attempts by threat actors targeting their firewall products.This follows a detailed report by cybersecurity firm Sekoia...
CVE/vulnerability
Helldown Ransomware Attacking Windows And Linux Servers Evading Detection
Helldown Ransomware, a sophisticated cyber threat, actively targets critical industries worldwide by leveraging advanced cross-platform capabilities, including Windows and Linux, to encrypt files and...
CVE/vulnerability
Critical Jenkins Vulnerability Let Attackers Trigger DoS & Inject Scripts
A series of vulnerabilities have been identified, posing significant risks to the system's security.These vulnerabilities could allow attackers to trigger denial of service...
CVE/vulnerability
New Windows 11 Vulnerability Lets Attackers Elevate Privileges
A new vulnerability has been discovered in Windows 11, specifically affecting the 23H2 version.This vulnerability is identified in the ksthunk.sys driver, allows attackers to exploit...
CVE/vulnerability
Microsoft Patches Multiple Vulnerabilities Allow Attackers to Elevate Privileges
Microsoft has recently released patches addressing multiple vulnerabilities that could enable attackers to elevate privileges across various Microsoft products.The patches are part of...
CVE/vulnerability
ProjectSend Authentication Vulnerability Exploited in the Wild
ProjectSend, an open-source file-sharing web application, has become a target of active exploitation following the recent assignment of CVE-2024-11680 on November 25, 2024.Despite the...