X

Vous n'êtes pas connecté

Maroc Maroc - THECYBERTHRONE.IN - A La Une - 01/Jan 09:58

CVE-2024-12987 affecting DrayTek Routers

CVE-2024-12987 is a critical security vulnerability identified in the DrayTek Vigor2960 and Vigor300B routers, specifically affecting firmware version 1.5.1.4. This vulnerability resides within the Web Management Interface, in the file path /cgi-bin/mainfunction.cgi/apmcfgupload. Detailed Breakdown 1. Nature of the Vulnerability:This vulnerability involves an OS Command Injection flaw. It is triggered by manipulating the session argument passed […]

Articles similaires

Sorry! Image not available at this time

Symantec Diagnostic Tool Flaw Enables Unauthorized Privilege Escalation

itsecuritynews.info - 20/Feb 08:11

Symantec, a division of Broadcom, has released a critical security update to address a high-severity vulnerability identified in its Symantec...

Sorry! Image not available at this time

CISA KEV Catalog Update Part I – March 2025

thecyberthrone.in - 04/Mar 01:36

On March 3, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities (KEV) catalog by adding...

Sorry! Image not available at this time

PoC Exploit Released for F5 BIG-IP Command Injection Vulnerability

itsecuritynews.info - 24/Feb 05:32

Security researchers have disclosed critical details about CVE-2025-20029, a command injection vulnerability in F5’s BIG-IP Traffic Management...

Sorry! Image not available at this time

Microsoft fixed actively exploited flaw in Power Pages

securityaffairs.co - 20/Feb 11:20

Microsoft addressed a privilege escalation vulnerability in Power Pages, the flaw is actively exploited in attacks. Microsoft has addressed two...

Sorry! Image not available at this time

U.S. CISA adds Microsoft Power Pages flaw to its Known Exploited Vulnerabilities catalog

securityaffairs.co - 23/Feb 15:07

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Power Pages vulnerability to its Known Exploited Vulnerabilities catalog....

Sorry! Image not available at this time

MongoDB is affected by Twin Critical Vulnerabilities

thecyberthrone.in - 21/Feb 14:04

CVE-2025-23061: Mongoose Search Injection Vulnerability Description: CVE-2025-23061 is a critical vulnerability identified in Mongoose versions prior...

Sorry! Image not available at this time

Nagios XI Flaw Exposes User Details and Emails to Unauthenticated Attackers”

itsecuritynews.info - 21/Feb 14:32

A security vulnerability in Nagios XI 2024R1.2.2, tracked as CVE-2024-54961, has been disclosed, allowing unauthenticated attackers to retrieve...

Sorry! Image not available at this time

Palo Alto Networks warns that CVE-2025-0111 flaw is actively exploited in attacks

securityaffairs.co - 20/Feb 06:32

Palo Alto Networks warns that the vulnerability CVE-2025-0111 is actively exploited with two other flaws to compromise PAN-OS firewalls. Palo Alto...

Sorry! Image not available at this time

Citrix NetScaler Vulnerability Exposes Systems to Unauthorized Commands

itsecuritynews.info - 20/Feb 06:07

Cloud Software Group has raced to address a severe security flaw in its widely used NetScaler management infrastructure that could enable...

Sorry! Image not available at this time

CISA Warns of Microsoft Partner Center Access Control Vulnerability Exploited in Wild

itsecuritynews.info - 26/Feb 05:33

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent advisory on February 25, 2025, confirming that threat actors are...

Les derniers communiqués

  • Aucun élément