B3NCLOUD.NET
News Intel Stats Tools
CyberNews
B3N.CLOUD
Hauptseiten
Startseite
CyberNews
Quick IT-Tools
Suche
Updates
Security Tools
Breach Check
Phishing Check
IoC Extractor
SSL Check
E-Mail Header Analyzer
CVE-Suche
Cyber IntelligenceNEU
IT-Praxis
Firewall RulesNEU
Security ChecklistsNEU
Incident ResponseNEU
Regex TesterNEU
Cron BuilderNEU
Log AnalyzerNEU
Informationen
Dokumentation
Statistiken
Impressum
Datenschutz
RSS Feed
© 2026 b3ncloud.net

ARTIKEL SUCHE

Threat Feed Query

Durchsuche alle aggregierten Security-Artikel nach Schlagworten, CVE-IDs und Quellen.

2865 Ergebnisse fuer critical Seite 64 von 144

Apache Struts 2 DoS Vulnerability Let Attackers Crash Server

A critical denial-of-service vulnerability has been discovered in Apache Struts 2, affecting multiple versions of the popular web application framework. The vulnerability, identified as CVE-2025-64775, exploits a file le

cybersecuritynews.com • 2025-12-12

React2Shell Exploitation Escalates into Large-Scale Global Attacks, Forcing Emergency Mitigation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged federal agencies to patch the recent React2Shell vulnerability by December 12, 2025, amid reports of widespread exploitation. The critical vulner

thehackernews.com • 2025-12-12

Windows Remote Access Connection Manager Vulnerabilities Let Attackers Escalate Privileges

Two critical privilege escalation flaws were disclosed in the Windows Remote Access Connection Manager on December 9, 2025. The vulnerabilities, tracked as CVE-2025-62472 and CVE-2025-62474, allow authorized attackers wi

cybersecuritynews.com • 2025-12-12

CISA Warns of OSGeo GeoServer 0-Day Vulnerability Exploited in Attacks

An urgent warning about a critical security flaw in OSGeo GeoServer, a widely used open-source geographic data-sharing server. CISA has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, indica

cybersecuritynews.com • 2025-12-12

New Vulnerabilities in React Server Components Allow DoS Attacks and Source Code Leaks

Less than a week after addressing a critical Remote Code Execution (RCE) vulnerability, the React team has disclosed three additional security flaws affecting React Server Components (RSC). Security researchers discovere

cybersecuritynews.com • 2025-12-12

CVE-2025-66446 - MaxKB has a Python sandbox LD_PRELOAD bypass

CVE ID : CVE-2025-66446 Published : Dec. 11, 2025, 10:15 p.m. | 35 minutes ago Description : MaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow att

cvefeed.io • 2025-12-11

Critical Gogs zero-day under attack, 700 servers hacked

Hackers exploited an unpatched Gogs zero-day, allowing remote code execution and compromising around 700 Internet-facing servers. Gogs is a self-hosted Git service, similar to GitHub, GitLab, or Bitbucket, but designed t

securityaffairs.com • 2025-12-11

Microsoft bounty program now includes any flaw impacting its services

Microsoft now pays security researchers for finding critical vulnerabilities in any of its online services, regardless of whether the code was written by Microsoft or a third party. [...]

bleepingcomputer.com • 2025-12-11

Gogs 0-Day Vulnerability Exploited in the Wild to Hack 700+ Instances

A critical zero-day vulnerability in Gogs, a widely used self-hosted Git service, is currently being exploited in the wild. Designated as CVE-2025-8110, this flaw allows authenticated users to execute a symlink bypass, l

cybersecuritynews.com • 2025-12-11

INE Highlights Enterprise Shift Toward Hands-On Training Amid Widening Skills Gaps

Cary, North Carolina, USA, December 11th, 2025, CyberNewsWire As AI accelerates job transformation, INE supports organizations reallocating Q4 budgets to experiential, performance-driven upskilling. With 90% of organizat

cybersecuritynews.com • 2025-12-11

Critical Vulnerability in Multiple India-Based CCTV Cameras Let Attackers Video and Account Credentials

A severe security vulnerability affecting multiple India-based CCTV camera manufacturers has been disclosed. Potentially allowing attackers to access video feeds and steal account credentials without authentication. The

cybersecuritynews.com • 2025-12-11

GitLab Patches Multiple Vulnerabilities that Allows Attackers to Trigger XSS and DoS Attack

Critical security patches on December 10, 2025, addressing ten significant vulnerabilities across its Community Edition and Enterprise Edition platforms. GitLab has released updated versions 18.6.2, 18.5.4, and 18.4.6 to

cybersecuritynews.com • 2025-12-11

IBM Patches Over 100 Vulnerabilities

Most of the 100 vulnerabilities resolved this week, including critical flaws, were in third-party dependencies. The post IBM Patches Over 100 Vulnerabilities appeared first on SecurityWeek.

securityweek.com • 2025-12-11

Windows Defender Firewall Service Vulnerability Let Attackers Disclose Sensitive Data

A critical information disclosure vulnerability in Windows Defender Firewall Service, which could allow authorized attackers to access sensitive heap memory on affected systems. The vulnerability, tracked as CVE-2025-624

cybersecuritynews.com • 2025-12-11

Adobe Acrobat Reader Vulnerabilities Let Attackers Execute Arbitrary Code and Bypass Security

Critical security updates for Acrobat and Reader are available, addressing multiple vulnerabilities that could allow attackers to execute arbitrary code and bypass essential security features. Adobe issued security bulle

cybersecuritynews.com • 2025-12-11

Fortinet fixed two critical authentication-bypass vulnerabilities

Fortinet patched 18 flaws, including two authentication-bypass bugs affecting FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager with FortiCloud SSO enabled. Fortinet addressed 18 vulnerabilities, including two authen

securityaffairs.com • 2025-12-10

CVE-2025-13607 - Cisco Camera Unauthenticated Configuration Information Disclosure

CVE ID : CVE-2025-13607 Published : Dec. 10, 2025, 6:16 p.m. | 33 minutes ago Description : A malicious actor can access camera configuration information, including account credentials, without authenticating when acc

cvefeed.io • 2025-12-10

Critical Ivanti EPM Vulnerability Allows Admin Session Hijacking via Stored XSS

A critical stored cross-site scripting vulnerability in Ivanti Endpoint Manager (“EPM”) versions 2024 SU4 and below, that could enable attackers to hijack administrator sessions without authentication. The vulnerability,

cybersecuritynews.com • 2025-12-10

Over 644,000 Domains Exposed to Critical React Server Components Vulnerability

The Shadowserver Foundation has released alarming new data regarding the exposure of web applications to CVE-2025-55182, a critical vulnerability affecting React Server Components. Following significant improvements to t

cybersecuritynews.com • 2025-12-10

Why a secure software development life cycle is critical for manufacturers

Recent supply-chain breaches show how attackers exploit development tools, compromised credentials, and malicious NPM packages to infiltrate manufacturing and production environments. Acronis explains why secure software

bleepingcomputer.com • 2025-12-10
 Zurueck 1 2 3 ... 63 64 65 ... 143 144 Weiter 
B3N.CLOUD
Docs News Tools Suche Impressum Datenschutz
Status
Cookies

Diese Website verwendet ausschließlich technisch notwendige Cookies (Session, Spracheinstellung). Kein Tracking, keine Werbung. Mehr erfahren