Aggregator
CVE-2024-47880 | OpenRefine up to 3.8.2 Header Content-Type cross site scripting (GHSA-79jv-5226-783f)
CVE-2024-48932 | IceWhaleTech ZimaOS up to 1.2.4 API Endpoint /v1/users/name` access control (GHSA-9mrr-px2c-w42c)
CVE-2024-47879 | OpenRefine up to 3.8.2 cross-site request forgery (GHSA-3jm4-c6qf-jrh3)
CVE-2024-49750 | snowflakedb snowflake-connector-python up to 3.12.2 Logging Level passcode log file (GHSA-5vvg-pvhp-hv2m)
CVE-2024-49762 | Pterodactyl Panel up to 1.11.7 Two-factor Authentication cleartext storage in a file or on disk (GHSA-c479-wq8g-57hr)
CVE-2024-41617 | Money Manager EX WebApp 1.2.2 functions_security.php redirect_if_not_loggedin access control (Issue 51)
CVE-2024-10327 | Okta Verify 9.25.1/9.27.0 on iOS Push Notification ContextExtension improper authentication
专家解读 | 赵刚:公共数据资源开发利用——深化数据要素市场化配置改革的关键举措
CNNVD | 关于Fortinet FortiManager访问控制错误漏洞的通报
专题·勒索软件治理 | 工业领域网络勒索攻击防范应对的挑战与对策
评论 | 让网络语言更规范又不失活力
观点 | 以“隐私设计”理念指引数据隐私保护
前沿 | 携手“全球南方”构建网络空间命运共同体
CVE-2012-4528 | Trustwave ModSecurity up to 2.7.0 Multipart Request Parser POST Request access control (SA-20121017-0 / EDB-37949)
Ntoseye: Windows kernel debugger for Linux hosts running Windows under KVM/QEMU
Ntoseye Windows kernel debugger for Linux hosts running Windows under KVM/QEMU. Features Command line interface WinDbg style commands Kernel debugging PDB fetching Breakpointing Scripting API (Lua) Supported Windows ntoseye currently only supports Windows 10...
The post Ntoseye: Windows kernel debugger for Linux hosts running Windows under KVM/QEMU appeared first on Penetration Testing Tools.
getaltname: Extract subdomains from SSL certificates in HTTPS sites
GetAltName GetAltName (or GAN) is a tool that can extract Subject Alternative Names found in SSL Certificates directly from HTTPS websites which can provide you with DNS names (subdomains) or virtual servers. This code extracts subdomain names from https sites...
The post getaltname: Extract subdomains from SSL certificates in HTTPS sites appeared first on Penetration Testing Tools.
TLS-Attacker: Java-based framework for analyzing TLS libraries
TLS Attacker TLS-Attacker is a Java-based framework for analyzing TLS libraries. It can send arbitrary protocol messages in an arbitrary order to the TLS peer, and define their modifications using a provided interface. This...
The post TLS-Attacker: Java-based framework for analyzing TLS libraries appeared first on Penetration Testing Tools.