Aggregator
GreyNoise Discovers Stealthy Backdoor Campaign Affecting Thousands of ASUS Routers
3 months 1 week ago
GreyNoise uncovers a stealth campaign exploiting ASUS routers, enabling persistent backdoor access via CVE-2023-39780 and unpatched techniques. Learn how attackers evade detection, how GreyNoise discovered it with AI-powered tooling, and what defenders need to know.
个人信息保护合规审计如何开展?速下载新规实践指南!
3 months 1 week ago
助力企业高效开展个保合规审计工作。
小米净利润首次超百亿,汽车占总营收 16%;雷鸟发布「柯南联名」AR 眼镜;可灵AI单季收入超1.5亿|极客早知道
3 months 1 week ago
小米集团公布财报,2025 年第一季度,集团收入及盈利均再次创下历史新高。一季度可灵 AI 的营业收入达到人民币 1.5 亿元。雷鸟今日推出了三款名侦探柯南联名 AR 眼镜。
CVE-2022-40933 | oretnom23 Online Pet Shop We App 1.0 Master.php?f=delete_order ID sql injection
3 months 1 week ago
A vulnerability, which was classified as critical, was found in oretnom23 Online Pet Shop We App 1.0. Affected is an unknown function of the file /pet_shop/classes/Master.php?f=delete_order. The manipulation of the argument ID leads to sql injection.
This vulnerability is traded as CVE-2022-40933. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2022-40934 | oretnom23 Online Pet Shop We App 1.0 Master.php?f=delete_sub_category ID sql injection
3 months 1 week ago
A vulnerability has been found in oretnom23 Online Pet Shop We App 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pet_shop/classes/Master.php?f=delete_sub_category. The manipulation of the argument ID leads to sql injection.
This vulnerability is known as CVE-2022-40934. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2022-40935 | oretnom23 Online Pet Shop We App 1.0 Master.php?f=delete_category ID sql injection
3 months 1 week ago
A vulnerability was found in oretnom23 Online Pet Shop We App 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /pet_shop/classes/Master.php?f=delete_category. The manipulation of the argument ID leads to sql injection.
This vulnerability is handled as CVE-2022-40935. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2022-35037 | OTFCC 617837b otfccdump+0x6adb1e heap-based overflow
3 months 1 week ago
A vulnerability, which was classified as critical, was found in OTFCC 617837b. Affected is an unknown function of the file /release-x64/otfccdump+0x6adb1e. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2022-35037. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2022-35038 | OTFCC 617837b otfccdump+0x6b064d out-of-bounds write
3 months 1 week ago
A vulnerability has been found in OTFCC 617837b and classified as critical. Affected by this vulnerability is an unknown functionality of the file /release-x64/otfccdump+0x6b064d. The manipulation leads to out-of-bounds write.
This vulnerability is known as CVE-2022-35038. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2022-35039 | OTFCC 617837b otfccdump+0x6e20a0 out-of-bounds write
3 months 1 week ago
A vulnerability was found in OTFCC 617837b and classified as critical. Affected by this issue is some unknown functionality of the file /release-x64/otfccdump+0x6e20a0. The manipulation leads to out-of-bounds write.
This vulnerability is handled as CVE-2022-35039. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2022-36934 | Facebook WhatsApp on iOS/Android Video Call heap-based overflow
3 months 1 week ago
A vulnerability has been found in Facebook WhatsApp on iOS/Android and classified as critical. This vulnerability affects unknown code of the component Video Call Handler. The manipulation leads to heap-based buffer overflow.
This vulnerability was named CVE-2022-36934. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-30426 | Acer Altos T110 F3 UEFI DXE Driver stack-based overflow
3 months 1 week ago
A vulnerability was found in Acer Altos T110 F3, AP130 F2, Aspire 1600X, Aspire 1602M, Aspire 7600U, Aspire MC605, Aspire TC-105, Aspire TC-120, Aspire U5-620, Aspire X1935, Aspire X3475, Aspire X3995, Aspire XC100, Aspire XC600, Aspire Z3-615, Veriton E430G, Veriton B630_49, Veriton E430 and Veriton M2110G. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component UEFI DXE Driver. The manipulation leads to stack-based buffer overflow.
This vulnerability is known as CVE-2022-30426. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2022-38573 | 10-Strike Network Inventory Explorer 9.3 Add Computers buffer overflow (ID 168133)
3 months 1 week ago
A vulnerability was found in 10-Strike Network Inventory Explorer 9.3. It has been rated as critical. Affected by this issue is some unknown functionality of the component Add Computers Handler. The manipulation leads to buffer overflow.
This vulnerability is handled as CVE-2022-38573. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2021-41803 | HashiCorp Consul up to 1.11.8/1.12.4/1.13.1 Name authorization
3 months 1 week ago
A vulnerability, which was classified as problematic, has been found in HashiCorp Consul up to 1.11.8/1.12.4/1.13.1. This issue affects some unknown processing of the component Name Handler. The manipulation leads to missing authorization.
The identification of this vulnerability is CVE-2021-41803. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-40298 | Crestron AirMedia 4.3.1.39 on Windows insecure inherited permissions
3 months 1 week ago
A vulnerability was found in Crestron AirMedia 4.3.1.39 on Windows and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to insecure inherited permissions.
This vulnerability is handled as CVE-2022-40298. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Daily Dose of Dark Web Informer - 27th of May 2025
3 months 1 week ago
This daily article is intended to make it easier for those who want to stay updated with my regular Dark Web Informer and X/Twitter posts.
Dark Web Informer - Cyber Threat Intelligence
Threat Attack Daily - 27th of May 2025
3 months 1 week ago
Threat Attack Daily - 27th of May 2025
Dark Web Informer - Cyber Threat Intelligence
Ransomware Attack Update for the 27th of May 2025
3 months 1 week ago
Ransomware Attack Update for the 27th of May 2025
Dark Web Informer - Cyber Threat Intelligence
CVE-2022-35025 | OTFCC 617837b otfccdump+0x5266a8 memory corruption
3 months 1 week ago
A vulnerability classified as critical was found in OTFCC 617837b. Affected by this vulnerability is an unknown functionality of the file /release-x64/otfccdump+0x5266a8. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2022-35025. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2022-35026 | OTFCC 617837b otfccdump+0x4fbc0b memory corruption
3 months 1 week ago
A vulnerability, which was classified as critical, has been found in OTFCC 617837b. Affected by this issue is some unknown functionality of the file /release-x64/otfccdump+0x4fbc0b. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2022-35026. The attack needs to be done within the local network. There is no exploit available.
vuldb.com