Aggregator
红队实战技巧,通过 .NET 控制系统服务无痕关闭 Windows Defender
4 months ago
CVE-2025-27007 | Brainstorm Force SureTriggers Plugin up to 1.0.82 on WordPress privileges assignment (EDB-52286)
4 months ago
A vulnerability classified as critical has been found in Brainstorm Force SureTriggers Plugin up to 1.0.82 on WordPress. Affected is an unknown function. The manipulation leads to incorrect privilege assignment.
This vulnerability is traded as CVE-2025-27007. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
aftermath: Swift-based, open-source macOS incident response framework
4 months ago
Aftermath Aftermath is a Swift-based, open-source incident response framework. Aftermath can be leveraged by defenders in order to collect and subsequently analyze the data from the compromised host. Aftermath can be deployed from an...
The post aftermath: Swift-based, open-source macOS incident response framework appeared first on Penetration Testing Tools.
ddos
2025-05-12: Unidentified malware infection from email attachment
4 months ago
赛迪顾问发布交换机研究报告,威努特获优质厂商推荐
4 months ago
交换机技术引领车路云一体化系统智能升级!
赛迪顾问发布交换机研究报告,威努特获优质厂商推荐
4 months ago
交换机技术引领车路云一体化系统智能升级!
Trend Micro Puts a Spotlight on AI at Pwn2Own Berlin
4 months ago
Get a sneak peak into how Trend Micro's Pwn2Own Berlin 2025 is breaking new ground, focusing on AI infrastructure and finding the bugs to proactively safeguard the future of computing.
Russ Meyers
[local] RDPGuard 9.9.9 - Privilege Escalation
4 months ago
RDPGuard 9.9.9 - Privilege Escalation
[webapps] Kentico Xperience 13.0.178 - Cross Site Scripting (XSS)
4 months ago
Kentico Xperience 13.0.178 - Cross Site Scripting (XSS)
[webapps] WordPress Frontend Login and Registration Blocks Plugin 1.0.7 - Privilege Escalation
4 months ago
WordPress Frontend Login and Registration Blocks Plugin 1.0.7 - Privilege Escalation
[local] TP-Link VN020 F3v(T) TT_V6.2.1021) - DHCP Stack Buffer Overflow
4 months ago
TP-Link VN020 F3v(T) TT_V6.2.1021) - DHCP Stack Buffer Overflow
Earth Ammit Disrupts Drone Supply Chains Through Coordinated Multi-Wave Attacks in Taiwan
4 months ago
Trend™ Research discusses the evolving tradecraft of threat actor Earth Ammit, proven by the advanced toolset used in its TIDRONE and VENOM campaigns that targeted the drone supply chain.
Pierre Lee
赛迪顾问发布交换机研究报告,威努特获优质厂商推荐
4 months ago
交换机技术引领车路云一体化系统智能升级!
CVE-2025-47729 | TeleMessage Archiving Backend up to 2025-05-05 wild backdoor
4 months ago
A vulnerability was found in TeleMessage Archiving Backend up to 2025-05-05. It has been rated as problematic. Affected by this issue is some unknown functionality of the component wild. The manipulation leads to backdoor.
This vulnerability is handled as CVE-2025-47729. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
This product is a managed service. It is not possible for users to maintain vulnerability countermeasures themselves.
vuldb.com
CVE-2025-22457 | Ivanti Connect Secure stack-based overflow
4 months ago
A vulnerability was found in Ivanti Connect Secure, Policy Secure and Neurons for ZTA Gateways and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to stack-based buffer overflow.
This vulnerability is handled as CVE-2025-22457. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-6884 | ZyXEL EMG2926 V1.00(AAQT.4)b8 nslookup ping_ip os command injection (EDB-41782 / ID 2026105)
4 months ago
A vulnerability classified as critical has been found in ZyXEL EMG2926 V1.00(AAQT.4)b8. Affected is the function nslookup of the file expert/maintenance/diagnostic/nslookup. The manipulation of the argument ping_ip leads to os command injection.
This vulnerability is traded as CVE-2017-6884. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-23006 | SonicWALL SMA1000 up to 12.4.3-02804 Appliance Management Console deserialization (SNWLID-2025-0002 / Nessus ID 214591)
4 months ago
A vulnerability was found in SonicWALL SMA1000 up to 12.4.3-02804. It has been declared as very critical. This vulnerability affects unknown code of the component Appliance Management Console/Central Management Console. The manipulation leads to deserialization.
This vulnerability was named CVE-2025-23006. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-0282 | Ivanti Connect Secure up to 22.7 stack-based overflow (EDB-52213 / Nessus ID 213570)
4 months ago
A vulnerability was found in Ivanti Connect Secure, Policy Secure and Neurons for ZTA gateways up to 22.7 and classified as critical. This issue affects some unknown processing. The manipulation leads to stack-based buffer overflow.
The identification of this vulnerability is CVE-2025-0282. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41713 | Mitel MiCollab up to 9.8.1.201 NuPoint Unified Messaging path traversal (misa-2024-0029 / Nessus ID 233866)
4 months ago
A vulnerability was found in Mitel MiCollab up to 9.8.1.201. It has been rated as critical. Affected by this issue is some unknown functionality of the component NuPoint Unified Messaging. The manipulation leads to path traversal.
This vulnerability is handled as CVE-2024-41713. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com