Aggregator
Microsoft: Some devices offered Windows 11 upgrades despite Intune blocks
5 months ago
Microsoft is working to fix an ongoing issue causing some users' Windows devices to be offered Windows 11 upgrades despite Intune policies preventing them. [...]
Sergiu Gatlan
Мод на «ходить сквозь стены» в Roblox? Теперь вирус ходит сквозь ваш телефон
5 months ago
Вирусы под видом игр атакуют Android через Telegram.
Product Walkthrough: A Look Inside Wing Security's Layered SaaS Identity Defense
5 months ago
Intro: Why hack in when you can log in?
SaaS applications are the backbone of modern organizations, powering productivity and operational efficiency. But every new app introduces critical security risks through app integrations and multiple users, creating easy access points for threat actors. As a result, SaaS breaches have increased, and according to a May 2024 XM Cyber report, identity and
The Hacker News
Web3 安全入门避坑指南|剪贴板安全
5 months ago
本期将围绕剪贴板安全展开,包括它的原理、攻击方式,以及防范建议。
Web3 安全入门避坑指南|剪贴板安全
5 months ago
本期将围绕剪贴板安全展开,包括它的原理、攻击方式,以及防范建议。
CVE-2025-2314 | User Profile Builder Plugin up to 3.13.5/3.13.6/3.13.7 on WordPress Shortcode cross site scripting
5 months ago
A vulnerability, which was classified as problematic, was found in User Profile Builder Plugin up to 3.13.5/3.13.6/3.13.7 on WordPress. Affected is an unknown function of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-2314. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-13452 | Supsystic Contact Form Plugin up to 1.7.29 on WordPress Setting saveAsCopy cross-site request forgery
5 months ago
A vulnerability has been found in Supsystic Contact Form Plugin up to 1.7.29 on WordPress and classified as problematic. Affected by this vulnerability is the function saveAsCopy of the component Setting Handler. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2024-13452. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-3247 | Contact Form 7 Plugin up to 6.0.5 on WordPress Order wpcf7_stripe_skip_spam_check behavioral workflow
5 months ago
A vulnerability has been found in Contact Form 7 Plugin up to 6.0.5 on WordPress and classified as critical. Affected by this vulnerability is the function wpcf7_stripe_skip_spam_check of the component Order Handler. The manipulation leads to enforcement of behavioral workflow.
This vulnerability is known as CVE-2025-3247. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-3495 | Delta Electronics COMMGR Session ID weak prng (icsa-25-105-07)
5 months ago
A vulnerability classified as problematic has been found in Delta Electronics COMMGR. This affects an unknown part of the component Session ID Handler. The manipulation leads to cryptographically weak prng.
This vulnerability is uniquely identified as CVE-2025-3495. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-3663 | TOTOLINK A3700R 9.1.2u.5822_B20200513 Password /cgi-bin/cstecgi.cgi setWiFiEasyCfg/setWiFiEasyGuestCfg access control
5 months ago
A vulnerability, which was classified as critical, has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513. This issue affects the function setWiFiEasyCfg/setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi of the component Password Handler. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2025-3663. The attack may be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-3664 | TOTOLINK A3700R 9.1.2u.5822_B20200513 /cgi-bin/cstecgi.cgi setWiFiEasyGuestCfg access control
5 months ago
A vulnerability, which was classified as critical, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2025-3664. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-3665 | TOTOLINK A3700R 9.1.2u.5822_B20200513 /cgi-bin/cstecgi.cgi setSmartQosCfg access control
5 months ago
A vulnerability has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this vulnerability is the function setSmartQosCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2025-3665. The attack can be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-3666 | TOTOLINK A3700R 9.1.2u.5822_B20200513 /cgi-bin/cstecgi.cgi setDdnsCfg access control
5 months ago
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this issue is the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2025-3666. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-3667 | TOTOLINK A3700R 9.1.2u.5822_B20200513 /cgi-bin/cstecgi.cgi setUPnPCfg access control
5 months ago
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been classified as critical. This affects the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2025-3667. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-3668 | TOTOLINK A3700R 9.1.2u.5822_B20200513 /cgi-bin/cstecgi.cgi setScheduleCfg access control
5 months ago
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. This vulnerability affects the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls.
This vulnerability was named CVE-2025-3668. The attack can be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-3674 | TOTOLINK A3700R 9.1.2u.5822_B20200513 /cgi-bin/cstecgi.cgi setUrlFilterRules access control
5 months ago
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. Affected by this vulnerability is the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2025-3674. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-3675 | TOTOLINK A3700R 9.1.2u.5822_B20200513 /cgi-bin/cstecgi.cgi setL2tpServerCfg access control
5 months ago
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been rated as critical. Affected by this issue is the function setL2tpServerCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2025-3675. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-24859:Apache Roller 严重漏洞致密码变更无法抵御非法访问
5 months ago
安全客
评论 | 对“人肉开盒”说“不”
5 months ago
近年来,“人肉开盒”这一网络毒瘤持续蔓延,引发社会广泛关注。所谓“人肉开盒”,即通过非法手段获取并公开他人隐私信息,将个人真实姓名、身份证号、住址、工作单位等敏感数据暴露于网络,甚至煽动网民对受害者进行辱骂、骚扰和威胁。