Aggregator
nxe Claims to be Selling Initial Access to Law Enforcement and Government Email Addresses
4 months 3 weeks ago
nxe Claims to have Selling Initial Access to Law Enforcement and Government Email Addresses
Dark Web Informer - Cyber Threat Intelligence
CVE-2025-0159: Vulnerabilities in the GUI affect IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products
4 months 3 weeks ago
CVE-2025-0159: Vulnerabilities in the GUI affect IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products
Dark Web Informer - Cyber Threat Intelligence
Notorious Malware, Spam Host “Prospero” Moves to Kaspersky Lab
4 months 3 weeks ago
One of the most notorious providers of abuse-friendly "bulletproof" web hosting for cybercriminals has started routing its operations through networks run by the Russian antivirus and security firm Kaspersky Lab, KrebsOnSecurity has learned.
BrianKrebs
Notorious Malware, Spam Host “Prospero” Moves to Kaspersky Lab
4 months 3 weeks ago
One of the most notorious providers of abuse-friendly "bulletproof" web hosting for cybercriminals has started routing its operations through networks run by the Russian antivirus and security firm Kaspersky Lab, KrebsOnSecurity has learned.
BrianKrebs
CVE-2025-1800 | D-Link DAR-7000 3.2 HTTP POST Request sxh_vpnlic.php get_ip_addr_details ethname command injection
4 months 3 weeks ago
A vulnerability has been found in D-Link DAR-7000 3.2 and classified as critical. This vulnerability affects the function get_ip_addr_details of the file /view/vpn/sxh_vpn/sxh_vpnlic.php of the component HTTP POST Request Handler. The manipulation of the argument ethname leads to command injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability was named CVE-2025-1800. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #502971: D-Link Corporation D-Link DAR-7000-20-V3.2 DAR-7000-20-V3.2 Command Injection [Accepted]
4 months 3 weeks ago
Submit #502971 / VDB-298030
Calmc1
CVE-2025-1799 | Zorlan SkyCaiji 2.9 Tool.php previewAction data server-side request forgery
4 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Zorlan SkyCaiji 2.9. This affects the function previewAction of the file vendor/skycaiji/app/admin/controller/Tool.php. The manipulation of the argument data leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2025-1799. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #502919: Niushop Niushop V5 V5 SQL Injection [Duplicate]
4 months 3 weeks ago
Submit #502919 / VDB-254812
BFS-Lab
Submit #502917: Niushop Niushop V5 V5 SQL Injection [Duplicate]
4 months 3 weeks ago
Submit #502917 / VDB-254822
BFS-Lab
Submit #502775: xunrui XunRuiCMS 4.6.3 Deserialization [Duplicate]
4 months 3 weeks ago
Submit #502775 / VDB-295080
fxizenta
CVE-2025-1797 | Hunan Zhonghe Baiyi Information Technology Baiyiyun Asset Management and Operations System up to 20250217 anyUserBoundHouse.php huid sql injection
4 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Hunan Zhonghe Baiyi Information Technology Baiyiyun Asset Management and Operations System up to 20250217. Affected by this issue is some unknown functionality of the file /wuser/anyUserBoundHouse.php. The manipulation of the argument huid leads to sql injection.
This vulnerability is handled as CVE-2025-1797. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #502651: https://github.com/zorlan/skycaiji skycaiji 2.9 RCE [Duplicate]
4 months 3 weeks ago
Submit #502651 / VDB-215099
sheratan
Submit #502650: https://github.com/zorlan/skycaiji skycaiji 2.9 SSRF [Accepted]
4 months 3 weeks ago
Submit #502650 / VDB-298029
sheratan
DEF CON 32 – Inside Dash Cam Custom Protocols And Discovered 0days
4 months 3 weeks ago
Authors/Presenters: Hyo Jin Lee & Hanryeol Park
Our sincere appreciation to DEF CON, and the Authors/Presenters for publishing their erudite DEF CON 32 content. Originating from the conference’s events located at the Las Vegas Convention Center; and via the organizations YouTube channel.
The post DEF CON 32 – Inside Dash Cam Custom Protocols And Discovered 0days appeared first on Security Boulevard.
Marc Handelman
CVE-2025-25429 | TRENDnet TEW-929DRU 1.0.0.10 /addschedule.htm have_same_name r_name cross site scripting
4 months 3 weeks ago
A vulnerability classified as problematic was found in TRENDnet TEW-929DRU 1.0.0.10. Affected by this vulnerability is the function have_same_name of the file /addschedule.htm. The manipulation of the argument r_name leads to cross site scripting.
This vulnerability is known as CVE-2025-25429. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-25431 | TRENDnet TEW-929DRU 1.0.0.10 /captive_portal.htm wifi_data cross site scripting
4 months 3 weeks ago
A vulnerability classified as problematic has been found in TRENDnet TEW-929DRU 1.0.0.10. Affected is an unknown function of the file /captive_portal.htm. The manipulation of the argument wifi_data leads to cross site scripting.
This vulnerability is traded as CVE-2025-25431. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-24318 | Dario Health Dario Application Database and Internet-based Server Infrastructure cookie httponly flag (icsma-25-058-01)
4 months 3 weeks ago
A vulnerability was found in Dario Health Dario Application Database and Internet-based Server Infrastructure. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cookie without 'httponly' flag.
The identification of this vulnerability is CVE-2025-24318. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-25430 | TRENDnet TEW-929DRU 1.0.0.10 /cbi_addcert.htm configname cross site scripting
4 months 3 weeks ago
A vulnerability was found in TRENDnet TEW-929DRU 1.0.0.10. It has been declared as problematic. This vulnerability affects unknown code of the file /cbi_addcert.htm. The manipulation of the argument configname leads to cross site scripting.
This vulnerability was named CVE-2025-25430. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-24316 | Dario Health Dario Application Database and Internet-based Server Infrastructure exposure of sensitive information due to incompatible policies (icsma-25-058-01)
4 months 3 weeks ago
A vulnerability was found in Dario Health Dario Application Database and Internet-based Server Infrastructure. It has been classified as problematic. This affects an unknown part. The manipulation leads to exposure of sensitive information due to incompatible policies.
This vulnerability is uniquely identified as CVE-2025-24316. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com