Aggregator
CVE-2025-61636 | Wikimedia MediaWiki up to 1.39.13/1.43.3/1.44.0 HTMLButtonField.Php cross site scripting (CNNVD-202602-187)
CVE-2025-6594 | Wikimedia MediaWiki up to 1.39.12/1.43.x ApiSandbox.Js cross site scripting
CVE-2025-6596 | Wikimedia Vector up to 1.42.6/1.43.1/1.43.x portlets.Js cross site scripting
CVE-2025-6595 | Wikimedia MultimediaViewer up to 1.39.12/1.42.6/1.43.1/1.43.x cross site scripting
CVE-2025-61637 | Wikimedia MediaWiki up to 1.39.13/1.43.3/1.44.0 mediawiki.Action.Edit.Preview.Js cross site scripting (CNNVD-202602-185)
CVE-2026-1770 | Crafter CMS up to 4.4.x dynamically-managed code resources (EUVD-2026-5112)
CVE-2022-50942 | Inciga Web 2.8.2 icinga.min.js EventListener.handleEvent cross site scripting (EUVD-2022-55948 / Nessus ID 297507)
德国DDR5内存价格停止上涨 20款内存套装1月涨幅0.1% 但高性能版仍在涨价
From UART to Glitching: Master Hardware Hacking with PwnPad’s Modular Learning Lab
PwnPad is an affordable, hands-on Hardware Hacking Learning Platform created by TwelveSec, designed to guide learners through progressively advanced hardware security
The post From UART to Glitching: Master Hardware Hacking with PwnPad’s Modular Learning Lab appeared first on Penetration Testing Tools.
The “Async” Surge: January 2026 Telemetry Reveals a Global Explosion in AsyncRAT Command Nodes
A pronounced escalation in the activity of infrastructure tethered to the AsyncRAT remote access trojan has been meticulously
The post The “Async” Surge: January 2026 Telemetry Reveals a Global Explosion in AsyncRAT Command Nodes appeared first on Penetration Testing Tools.
The “VISTA” Vigilante: South Korea Deploys High-Speed AI to Crush Crypto “Pump and Dump” Scams
Authorities in South Korea and the nation’s preeminent financial institutions have intensified the integration of artificial intelligence to
The post The “VISTA” Vigilante: South Korea Deploys High-Speed AI to Crush Crypto “Pump and Dump” Scams appeared first on Penetration Testing Tools.
CVE-2025-68258 | Linux Kernel up to 6.12.61/6.17.11/6.18.0 kernel/sched/core.c multiq3_attach denial of service (EUVD-2025-203743 / WID-SEC-2025-2868)
CVE-2025-68257 | Linux Kernel up to 6.12.61/6.17.11/6.18.0 IOCTL comedi_fops.c get_valid_routes null pointer dereference (EUVD-2025-203740 / WID-SEC-2025-2868)
CVE-2025-68256 | Linux Kernel up to 6.12.61/6.17.11/6.18.0 rtw_get_ie out-of-bounds (EUVD-2025-203737 / WID-SEC-2025-2868)
CVE-2025-68255 | Linux Kernel up to 6.12.61/6.17.11/6.18.0 OnAssocReq IE Parser memcpy stack-based overflow (EUVD-2025-203742 / Nessus ID 296481)
CVE-2025-68254 | Linux Kernel up to 6.12.61/6.17.11/6.18.0 ESR IE Parser out-of-bounds (EUVD-2025-203746 / WID-SEC-2025-2868)
CVE-2025-68253 | Linux Kernel up to 6.17.5 mm/page_owner.c add_stack_record_to_list stack-based overflow (EUVD-2025-203643 / WID-SEC-2025-2868)
The “Update” Trap: How State-Sponsored Hackers Hijacked Notepad++ Infrastructure for 6 Months
For nearly half a year, the ubiquitous text editor Notepad++ inadvertently disseminated malicious payloads rather than legitimate refinements.
The post The “Update” Trap: How State-Sponsored Hackers Hijacked Notepad++ Infrastructure for 6 Months appeared first on Penetration Testing Tools.