Aggregator
CVE-2017-15987 | Fake Magazine Cover Script rate.php Value sql injection (EDB-43072)
CVE-2017-17615 | Facebook Clone Script 1.0 friend-profile.php ID sql injection (ID 145320 / EDB-43280)
CVE-2017-6087 | EyesOfNetwork up to 5.0 ged_functions.php acknowledge/delete/ownDisown selected_events[] code injection (EDB-41746 / BID-97109)
CVE-2017-6088 | EyesOfNetwork up to 5.0 ged_functions.php bp_name/display/search/equipment/type sql injection (EDB-41747 / BID-97084)
CVE-2017-17616 | Event Search Script 1.0 /event-list city sql injection (ID 145306 / EDB-43279)
INC
You must login to view this content
美国将限制留学生和记者签证有效期
CVE-2024-13986 | Nagios XI up to 2024R1.3.1 Config Snapshots Interface unrestricted upload (EUVD-2024-54929)
CVE-2025-25010 | Elastic Kibana up to 9.0.5/9.1.2 reporting_user authorization (EUVD-2025-26116 / WID-SEC-2025-1923)
Feds Seize $6.4M VerifTools Fake-ID Marketplace, but Operators Relaunch on New Domain
Украл миллионы, но передумал: кто стоит за взломом BetterBank
AI 无限上下文(一):如何让 AI 吞下超长视频沉淀知识库【AI 学习必备】
PhpSpreadsheet Library Vulnerability Enables Attackers to Feed Malicious HTML Input
A high-severity Server-Side Request Forgery (SSRF) vulnerability has been identified in the widely used PhpSpreadsheet library, potentially allowing attackers to exploit internal network resources and compromise server security. The vulnerability, tracked as CVE-2025-54370, affects multiple versions of the phpoffice/phpspreadsheet package and carries a CVSS v4.0 score of 8.7. Key Takeaways1. SSRF in PhpSpreadsheet’s Worksheet\Drawing::setPath via […]
The post PhpSpreadsheet Library Vulnerability Enables Attackers to Feed Malicious HTML Input appeared first on Cyber Security News.
Nagios XSS Vulnerability Let Remote Attackers to Execute Arbitrary JavaScript
Nagios XI, a widely-deployed network monitoring solution, has addressed a critical cross-site scripting (XSS) vulnerability in its Graph Explorer feature that could enable remote attackers to execute malicious JavaScript code within users’ browsers. The security flaw was patched in version 2024R2.1, released on August 12, 2025, following responsible disclosure by security researcher Marius Lihet. Key […]
The post Nagios XSS Vulnerability Let Remote Attackers to Execute Arbitrary JavaScript appeared first on Cyber Security News.
New Mac Malware Dubbed ‘JSCoreRunner’ Weaponizing PDF Conversion Site to Deliver Malware
A sophisticated new Mac malware campaign has emerged, targeting users through a deceptive PDF conversion website that conceals a dangerous two-stage payload. The malware, dubbed “JSCoreRunner,” represents a significant evolution in macOS threats, demonstrating how cybercriminals are adapting their techniques to bypass Apple’s security measures while maintaining zero detection rates on major security platforms. The […]
The post New Mac Malware Dubbed ‘JSCoreRunner’ Weaponizing PDF Conversion Site to Deliver Malware appeared first on Cyber Security News.