Aggregator
CNCERT:关于Foxmail邮件客户端存在跨站脚本攻击漏洞的安全公告
4 months 3 weeks ago
基因信息出境,是否既要“安全审查”,又要“安全评估”?
4 months 3 weeks ago
解析一定数量基因资源出境是否需同时满足“安全审查”与“安全评估”的法律与逻辑关系
固件安全的隐忧:UEFI漏洞的持续威胁与修复之路
4 months 3 weeks ago
UEFI固件漏洞:为何它们反复出现,又该如何守护我们的设备安全?
固件安全的隐忧:UEFI漏洞的持续威胁与修复之路
4 months 3 weeks ago
UEFI固件漏洞:为何它们反复出现,又该如何守护我们的设备安全?
继续反制,中国对美所有商品加征 125% 关税;小米汽车回应 SU7 湛江事故;GPT-4 将退役 | 极客早知道
4 months 3 weeks ago
传字节跳动正开发 AI 智能眼镜;消息称 Shein 伦敦上市获英国 FCA 批准;特斯拉中国停止提供 Model X 和 Model S 新车订购选项
Phobos勒索病毒样本分析
4 months 3 weeks ago
Phobos勒索病毒样本分析
英伟达漏洞补丁不完整致攻击者可窃取AI模型数据
4 months 3 weeks ago
英伟达AI容器漏洞补丁不彻底,攻击者可窃取敏感模型数据!
EDRaser: powerful tool for remotely deleting access logs, Windows event logs, databases
4 months 3 weeks ago
EDRaser EDRaser is a powerful tool for remotely deleting access logs, Windows event logs, databases, and other files on remote machines. It offers two modes of operation: automated and manual. Automated Mode In automated...
The post EDRaser: powerful tool for remotely deleting access logs, Windows event logs, databases appeared first on Penetration Testing Tools.
ddos
dot: The Deepfake Offensive Toolkit
4 months 3 weeks ago
Deepfake Offensive Toolkit dot (aka Deepfake Offensive Toolkit) makes real-time, controllable deepfakes ready for virtual camera injection. dot is created for performing penetration testing against e.g. identity verification and video conferencing systems, for the use by...
The post dot: The Deepfake Offensive Toolkit appeared first on Penetration Testing Tools.
ddos
美国西雅图港泄漏员工数据,澳大利亚基金会遭撞库攻击|一周特辑
4 months 3 weeks ago
点击查看本周全球网络安全大事件。
蓝宝石狼组织升级攻击工具包,利用新型紫水晶窃密软件瞄准能源企业
4 months 3 weeks ago
蓝宝石狼升级紫水晶窃密软件,瞄准能源企业窃取敏感数据。
Daily Dose of Dark Web Informer - 11th of April 2025
4 months 3 weeks ago
This daily article is intended to make it easier for those who want to stay updated with my regular Dark Web Informer and X/Twitter posts.
Dark Web Informer - Cyber Threat Intelligence
CVE-2025-30281
4 months 3 weeks ago
Currently trending CVE - Hype Score: 1 - ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. ...
CVE-2025-24447
4 months 3 weeks ago
Currently trending CVE - Hype Score: 1 - ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must ...
CVE-2025-24446
4 months 3 weeks ago
Currently trending CVE - Hype Score: 1 - ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a ...
CVE-2023-45673 | laurent22 joplin up to 2.13.2 code injection (GHSA-g8qx-5vcm-3x59)
4 months 3 weeks ago
A vulnerability classified as critical has been found in laurent22 joplin up to 2.13.2. This affects an unknown part. The manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2023-45673. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-34452 | CMSimple_XH 1.7.6 SVG Document cross site scripting
4 months 3 weeks ago
A vulnerability classified as problematic was found in CMSimple_XH 1.7.6. This vulnerability affects unknown code of the component SVG Document Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-34452. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-37231 | Salon Booking System Plugin up to 9.9 on WordPress path traversal
4 months 3 weeks ago
A vulnerability was found in Salon Booking System Plugin up to 9.9 on WordPress. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to path traversal.
The identification of this vulnerability is CVE-2024-37231. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-39315 | Pomerium up to 0.26.0 OAuth2 Access Token /.pomerium insertion of sensitive information into sent data (GHSA-rrqr-7w59-637v)
4 months 3 weeks ago
A vulnerability was found in Pomerium up to 0.26.0. It has been rated as problematic. This issue affects some unknown processing of the file /.pomerium of the component OAuth2 Access Token Handler. The manipulation leads to insertion of sensitive information into sent data.
The identification of this vulnerability is CVE-2024-39315. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com