Aggregator
PerfektBlue Bluetooth flaws impact Mercedes, Volkswagen, Skoda cars
CVE-2025-7401 | Premium Age Verification Restriction Plugin up to 3.0.2 on WordPress remote_tunnel.php path traversal (EUVD-2025-21108)
British Police Bust Four Scattered Spider Suspects in England
The U.K.'s National Crime Agency on Thursday arrested in England four suspected members of the Scattered Spider cybercrime collective, as part of an ongoing investigation into major, disruptive hack attacks in April against major retailers Marks & Spencer, the Co-Op and Harrods.
500 млн экономии на ИИ — и минус 15 000 человек. Copilot знает, как делать бизнес
SecWiki News 2025-07-10 Review
CVE-2025-7436 | Campcodes Online Recruitment Management System 1.0 ajax.php?action=delete_vacancy ID sql injection (EUVD-2025-21102)
CVE-2025-7435 | LiveHelperChat lhc-php-resque Extension up to ee1270b35625f552425e32a6a3061cd54b5085c4 List list queue name cross site scripting (EUVD-2025-21100)
19.39 万起!乐道 L90,蔚来不能输的一场硬仗
Submit #609358: Campcodes Online Recruitment Management System V1.0 SQL Injection [Accepted]
GlobalFoundries 收购 MIPS
ServiceNow Platform Vulnerability Let Attackers Exfiltrate Sensitive Data
A significant vulnerability in ServiceNow’s platform, designated CVE-2025-3648 and dubbed “Count(er) Strike,” enables attackers to exfiltrate sensitive data, including PII, credentials, and financial information. This high-severity vulnerability exploits the record count UI element on list pages through enumeration techniques and query filters, potentially affecting all ServiceNow instances with hundreds of tables at risk. Key Takeaways1. […]
The post ServiceNow Platform Vulnerability Let Attackers Exfiltrate Sensitive Data appeared first on Cyber Security News.
Submit #609068: Live Helper Chat lhc-php-resque extension for Live Helper Chat < 0ce7b4f1193c0ed6c6e31a960fafededf979eef2 Cross Site Scripting [Accepted]
CVE-2025-7434 | Tenda FH451 up to 1.0.0.9 POST Request /goform/addressNat fromAddressNat page stack-based overflow (EUVD-2025-21101)
CVE-2025-53364 | parse-server up to 7.5.2/8.2.1 GraphQL Schema exposure of sensitive system information to an unauthorized control sphere (EUVD-2025-21001)
CVE-2025-6395 | GnuTLS _gnutls_figure_common_ciphersuite null pointer dereference (EUVD-2025-21000)
Apache Tomcat webshell application for RCE
Apache Tomcat webshell application for RCE A webshell application and interactive shell for pentesting Apache Tomcat servers. Features Webshell plugin for Apache Tomcat. Execute system commands via an API with ?action=exec. Download files from the...
The post Apache Tomcat webshell application for RCE appeared first on Penetration Testing Tools.
Submit #609058: Tenda FH451 v1.0.0.9 Stack-based Buffer Overflow [Accepted]
gallia: comprehensive penetration testing toolchain for cars
Gallia Gallia is an extendable pentesting framework with the focus on the automotive domain. The scope of the toolchain is conducting penetration tests from a single ECU up to whole cars, with the main...
The post gallia: comprehensive penetration testing toolchain for cars appeared first on Penetration Testing Tools.