Aggregator
Minifilter实现文件备份
9 months 1 week ago
Minifilter实现文件备份
Keras解析config时动态加载任意模块中的类造成rce分析(cve-2025-1550)
9 months 1 week ago
Keras在解析config时允许动态加载任意模块中的类,导致出现非预期的方法调用,最终造成rce
CookieShop商城代码审计小结
9 months 1 week ago
蛋糕商城JPA版本是一个开源的CMS系统,它主要基于Spring Boot 3.4.0进行开发,采用MariaDB数据库,涉及Jakarta Servlet、JSP、JSTL,同时使用了Java通用代码生成器来生成后台界面,使用方可以按需定制页面并对项目进行二开,总体是一个对使用者很友好的产品
SROP攻击流程
9 months 1 week ago
初步观察srop的利用方式
CVE-2019-6693 | Fortinet FortiOS up to 5.6.10/6.0.6/6.2.0 Configuration Backup hard-coded credentials (FG-IR-19-007 / Nessus ID 209820)
9 months 1 week ago
A vulnerability was found in Fortinet FortiOS up to 5.6.10/6.0.6/6.2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Configuration Backup. The manipulation leads to hard-coded credentials.
This vulnerability is known as CVE-2019-6693. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Google releases Gemini CLI with free Gemini 2.5 Pro
9 months 1 week ago
Google has released Gemini 2.5 Pro-powered Gemini CLI, which allows you to use Gemini inside your terminal, including Windows Terminal. [...]
Mayank Parmar
The Era of Agentic Security with Microsoft Security Copilot
9 months 1 week ago
In the evolving landscape of cyber threats, security teams often find themselves overwhelmed. They are constantly battling an unrelenting barrage of incidents with limited resources. Traditional automation falls short. The dynamic and unpredictable nature of modern attacks keeps threat actors one step ahead of defenders. This is where Microsoft Security Copilot steps in. It’s not..
The post The Era of Agentic Security with Microsoft Security Copilot appeared first on Security Boulevard.
Tom Hollingsworth
Квантовый ИИ: 3 фотона делают то, на что у NVIDIA уходят мегаватты
9 months 1 week ago
Учёные впервые применили выборку бозонов для практической задачи.
Citrix warns of NetScaler vulnerability exploited in DoS attacks
9 months 1 week ago
Citrix is warning that a vulnerability in NetScaler appliances tracked as CVE-2025-6543 is being actively exploited in the wild, causing devices to enter a denial of service condition. [...]
Lawrence Abrams
CVE-2025-48467 | Advantech Wireless Sensing and Equipment A2.01 B00 denial of service (EUVD-2025-18990)
9 months 1 week ago
A vulnerability, which was classified as problematic, was found in Advantech Wireless Sensing and Equipment A2.01 B00. This affects an unknown part. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2025-48467. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2025-48468 | Advantech Wireless Sensing and Equipment A2.01 B00 JTAG injection (EUVD-2025-18989)
9 months 1 week ago
A vulnerability classified as critical has been found in Advantech Wireless Sensing and Equipment A2.01 B00. This affects an unknown part of the component JTAG. The manipulation leads to injection.
This vulnerability is uniquely identified as CVE-2025-48468. It is possible to launch the attack on the physical device. There is no exploit available.
vuldb.com
CVE-2025-6428 | Mozilla Firefox up to 139 on Android URL querystring redirect
9 months 1 week ago
A vulnerability was found in Mozilla Firefox up to 139 on Android and classified as problematic. This issue affects some unknown processing of the component URL Handler. The manipulation of the argument querystring leads to open redirect.
The identification of this vulnerability is CVE-2025-6428. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-6429 | Mozilla Firefox up to 139 Embed Tag escape output (Nessus ID 240336)
9 months 1 week ago
A vulnerability classified as problematic has been found in Mozilla Firefox up to 139. Affected is an unknown function of the component Embed Tag Handler. The manipulation leads to escaping of output.
This vulnerability is traded as CVE-2025-6429. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-6430 | Mozilla Firefox up to 139 HTTP Header Content-Disposition cross site scripting (Nessus ID 240336)
9 months 1 week ago
A vulnerability was found in Mozilla Firefox up to 139. It has been classified as problematic. Affected is an unknown function of the component HTTP Header Handler. The manipulation of the argument Content-Disposition leads to cross site scripting.
This vulnerability is traded as CVE-2025-6430. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-6533 | xxyopen/201206030 novel-plus up to 5.1.3 CATCHA LoginController.java ajaxLogin authentication replay (EUVD-2025-18961)
9 months 1 week ago
A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus up to 5.1.3. Affected by this issue is the function ajaxLogin of the file novel-admin/src/main/java/com/java2nb/system/controller/LoginController.java of the component CATCHA Handler. The manipulation leads to authentication bypass by capture-replay.
This vulnerability is handled as CVE-2025-6533. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-5446 | Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 RP_checkCredentialsByBBS pwd os command injection
9 months 1 week ago
A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been classified as critical. This affects the function RP_checkCredentialsByBBS of the file /goform/RP_checkCredentialsByBBS. The manipulation of the argument pwd leads to os command injection.
This vulnerability is uniquely identified as CVE-2025-5446. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-48827 | vBulletin up to 5.7.5/6.0.3 api.php?method=protectedMethod improper protection of alternate path
9 months 1 week ago
A vulnerability, which was classified as critical, was found in vBulletin up to 5.7.5/6.0.3. Affected is an unknown function of the file /api.php?method=protectedMethod. The manipulation leads to improper protection of alternate path.
This vulnerability is traded as CVE-2025-48827. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6608 | SourceCodester Best Salon Management System 1.0 /panel/edit-services.php editid sql injection (EUVD-2025-19100)
9 months 1 week ago
A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /panel/edit-services.php. The manipulation of the argument editid leads to sql injection.
This vulnerability is known as CVE-2025-6608. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6611 | code-projects Inventory Management System 1.0 createBrand.php brandStatus sql injection (EUVD-2025-19110)
9 months 1 week ago
A vulnerability was found in code-projects Inventory Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /php_action/createBrand.php. The manipulation of the argument brandStatus leads to sql injection.
This vulnerability was named CVE-2025-6611. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com