Aggregator
GITEX GLOBAL 2025
1 week 1 day hence
Red, Blue, Purple in Offensive Security
2 hours 20 minutes hence
这篇文章探讨了企业中红队(Red Team)、蓝队(Blue Team)和紫队(Purple Team)之间的关系及挑战。作为红队成员,作者指出在公司环境中很难保持纯粹的攻击性思维;红队的工作往往更偏向防御和协作( Purple 或 Indigo)。作者强调持续学习和创造机会进行真正“红色”工作的必要性,并认为只有深入理解 Red 的本质才能实现 Purple 的平衡。
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
1 hour 9 minutes ago
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
SECUROTROP
1 hour 13 minutes ago
You must login to view this content
cohenido
Qilin
2 hours 8 minutes ago
You must login to view this content
cohenido
CVE-2025-3335 | codeprojects Online Restaurant Management System 1.0 category_update.php ID sql injection (EUVD-2025-9953)
4 hours 3 minutes ago
A vulnerability classified as critical was found in codeprojects Online Restaurant Management System 1.0. This vulnerability affects unknown code of the file /admin/category_update.php. Such manipulation of the argument ID leads to sql injection.
This vulnerability is listed as CVE-2025-3335. The attack may be performed from remote. In addition, an exploit is available.
vuldb.com
CVE-2025-3336 | codeprojects Online Restaurant Management System 1.0 /admin/member_save.php last sql injection (EUVD-2025-9955)
4 hours 3 minutes ago
A vulnerability, which was classified as critical, has been found in codeprojects Online Restaurant Management System 1.0. This issue affects some unknown processing of the file /admin/member_save.php. Performing manipulation of the argument last results in sql injection.
This vulnerability is cataloged as CVE-2025-3336. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
Other parameters might be affected as well.
vuldb.com
CVE-2025-20659 | MediaTek MT8863 Modem out-of-bounds (MSV-2768 / MOLY01519028)
4 hours 3 minutes ago
A vulnerability classified as problematic was found in MediaTek MT2735, MT2737, MT6739, MT6761, MT6762, MT6762D, MT6762M, MT6763, MT6765, MT6765T, MT6767, MT6768, MT6769, MT6769K, MT6769S, MT6769T, MT6769Z, MT6771, MT6779, MT6781, MT6783, MT6785, MT6785T, MT6785U, MT6789, MT6813, MT6833, MT6833P, MT6835, MT6835T, MT6853, MT6853T, MT6855, MT6855T, MT6873, MT6875, MT6875T, MT6877, MT6877T, MT6877TT, MT6878, MT6878M, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6895TT, MT6896, MT6897, MT6899, MT6980, MT6980D, MT6983, MT6983T, MT6985, MT6985T, MT6989, MT6989T, MT6990, MT6991, MT8666, MT8667, MT8673, MT8675, MT8676, MT8678, MT8765, MT8766, MT8768, MT8771, MT8781, MT8786, MT8788, MT8788E, MT8791T, MT8796, MT8797, MT8798 and MT8863. This impacts an unknown function of the component Modem. The manipulation results in out-of-bounds read.
This vulnerability is identified as CVE-2025-20659. The attack can be executed remotely. There is not any exploit available.
Applying a patch is advised to resolve this issue.
vuldb.com
CVE-2025-31172 | Huawei HarmonyOS 5.0.0 Kernel Futex insufficient permissions or privileges (EUVD-2025-9956)
4 hours 3 minutes ago
A vulnerability was found in Huawei HarmonyOS 5.0.0. It has been declared as critical. This issue affects some unknown processing of the component Kernel Futex Module. The manipulation results in improper handling of insufficient permissions or privileges.
This vulnerability is reported as CVE-2025-31172. The attack requires a local approach. No exploit exists.
vuldb.com
CVE-2025-20654 | MediaTek MT6890/MT7622/MT7915/MT7916/MT7981/MT7986 WLAN Service out-of-bounds write (MSV-2875 / EUVD-2025-9958)
4 hours 3 minutes ago
A vulnerability marked as critical has been reported in MediaTek MT6890, MT7622, MT7915, MT7916, MT7981 and MT7986. The affected element is an unknown function of the component WLAN Service. Performing manipulation results in out-of-bounds write.
This vulnerability was named CVE-2025-20654. The attack may be initiated remotely. There is no available exploit.
Applying a patch is the recommended action to fix this issue.
vuldb.com
CVE-2025-20661 | MediaTek MT9972 PlayReady TA out-of-bounds (MSV-3185 / EUVD-2025-9959)
4 hours 3 minutes ago
A vulnerability was found in MediaTek MT9972 and classified as critical. This affects an unknown part of the component PlayReady TA. Executing manipulation can lead to out-of-bounds read.
This vulnerability is registered as CVE-2025-20661. The attack needs to be launched locally. No exploit is available.
It is advisable to implement a patch to correct this issue.
vuldb.com
CVE-2025-31173 | Huawei HarmonyOS 5.0.0 Kernel Futex insufficient permissions or privileges (EUVD-2025-9957)
4 hours 3 minutes ago
A vulnerability was found in Huawei HarmonyOS 5.0.0. It has been rated as critical. Impacted is an unknown function of the component Kernel Futex Module. This manipulation causes improper handling of insufficient permissions or privileges.
This vulnerability appears as CVE-2025-31173. The attack requires local access. There is no available exploit.
vuldb.com
CVE-2024-58126 | Huawei HarmonyOS/EMUI Security Verification authentication spoofing (EUVD-2025-9960)
4 hours 3 minutes ago
A vulnerability classified as critical has been found in Huawei HarmonyOS and EMUI. Affected by this vulnerability is an unknown functionality of the component Security Verification Module. This manipulation causes authentication bypass by spoofing.
The identification of this vulnerability is CVE-2024-58126. The attack can only be executed locally. There is no exploit available.
vuldb.com
CVE-2025-20657 | MediaTek MT6765 Vdec out-of-bounds write (MSV-2609 / ALPS09486425)
4 hours 3 minutes ago
A vulnerability, which was classified as critical, was found in MediaTek MT6765, MT6768, MT6781, MT6789, MT6833, MT6853, MT6877, MT6885, MT8768, MT8771, MT8781, MT8786 and MT8791T. Affected by this vulnerability is an unknown functionality of the component Vdec. Such manipulation leads to out-of-bounds write.
This vulnerability is listed as CVE-2025-20657. The attack must be carried out locally. There is no available exploit.
A patch should be applied to remediate this issue.
vuldb.com
CVE-2024-58125 | Huawei HarmonyOS/EMUI Security Verification authentication spoofing (EUVD-2025-9962)
4 hours 3 minutes ago
A vulnerability described as critical has been identified in Huawei HarmonyOS and EMUI. Affected is an unknown function of the component Security Verification Module. The manipulation results in authentication bypass by spoofing.
This vulnerability was named CVE-2024-58125. The attack needs to be approached locally. There is no available exploit.
vuldb.com
CVE-2024-58109 | Huawei HarmonyOS 5.0.0 Codec buffer overflow (EUVD-2025-9961)
4 hours 3 minutes ago
A vulnerability was found in Huawei HarmonyOS 5.0.0. It has been classified as critical. The affected element is an unknown function of the component Codec Module. This manipulation causes buffer overflow.
This vulnerability is registered as CVE-2024-58109. The attack requires access to the local network. No exploit is available.
vuldb.com
CVE-2024-58110 | Huawei HarmonyOS 5.0.0 Codec buffer overflow (EUVD-2025-9963)
4 hours 3 minutes ago
A vulnerability was found in Huawei HarmonyOS 5.0.0. It has been declared as critical. The impacted element is an unknown function of the component Codec Module. Such manipulation leads to buffer overflow.
This vulnerability is documented as CVE-2024-58110. The attack requires being on the local network. There is not any exploit available.
vuldb.com
CVE-2025-20663 | MediaTek MT7915/MT7916/MT7981/MT7986 WLAN AP Driver uncaught exception (MSV-3031 / EUVD-2025-9965)
4 hours 3 minutes ago
A vulnerability described as problematic has been identified in MediaTek MT7915, MT7916, MT7981 and MT7986. The impacted element is an unknown function of the component WLAN AP Driver. Executing manipulation can lead to uncaught exception.
The identification of this vulnerability is CVE-2025-20663. The attack needs to be done within the local network. There is no exploit available.
It is best practice to apply a patch to resolve this issue.
vuldb.com
CRAC CTF - Cloud and IAM CTF
4 hours 10 minutes ago
Name: CRAC CTF - Cloud and IAM CTF (an CRAC CTFs event.)
Date: Oct. 4, 2025, 8:30 a.m. — 04 Oct. 2025, 11:30 UTC [add to calendar]
Format: Jeopardy
On-line
Location: Delhi, India
Offical URL: https://defhawk.com/battleground/raid/cloud-and-iam-ctf
Rating weight: 0
Event organizers: h4wk
Date: Oct. 4, 2025, 8:30 a.m. — 04 Oct. 2025, 11:30 UTC [add to calendar]
Format: Jeopardy
On-line
Location: Delhi, India
Offical URL: https://defhawk.com/battleground/raid/cloud-and-iam-ctf
Rating weight: 0
Event organizers: h4wk