Aggregator
CVE-2017-6088 | EyesOfNetwork up to 5.0 ged_functions.php bp_name/display/search/equipment/type sql injection (EDB-41747 / BID-97084)
CVE-2017-17616 | Event Search Script 1.0 /event-list city sql injection (ID 145306 / EDB-43279)
INC
You must login to view this content
美国将限制留学生和记者签证有效期
CVE-2024-13986 | Nagios XI up to 2024R1.3.1 Config Snapshots Interface unrestricted upload (EUVD-2024-54929)
CVE-2025-25010 | Elastic Kibana up to 9.0.5/9.1.2 reporting_user authorization (EUVD-2025-26116 / WID-SEC-2025-1923)
CVE-2025-58334 | JetBrains IDE Services prior 2025.5.0.1086/ 2025.4.2.2164 authorization (EUVD-2025-26122)
Feds Seize $6.4M VerifTools Fake-ID Marketplace, but Operators Relaunch on New Domain
Украл миллионы, но передумал: кто стоит за взломом BetterBank
AI 无限上下文(一):如何让 AI 吞下超长视频沉淀知识库【AI 学习必备】
PhpSpreadsheet Library Vulnerability Enables Attackers to Feed Malicious HTML Input
A high-severity Server-Side Request Forgery (SSRF) vulnerability has been identified in the widely used PhpSpreadsheet library, potentially allowing attackers to exploit internal network resources and compromise server security. The vulnerability, tracked as CVE-2025-54370, affects multiple versions of the phpoffice/phpspreadsheet package and carries a CVSS v4.0 score of 8.7. Key Takeaways1. SSRF in PhpSpreadsheet’s Worksheet\Drawing::setPath via […]
The post PhpSpreadsheet Library Vulnerability Enables Attackers to Feed Malicious HTML Input appeared first on Cyber Security News.
Nagios XSS Vulnerability Let Remote Attackers to Execute Arbitrary JavaScript
Nagios XI, a widely-deployed network monitoring solution, has addressed a critical cross-site scripting (XSS) vulnerability in its Graph Explorer feature that could enable remote attackers to execute malicious JavaScript code within users’ browsers. The security flaw was patched in version 2024R2.1, released on August 12, 2025, following responsible disclosure by security researcher Marius Lihet. Key […]
The post Nagios XSS Vulnerability Let Remote Attackers to Execute Arbitrary JavaScript appeared first on Cyber Security News.
New Mac Malware Dubbed ‘JSCoreRunner’ Weaponizing PDF Conversion Site to Deliver Malware
A sophisticated new Mac malware campaign has emerged, targeting users through a deceptive PDF conversion website that conceals a dangerous two-stage payload. The malware, dubbed “JSCoreRunner,” represents a significant evolution in macOS threats, demonstrating how cybercriminals are adapting their techniques to bypass Apple’s security measures while maintaining zero detection rates on major security platforms. The […]
The post New Mac Malware Dubbed ‘JSCoreRunner’ Weaponizing PDF Conversion Site to Deliver Malware appeared first on Cyber Security News.
从隐藏参数突破到发现高危的src挖掘记录
基于优化推理的人工智能智能体漏洞注入与转换
CVE-2025-9606 | Portabilis i-Educar up to 2.10 agenda_preferencias.php cod_agenda sql injection
CVE-2025-9607 | Portabilis i-Educar up to 2.10 Tabelas de Arredondamento Page view ID sql injection
CVE-2025-9608 | Portabilis i-Educar up to 2.10 Formula de Cálculo de Média Page view ID sql injection
TransUnion Hack Exposes 4M+ Customers Personal Information
TransUnion, one of the nation’s three major credit reporting agencies, has disclosed a significant data breach that exposed the personal information of more than four million U.S. customers. The company is now alerting affected individuals about the cyber incident, which involved unauthorized access to data stored on a third-party application. On July 28, 2025, TransUnion […]
The post TransUnion Hack Exposes 4M+ Customers Personal Information appeared first on Cyber Security News.