Aggregator
聚焦主论坛|“安芯守护 智启未来”——2025年 · 安全守护者峰会
2 months ago
开放融合、AI赋能、智慧运维
聚焦主论坛|“安芯守护 智启未来”——2025年 · 安全守护者峰会
2 months ago
当前环境出现异常,需完成验证后才能继续访问。
How to Actually Read Weather Radar (Like a Developer)
2 months ago
文章解释了如何解读雷达图,揭示其显示降雨以外的因素如鸟类和尘埃,并讨论了数据延迟、运动分析和噪声过滤的重要性。还提供了获取可靠雷达数据的资源。
DeviceCodePhishing: A New Automated Tool Bypasses MFA & FIDO for Azure Entra Users
2 months ago
DeviceCodePhishing This is a novel technique that leverages the well-known Device Code phishing approach. It dynamically initiates the flow as soon as the victim opens the phishing link and instantly redirects them to the...
The post DeviceCodePhishing: A New Automated Tool Bypasses MFA & FIDO for Azure Entra Users appeared first on Penetration Testing Tools.
ddos
美国网络司令部2026财年拟强化联合网络作战架构的集成和创新
2 months ago
美国网络司令部拟加强JCWA的内部集成和外部创新引入
美国网络司令部2026财年拟强化联合网络作战架构的集成和创新
2 months ago
当前环境出现异常,需完成验证后方可继续访问。
Manus 清空国内多平台账号,北京办公区目前仅剩十余人在岗;Meta 离职大牛千字怒揭「黑幕」;小米王腾将出演短剧|极客早知道
2 months ago
亚马逊加码 AI 竞赛,拟向 Anthropic 增投数十亿美元抗衡谷歌;
马斯克否认 xAI 以 2000 亿美元估值融资:我们资金充足;
二审维持原判,特斯拉「车顶维权」事件女一号被判道歉并赔偿
Manus 清空国内多平台账号,北京办公区目前仅剩十余人在岗;Meta 离职大牛千字怒揭「黑幕」;小米王腾将出演短剧|极客早知道
2 months ago
当前环境出现异常,需完成验证后方可继续访问。
INC
2 months ago
You must login to view this content
cohenido
MSSqlPwner: An advanced and versatile pentesting tool designed to seamlessly interact and pwn MSSQL servers
2 months ago
MSSqlPwner: An advanced and versatile pentesting tool designed to seamlessly interact and pwn MSSQL servers
Dark Web Informer - Cyber Threat Intelligence
麦当劳泄露求职者数据,新漏洞威胁大众等汽车品牌安全|一周特辑
2 months ago
点击查看更多本周网络安全大事件。
CVE-2019-6981 | Synacor Zimbra Collaboration Suite up to 8.7.x/8.8.11 Feed server-side request forgery (Nessus ID 241987)
2 months ago
A vulnerability was found in Synacor Zimbra Collaboration Suite up to 8.7.x/8.8.11. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Feed. The manipulation leads to server-side request forgery.
This vulnerability is known as CVE-2019-6981. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2019-9621 | Synacor Zimbra Collaboration ProxyServlet server-side request forgery (EDB-46693 / Nessus ID 241987)
2 months ago
A vulnerability classified as critical was found in Synacor Zimbra Collaboration up to 8.6 Patch 12/8.7.11 Patch 9/8.8.10 Patch 6/8.8.11 Patch 2. Affected by this vulnerability is an unknown functionality of the component ProxyServlet. The manipulation leads to server-side request forgery.
This vulnerability is known as CVE-2019-9621. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-3083 | MongoDB Server up to 5.0.30/6.0.19/7.0.15 Wire Protocol Message uncaught exception (Nessus ID 241991)
2 months ago
A vulnerability was found in MongoDB Server up to 5.0.30/6.0.19/7.0.15. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Wire Protocol Message Handler. The manipulation leads to uncaught exception.
This vulnerability is known as CVE-2025-3083. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-41190 | OCI Distribution Spec up to 1.0.0 Content-Type Header mediaType type confusion (GHSA-mc8v-mgrf-8f4m / Nessus ID 241992)
2 months ago
A vulnerability classified as problematic has been found in OCI Distribution Spec up to 1.0.0. This affects an unknown part of the component Content-Type Header Handler. The manipulation of the argument mediaType leads to type confusion.
This vulnerability is uniquely identified as CVE-2021-41190. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2018-1000519 | aio-libs aiohttp-session Session session fixiation (ID 272)
2 months ago
A vulnerability, which was classified as critical, has been found in aio-libs aiohttp-session. Affected by this issue is some unknown functionality of the component Session Handler. The manipulation leads to session fixiation.
This vulnerability is handled as CVE-2018-1000519. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-41842 | Fortinet FortiManager/FortiAnalyzer/FortiPortal Command Argument format string (FG-IR-23-304)
2 months ago
A vulnerability was found in Fortinet FortiManager, FortiAnalyzer and FortiPortal. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Command Argument Handler. The manipulation leads to format string.
This vulnerability is known as CVE-2023-41842. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-1529 | CMS Made Simple 2.2.14 /admin/adduser.php cross site scripting
2 months ago
A vulnerability was found in CMS Made Simple 2.2.14. It has been rated as problematic. This issue affects some unknown processing of the file /admin/adduser.php. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-1529. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-7810 | SourceCodester Online Graduate Tracer System 1.0 view_itprofile.php ID sql injection
2 months ago
A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /tracking/admin/view_itprofile.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is handled as CVE-2024-7810. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com