Aggregator
CVE-2025-7435 | LiveHelperChat lhc-php-resque Extension up to ee1270b35625f552425e32a6a3061cd54b5085c4 List list queue name cross site scripting (EUVD-2025-21100)
19.39 万起!乐道 L90,蔚来不能输的一场硬仗
Submit #609358: Campcodes Online Recruitment Management System V1.0 SQL Injection [Accepted]
GlobalFoundries 收购 MIPS
ServiceNow Platform Vulnerability Let Attackers Exfiltrate Sensitive Data
A significant vulnerability in ServiceNow’s platform, designated CVE-2025-3648 and dubbed “Count(er) Strike,” enables attackers to exfiltrate sensitive data, including PII, credentials, and financial information. This high-severity vulnerability exploits the record count UI element on list pages through enumeration techniques and query filters, potentially affecting all ServiceNow instances with hundreds of tables at risk. Key Takeaways1. […]
The post ServiceNow Platform Vulnerability Let Attackers Exfiltrate Sensitive Data appeared first on Cyber Security News.
Submit #609068: Live Helper Chat lhc-php-resque extension for Live Helper Chat < 0ce7b4f1193c0ed6c6e31a960fafededf979eef2 Cross Site Scripting [Accepted]
CVE-2025-7434 | Tenda FH451 up to 1.0.0.9 POST Request /goform/addressNat fromAddressNat page stack-based overflow (EUVD-2025-21101)
CVE-2025-53364 | parse-server up to 7.5.2/8.2.1 GraphQL Schema exposure of sensitive system information to an unauthorized control sphere (EUVD-2025-21001)
CVE-2025-6395 | GnuTLS _gnutls_figure_common_ciphersuite null pointer dereference (EUVD-2025-21000)
Apache Tomcat webshell application for RCE
Apache Tomcat webshell application for RCE A webshell application and interactive shell for pentesting Apache Tomcat servers. Features Webshell plugin for Apache Tomcat. Execute system commands via an API with ?action=exec. Download files from the...
The post Apache Tomcat webshell application for RCE appeared first on Penetration Testing Tools.
Submit #609058: Tenda FH451 v1.0.0.9 Stack-based Buffer Overflow [Accepted]
gallia: comprehensive penetration testing toolchain for cars
Gallia Gallia is an extendable pentesting framework with the focus on the automotive domain. The scope of the toolchain is conducting penetration tests from a single ECU up to whole cars, with the main...
The post gallia: comprehensive penetration testing toolchain for cars appeared first on Penetration Testing Tools.