Aggregator
CVE-2025-48866 | OWASP ModSecurity up to 2.9.9 sanitiseArg/sanitizeArg excessive platform resource consumption within a loop
CVE-2025-48940 | MyBB up to 1.8.38 path traversal
Cryptojacking Campaign Exploits DevOps APIs Using Off-the-Shelf Tools from GitHub
IBM security advisory (AV25-307)
几个有趣而真诚的灵魂
SecWiki News 2025-06-02 Review
更多最新文章,请访问SecWiki
CVE-2025-44115 | Cotonti Siena 0.9.25 admin.php?m=config&n=edit&o=core&p=title Title cross site scripting (EUVD-2025-16662)
Qualcomm fixed three zero-days exploited in limited, targeted attacks
Australia Begins New Ransomware Payment Disclosure Rules
CVE-2025-45542 | CloudClassroom-PHP-Project 1.0 registrationform pass sql injection (EUVD-2025-16669)
Trump budget proposal would slash more than 1,000 CISA jobs
The fate of the fiscal 2026 budget blueprint, which includes a $495 million reduction for the agency, is uncertain.
The post Trump budget proposal would slash more than 1,000 CISA jobs appeared first on CyberScoop.
Critical Bugs Could Spark Takeover of Widely Used Fire Safety OT/ICS Platform
Vulnerabilities in Preinstalled Android Apps Expose PIN Codes and Allow Command Injection
Significant vulnerabilities were uncovered in pre-installed applications on Ulefone and Krüger&Matz Android smartphones that expose users to significant risks, including unauthorized factory resets, PIN code theft, and malicious command injection. These flaws, published on May 30, 2025, demonstrate how Improper Export of Android Application Components (CWE-926) can compromise device security at the system level. Factory […]
The post Vulnerabilities in Preinstalled Android Apps Expose PIN Codes and Allow Command Injection appeared first on Cyber Security News.