Aggregator
CVE-2023-54327 | Tinycontrol LAN Controller up to 1.58a API /stm.cgi authorization (Exploit 51732 / EDB-51732)
CVE-2024-58337 | Akuvox Smart Doorphone/Smart Intercom API Setting authorization (ID 182870)
CVE-2025-15390 | PHPGurukul Small CRM 4.0 /admin/edit-user.php authorization
CVE-2025-15394 | iCMS up to 8.0.0 POST Parameter ConfigAdmincp.php save config code injection (EUVD-2025-206086)
CVE-2025-34469 | Cowrie up to 2.8.x Outbound Requests server-side request forgery (EUVD-2025-204642)
CVE-2026-0565 | code-projects Content Management System 1.0 /admin/delete.php del sql injection (EUVD-2026-0697)
CVE-2025-15451 | xnx3 wangmarket up to 4.9 System Variables Page variableSave.do Description cross site scripting
CVE-2025-15442 | CRMEB up to 5.6.1 product_list cate_id sql injection (EUVD-2026-0776 / CNNVD-202601-803)
CVE-2025-15405 | PHPEMS up to 11.0 cross-site request forgery (EUVD-2026-0017)
The Olympic Ultimatum: Cloudflare Threatens Italy Exit Over €14M Fine
Matthew Prince, the Chief Executive of Cloudflare, has issued a formidable ultimatum to terminate the corporation’s operations in
The post The Olympic Ultimatum: Cloudflare Threatens Italy Exit Over €14M Fine appeared first on Penetration Testing Tools.
CVE-2021-39275 | Apache HTTP Server up to 2.4.48 ap_escape_quotes buffer overflow (Nessus ID 282589)
CVE-2021-34798 | Oracle HTTP Server 12.2.1.4.0 SSL Module denial of service (Nessus ID 282589)
CVE-2021-34798 | Apache HTTP Server up to 2.4.48 null pointer dereference (Nessus ID 282589)
The Invisible Insider: How North Korean Operatives Are Infiltrating Your Remote Teams
For years, the concept of the “insider threat” was synonymous with the disgruntled employee or the inadvertent contractor.
The post The Invisible Insider: How North Korean Operatives Are Infiltrating Your Remote Teams appeared first on Penetration Testing Tools.
成果分享 | 智能体漏洞检测 [ASE'25, Security'25/26, BlackHat EU]
Armenia Under Siege: Hacker Claims Sale of 8 Million Government Records
Disclosures regarding the illicit sale of a database purportedly linked to Armenia’s state postal and notification services have
The post Armenia Under Siege: Hacker Claims Sale of 8 Million Government Records appeared first on Penetration Testing Tools.
Digital Eclipse: Iran Implements “Whitelist” Web as Death Toll Mounts
For the fourth consecutive day, Iran remains almost entirely severed from the global digital landscape. Domestic authorities persist
The post Digital Eclipse: Iran Implements “Whitelist” Web as Death Toll Mounts appeared first on Penetration Testing Tools.
900GB Under Siege: Everest Collective Claims Massive Nissan Data Heist
The Everest collective has asserted responsibility for a cyber incursion against the Japanese automotive titan Nissan Motor Co.,
The post 900GB Under Siege: Everest Collective Claims Massive Nissan Data Heist appeared first on Penetration Testing Tools.
The Ghost Window: Trellix Warns of “Perfect” Facebook Phishing Traps
Adversaries have intensified their offensives against Facebook users by deploying one of the most inconspicuous and treacherous phishing
The post The Ghost Window: Trellix Warns of “Perfect” Facebook Phishing Traps appeared first on Penetration Testing Tools.