Aggregator
Apple issues urgent lock screen warnings for unpatched iPhones and iPads
3 weeks 6 days ago
Apple is alerting users of outdated iPhones and iPads via lock screen warnings about active web-based exploits, urging immediate software updates. Apple is sending lock screen alerts to users running outdated iOS and iPadOS versions, warning of active web-based attacks targeting their devices. The notifications urge users to install critical updates to stay protected, highlighting […]
Pierluigi Paganini
Apple issues urgent lock screen warnings for unpatched iPhones and iPads
3 weeks 6 days ago
好的,我现在需要帮用户总结这篇文章的内容,控制在100字以内。首先,我得通读整篇文章,抓住主要信息。
文章讲的是苹果公司向使用旧版iOS和iPadOS的用户发送锁屏警告,提醒他们存在基于网络的攻击。这些攻击利用了未修补的漏洞,可能窃取敏感数据。苹果建议用户立即更新软件,并提到一些具体的漏洞套件,比如Coruna和DarkSword。
接下来,我需要将这些信息浓缩到100字以内。要确保涵盖苹果发出警告、针对旧设备、存在网络攻击、建议更新软件以及提到的漏洞套件名称。
可能会这样组织句子:苹果向旧设备用户发送锁屏警告,提醒存在基于网络的攻击和漏洞套件Coruna及DarkSword的风险,建议立即更新软件以保护数据安全。
检查一下字数,确保不超过限制,并且信息准确无误。
Apple向使用旧版iOS和iPadOS的用户发送锁屏警告,提醒存在基于网络的攻击和漏洞套件Coruna及DarkSword的风险,建议立即更新软件以保护数据安全。
一张卫星图片,终结了一场战争的叙事谎言——GEOINT与商业卫星的情报革命
3 weeks 6 days ago
关注本号,每天洞见真实情报世界。2025 年 5 月 10 日,印度空军完成了它有史以来最深入的对巴空袭。
CVE-2019-25643 | Endonesia eNdonesia Portal 8.7 banners.php bid sql injection (Exploit 46559 / EUVD-2019-20026)
3 weeks 6 days ago
A vulnerability was found in Endonesia eNdonesia Portal 8.7 and classified as critical. This affects an unknown part of the file banners.php. Such manipulation of the argument bid leads to sql injection.
This vulnerability is documented as CVE-2019-25643. The attack can be executed remotely. Additionally, an exploit exists.
vuldb.com
CVE-2019-25639 | Matri4Web Matrimony Website Script M-Plus POST Parameter simplesearch_results.php txtGender/religion/Fage/cboCountry sql injection (Exploit 46591 / EDB-46591)
3 weeks 6 days ago
A vulnerability was found in Matri4Web Matrimony Website Script M-Plus. It has been classified as critical. This vulnerability affects unknown code of the file simplesearch_results.php of the component POST Parameter Handler. Performing a manipulation of the argument txtGender/religion/Fage/cboCountry results in sql injection.
This vulnerability is reported as CVE-2019-25639. The attack is possible to be carried out remotely. Moreover, an exploit is present.
vuldb.com
CVE-2019-25638 | Meeplace Business Review Script addclick.php ID sql injection (Exploit 46592 / EDB-46592)
3 weeks 6 days ago
A vulnerability was found in Meeplace Business Review Script. It has been declared as critical. This issue affects some unknown processing of the file addclick.php. Executing a manipulation of the argument ID can lead to sql injection.
This vulnerability appears as CVE-2019-25638. The attack may be performed from remote. In addition, an exploit is available.
vuldb.com
CVE-2019-25642 | Bootstrapy CMS Parameter forum-thread.php thread_id sql injection (Exploit 46590 / EUVD-2019-20024)
3 weeks 6 days ago
A vulnerability was found in Bootstrapy CMS. It has been rated as critical. Impacted is an unknown function of the file forum-thread.php of the component Parameter Handler. The manipulation of the argument thread_id leads to sql injection.
This vulnerability is traded as CVE-2019-25642. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2019-25641 | Netartmedia Vlog System Parameter index.php forgotten_password email sql injection (Exploit 46583 / EUVD-2019-20022)
3 weeks 6 days ago
A vulnerability categorized as critical has been discovered in Netartmedia Vlog System. The affected element is the function forgotten_password of the file index.php of the component Parameter Handler. The manipulation of the argument email results in sql injection.
This vulnerability is known as CVE-2019-25641. It is possible to launch the attack remotely. Furthermore, an exploit is available.
vuldb.com
CVE-2019-25636 | Zeeways Jobsite CMS news_details.php ID sql injection (Exploit 46602 / EDB-46602)
3 weeks 6 days ago
A vulnerability labeled as critical has been found in Zeeways Jobsite CMS. This affects an unknown function of the file news_details.php. Such manipulation of the argument ID leads to sql injection.
This vulnerability is uniquely identified as CVE-2019-25636. The attack can be launched remotely. Moreover, an exploit is present.
vuldb.com
CVE-2019-25640 | Inoutscripts Inout Article Base CMS GET Request p/u sql injection (Exploit 46593 / EUVD-2019-20020)
3 weeks 6 days ago
A vulnerability marked as critical has been reported in Inoutscripts Inout Article Base CMS. This impacts an unknown function of the component GET Request Handler. Performing a manipulation of the argument p/u results in sql injection.
This vulnerability was named CVE-2019-25640. The attack may be initiated remotely. In addition, an exploit is available.
vuldb.com
CVE-2019-25635 | Zeeways Matrimony CMS Parameter up_cast/s_mother/s_religion sql injection (Exploit 46603 / EDB-46603)
3 weeks 6 days ago
A vulnerability was found in Zeeways Matrimony CMS. It has been rated as critical. This affects an unknown function of the component Parameter Handler. This manipulation of the argument up_cast/s_mother/s_religion causes sql injection.
This vulnerability appears as CVE-2019-25635. The attack may be initiated remotely. In addition, an exploit is available.
vuldb.com
CVE-2019-25637 | Freshsoftware X-NetStat Pro up to 5.63 out-of-bounds write (Exploit 46596 / EDB-46596)
3 weeks 6 days ago
A vulnerability categorized as critical has been discovered in Freshsoftware X-NetStat Pro up to 5.63. This impacts an unknown function. Such manipulation leads to out-of-bounds write.
This vulnerability is traded as CVE-2019-25637. An attack has to be approached locally. Furthermore, there is an exploit available.
vuldb.com
CVE-2019-25644 | WinMPG Video Convert 9.3.5 Registration out-of-bounds write (Exploit 46553 / EUVD-2019-20028)
3 weeks 6 days ago
A vulnerability marked as critical has been reported in WinMPG Video Convert 9.3.5. Affected by this issue is some unknown functionality of the component Registration Handler. The manipulation leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2019-25644. Local access is required to approach this attack. Moreover, an exploit is present.
vuldb.com
CVE-2019-25645 | WinAVI iPod 3GP MP4 PSP Converter 4.4.2 AVI File Parser denial of service (Exploit 46554 / EUVD-2019-20029)
3 weeks 6 days ago
A vulnerability described as problematic has been identified in WinAVI iPod 3GP MP4 PSP Converter 4.4.2. This affects an unknown part of the component AVI File Parser. The manipulation results in denial of service.
This vulnerability was named CVE-2019-25645. The attack needs to be approached locally. In addition, an exploit is available.
vuldb.com
CVE-2025-64998 | Checkmk up to 2.2.0/2.3.0p44/2.4.0p22 Session Cookie insufficiently protected credentials (Nessus ID 304142)
3 weeks 6 days ago
A vulnerability classified as problematic was found in Checkmk up to 2.2.0/2.3.0p44/2.4.0p22. Affected by this issue is some unknown functionality of the component Session Cookie Handler. The manipulation results in insufficiently protected credentials.
This vulnerability is identified as CVE-2025-64998. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
I built a CTF the way I wanted to play one... Maybe it lands for some of you here too.
3 weeks 6 days ago
嗯,用户让我帮忙总结一篇文章的内容,控制在一百个字以内,而且不需要特定的开头。我先看看这篇文章讲的是什么。
文章提到一个互动式游戏,看起来像是解谜游戏,但更偏向于调查和情境。游戏环境是终端式的,没有太多指导,玩家需要自己探索和发现线索。进度取决于玩家观察到的东西和拼凑出来的信息。游戏有多个层次,包括法证阶段。
作者说这个游戏已经上线一段时间了,现在拿出来供大家周末体验。目标是让玩家感觉像是在处理真实事件,而不是解决孤立的问题。不需要账号,直接选择用户名就可以开始玩了,不过要注意保存进度。
作者还邀请玩家提供反馈,包括哪里让人困惑、难度如何、哪里让人失去兴趣等,并提供了联系方式。此外,还有赞助商提供的奖品和特殊奖励。
总结一下,文章介绍了一个互动式解谜游戏,强调调查和情境体验,并邀请玩家参与并提供反馈。
文章介绍了一个互动式解谜游戏平台,强调调查、情境和多层挑战。玩家需自行探索线索并推进进度。无需注册即可参与,并可保存进度。作者邀请玩家提供反馈,并提供奖品激励参与者。
【2026春节】解题领红包【10.Windows 高级题 11.MCP 中级题】WP 通杀
3 weeks 6 days ago
不得不说,现在的AI能力真的吓人,大部分题目解题都是分析出思路,慢慢调教AI,最终解出flag,前两道题直接粘汇编代码AI秒出答案。最后这两道题就很离谱,用的gpt5.3-codex掉进了很多坑,都是一步一步慢慢调教爬出来,海量token尝试后的结果。
【2026春节】解题领红包 【2-9】WP 通杀
3 weeks 6 days ago
AI的发展太离谱了。不学习AI 就像发明了汽车马夫不学开车一样。
CVE-2016-20041 | Yasr Screen Reader 0.6.9-5 -p path traversal (Exploit 39734 / EUVD-2016-10837)
3 weeks 6 days ago
A vulnerability classified as critical was found in Yasr Screen Reader 0.6.9-5. This impacts an unknown function. Executing a manipulation of the argument -p can lead to path traversal.
This vulnerability appears as CVE-2016-20041. The attack requires local access. In addition, an exploit is available.
vuldb.com