Aggregator
新型VMScape攻击突破AMD、英特尔CPU的客户机-主机隔离
4 weeks 1 day ago
安全客
现代智能手机易受无声“选择劫持”(ChoiceJacking)USB攻击
4 weeks 1 day ago
安全客
CoreDNS漏洞允许攻击者固定DNS缓存并拒绝服务更新
4 weeks 1 day ago
安全客
Angular SSR漏洞允许攻击者访问敏感数据
4 weeks 1 day ago
安全客
ZynorRAT攻击Windows和Linux系统以获取远程访问权限
4 weeks 1 day ago
安全客
应急“国家队”再发力!360入选全国20余省市级网络安全技术支撑单位
4 weeks 1 day ago
安全客
F5拟收购CalypsoAI,瞄准AI模型滥用问题
4 weeks 1 day ago
安全客
Early Access Program (Elite Subscribers)
4 weeks 1 day ago
Dark Web Informer
CVE-2025-10273 | erjinzhi 10OA 1.0 /view/file.aspx File path traversal (EUVD-2025-28998)
4 weeks 1 day ago
A vulnerability was found in erjinzhi 10OA 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /view/file.aspx. Such manipulation of the argument File leads to path traversal.
This vulnerability is uniquely identified as CVE-2025-10273. The attack can only be initiated within the local network. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-10319 | JeecgBoot up to 3.8.2 Tenant Log Export /sys/tenant/exportLog improper authorization (EUVD-2025-29051)
4 weeks 1 day ago
A vulnerability was found in JeecgBoot up to 3.8.2. It has been declared as critical. Affected by this issue is some unknown functionality of the file /sys/tenant/exportLog of the component Tenant Log Export. The manipulation results in improper authorization.
This vulnerability is reported as CVE-2025-10319. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-10266 | NewType Infortech NUP Portal up to SP5.0 sql injection (EUVD-2025-29038)
4 weeks 1 day ago
A vulnerability marked as critical has been reported in NewType Infortech NUP Portal up to SP5.0. This impacts an unknown function. This manipulation causes sql injection.
This vulnerability is handled as CVE-2025-10266. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2025-10267 | NewType Infortech NUP Portal up to SP5.0 File Extension missing authentication (EUVD-2025-29037)
4 weeks 1 day ago
A vulnerability classified as critical has been found in NewType Infortech NUP Portal up to SP5.0. Affected by this vulnerability is an unknown functionality of the component File Extension Handler. Performing manipulation results in missing authentication.
This vulnerability was named CVE-2025-10267. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2025-10320 | iteachyou Dreamer CMS up to 4.1.3.2 /admin/user/updatePwd weak password (EUVD-2025-29054)
4 weeks 1 day ago
A vulnerability identified as critical has been detected in iteachyou Dreamer CMS up to 4.1.3.2. This issue affects some unknown processing of the file /admin/user/updatePwd. Performing manipulation results in weak password requirements.
This vulnerability is known as CVE-2025-10320. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-10264 | Digiever DS-1200 exposure of sensitive system information to an unauthorized control sphere (EUVD-2025-29031)
4 weeks 1 day ago
A vulnerability described as problematic has been identified in Digiever DS-1200, DS-2100 Pro, DS-2100 Pro+, DS-2100 UHD, DS-2200 UHD, DS-2200 UHD+, DS-4200 Pro, DS-4200 Pro+, DS-4200 UHD, DS-4200 UHD+, DS-4100-RM, DS-4200-RM Pro+, DS-4200-RM UHD, DS-8x00-RM Pro+, DS-8x00-SRM Pro+, DS-8x00-RM UHD, DS-16x00-RM Pro+ and DS-16x00-RM UHD. Affected is an unknown function. Such manipulation leads to exposure of sensitive system information to an unauthorized control sphere.
This vulnerability is uniquely identified as CVE-2025-10264. The attack can be launched remotely. No exploit exists.
vuldb.com
Why Hybrid Windows Environments are Still a Security Blind Spot
4 weeks 1 day ago
5 min readHybrid Windows environments pose a security risk due to outdated identity controls. Relying on static credentials and fragmented visibility, these setups are vulnerable. Modernization with workload identity federation, conditional access, and centralized monitoring is crucial to close security gaps.
The post Why Hybrid Windows Environments are Still a Security Blind Spot appeared first on Aembit.
The post Why Hybrid Windows Environments are Still a Security Blind Spot appeared first on Security Boulevard.
Ashur Kanoon
CVE-2006-1971 | KRANKIKOM ContentBoxX login.php action cross site scripting (EDB-27688 / XFDB-25952)
4 weeks 1 day ago
A vulnerability, which was classified as problematic, was found in KRANKIKOM ContentBoxX. Affected by this issue is some unknown functionality of the file login.php. Such manipulation of the argument action leads to basic cross site scripting.
This vulnerability is uniquely identified as CVE-2006-1971. The attack can be launched remotely. Moreover, an exploit is present.
vuldb.com
CVE-2006-3172 | Content*Builder headline/headlineBox.php rel privileges management (EDB-1903 / XFDB-27044)
4 weeks 1 day ago
A vulnerability, which was classified as critical, was found in Content*Builder. This affects an unknown part of the file headline/headlineBox.php. Such manipulation of the argument rel leads to improper privilege management.
This vulnerability is documented as CVE-2006-3172. The attack needs to be performed locally. Additionally, an exploit exists.
vuldb.com
CVE-2006-3172 | Content*Builder showHeadline.inc.php rel privileges management (EDB-1903 / XFDB-27044)
4 weeks 1 day ago
A vulnerability has been found in Content*Builder and classified as critical. This vulnerability affects unknown code of the file headline/showHeadline.inc.php. Performing manipulation of the argument rel results in improper privilege management.
This vulnerability is reported as CVE-2006-3172. The attack requires a local approach. Moreover, an exploit is present.
vuldb.com
CVE-2006-3172 | Content*Builder overview.inc.php rel privileges management (EDB-1903 / XFDB-27044)
4 weeks 1 day ago
A vulnerability classified as critical has been found in Content*Builder. Affected is an unknown function of the file article2/overview.inc.php. The manipulation of the argument rel leads to improper privilege management.
This vulnerability is listed as CVE-2006-3172. The attack must be carried out locally. In addition, an exploit is available.
vuldb.com