Aggregator
[remote] Microsoft Edge Windows 10 Version 1511 - Cross Site Scripting (XSS)
[webapps] Joomla JS Jobs plugin 1.4.2 - SQL injection
[remote] Tenda FH451 1.0.0.9 Router - Stack-based Buffer Overflow
[webapps] Discourse 3.1.1 - Unauthenticated Chat Message Access
[webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Telegram Bot Username
[webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Operator Surname
[webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Facebook Integration Page Name Field
[webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Personal Canned Messages
[webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via the Chat Transfer Function
[webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Department Assignment Alias Nick Field
[webapps] Pie Register WordPress Plugin 3.7.1.4 - Authentication Bypass to RCE
[webapps] Simple File List WordPress Plugin 4.2.2 - File Upload to RCE
Proactive Security and Insights for SharePoint Attacks (CVE-2025-53770 and CVE-2025-53771)
威努特助力银行网点实现高可靠性无线组网
Critical Flaw (CVE-2025-37103) in Aruba Instant On APs: Hardcoded Credentials Allow Full Admin Takeover – Patch Now!
Hewlett-Packard Enterprise has issued a critical security advisory concerning a severe vulnerability in Aruba Instant On access points. Embedded credentials have been discovered within the devices, enabling malicious actors to bypass standard authentication and...
The post Critical Flaw (CVE-2025-37103) in Aruba Instant On APs: Hardcoded Credentials Allow Full Admin Takeover – Patch Now! appeared first on Penetration Testing Tools.
npm Supply Chain Attack Exploited in the Wild – Phishing Steals Maintainer Tokens, Injects Malware into Popular Packages
Hackers have successfully injected malicious code into popular npm packages by leveraging a phishing campaign against project maintainers. The attackers orchestrated a targeted campaign aimed at developers stewarding key projects and managed to steal...
The post npm Supply Chain Attack Exploited in the Wild – Phishing Steals Maintainer Tokens, Injects Malware into Popular Packages appeared first on Penetration Testing Tools.