Aggregator
国内最专业、最全面的 [ .NET 代码审计 ] 体系化视频学习课程
2 months 1 week ago
.NET 攻击面发现新维度,提取临时编译文件跨应用获取敏感信息
2 months 1 week ago
盘点闭眼就扫的RCE漏洞利用工具
2 months 1 week ago
前言安服累,渗透狂,一入网安破大防,莫说勤奋自然强;挤地铁,上HW,渗透工位坐机房,意淫桃谷伴身旁;电脑背,
盘点闭眼就扫的RCE漏洞利用工具
2 months 1 week ago
当前环境出现异常状态,需完成验证后方可继续访问相关服务或网站。
WordPress Redirect Malware Hidden in Google Tag Manager Code
2 months 1 week ago
攻击者通过将恶意代码注入WordPress数据库中的wp_options和wp_posts表,利用Google Tag Manager(GTM)加载远程JavaScript脚本,导致网站在4-5秒后重定向至spam域名spelletjes[.]nl。该攻击隐蔽性强,难以通过文件扫描检测,并对网站信任度、SEO及转化率造成严重影响。修复需移除可疑GTM标签并进行全面扫描。
Air Serbia Hit by Major Cyberattack: Internal Systems Disrupted, Active Directory Compromised
2 months 1 week ago
Air Serbia has fallen victim to a cyberattack that has significantly disrupted the company’s internal operations. The digital crisis began in the early days of July 2025 and persists to this day. One of...
The post Air Serbia Hit by Major Cyberattack: Internal Systems Disrupted, Active Directory Compromised appeared first on Penetration Testing Tools.
ddos
银狐最新攻击样本行为特征与威胁情报
2 months 1 week ago
银狐最新攻击样本行为特征与威胁情报
银狐最新攻击样本行为特征与威胁情报
2 months 1 week ago
当前环境出现异常,需完成验证后才能继续访问。
美团正式推骑手养老保险,不限时长;中国「豪车税」标准降至 90 万;OpenAI 推出 Agent 功能 | 极客早知道
2 months 1 week ago
Uber 投资 3 亿美元,计划明年推出 Robotaxi;Anthropic 估值超千亿美元;马斯克预告 Grok 将推出「AI 男友」。
CVE-2025-53833
2 months 1 week ago
Currently trending CVE - Hype Score: 7 - LaRecipe is an application that allows users to create documentation with Markdown inside a Laravel app. Versions prior to 2.8.1 are vulnerable to Server-Side Template Injection (SSTI), which could potentially lead to Remote Code Execution (RCE) in vulnerable configurations. ...
免费领《文明6:白金版》!经典必玩的回合制策略模拟游戏大作
2 months 1 week ago
《文明6:白金版》限时免费领取,包含6个DLC和2个资料片。这款经典回合制策略游戏让玩家创建并发展文明,跨越历史进程,在外交与战争中扩张势力。丰富的玩法和极高的耐玩性使其成为策略爱好者的必玩之作。
hoaxshell: A Windows reverse shell payload generator and handler
2 months 1 week ago
hoaxshell is a Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell, based on the following concept: This c2 concept (which could be implemented by...
The post hoaxshell: A Windows reverse shell payload generator and handler appeared first on Penetration Testing Tools.
ddos
CVE-2025-3323 | godcheese/code-projects Nimrod 0.8 ViewMenuCategoryRestController.java searchAllByName sql injection (EUVD-2025-10024)
2 months 1 week ago
A vulnerability classified as critical was found in godcheese/code-projects Nimrod 0.8. Affected by this vulnerability is the function searchAllByName of the file ViewMenuCategoryRestController.java. The manipulation of the argument Name leads to sql injection.
This vulnerability is known as CVE-2025-3323. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-2876 | Melapress Security Plugin/Security Premium Plugin 2.1.0 on WordPress monitor_admin_actions authorization
2 months 1 week ago
A vulnerability, which was classified as critical, has been found in Melapress Security Plugin and Security Premium Plugin 2.1.0 on WordPress. This issue affects the function monitor_admin_actions. The manipulation leads to missing authorization.
The identification of this vulnerability is CVE-2025-2876. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-2572 | Progress WhatsUp Gold up to 2024.0.2 WhatsUp.dbo.WrlsMacAddressGroup improper authentication (Nessus ID 234498)
2 months 1 week ago
A vulnerability, which was classified as critical, has been found in Progress WhatsUp Gold up to 2024.0.2. This issue affects some unknown processing. The manipulation of the argument WhatsUp.dbo.WrlsMacAddressGroup leads to improper authentication.
The identification of this vulnerability is CVE-2025-2572. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-43850 | IBM Aspera Console up to 3.4.4 Web UI cross site scripting
2 months 1 week ago
A vulnerability was found in IBM Aspera Console up to 3.4.4. It has been declared as problematic. This vulnerability affects unknown code of the component Web UI. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2022-43850. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-43847 | IBM Aspera Console up to 3.4.4 HTTP Header http headers for scripting syntax
2 months 1 week ago
A vulnerability was found in IBM Aspera Console up to 3.4.4. It has been rated as critical. This issue affects some unknown processing of the component HTTP Header Handler. The manipulation leads to improper neutralization of http headers for scripting syntax.
The identification of this vulnerability is CVE-2022-43847. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-43851 | IBM Aspera Console up to 3.4.4 risky encryption
2 months 1 week ago
A vulnerability classified as problematic was found in IBM Aspera Console up to 3.4.4. Affected by this vulnerability is an unknown functionality. The manipulation leads to risky cryptographic algorithm.
This vulnerability is known as CVE-2022-43851. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-3548 | Open Asset Import Library Assimp up to 5.4.3 File include/assimp/types.h aiString::Set heap-based overflow (Issue 6068 / Nessus ID 235880)
2 months 1 week ago
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp up to 5.4.3. This issue affects the function aiString::Set in the library include/assimp/types.h of the component File Handler. The manipulation leads to heap-based buffer overflow.
The identification of this vulnerability is CVE-2025-3548. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com