Aggregator
CVE-2025-4018 | 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160 CrawlController.java addCrawlSource missing authentication
CVE-2025-4019 | 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160 GeneratorController.java genCode missing authentication
CVE-2025-4020 | PHPGurukul Old Age Home Management System 1.0 /contact.php fname sql injection
CVE-2025-4021 | code-projects Patient Record Management System 1.0 /edit_spatient.php ID sql injection
SAP NetWeaver 0-Day Flaw Actively Exploited to Deploy Webshells
SAP disclosed a critical zero-day vulnerability, identified as CVE-2025-31324, in its NetWeaver Visual Composer component. This vulnerability, with a maximum CVSSv3 severity score of 10.0, stems from a missing authorization check within the Metadata Uploader module of Visual Composer. When exploited, it allows unauthenticated attackers to upload arbitrary malicious files via specially crafted POST requests to […]
The post SAP NetWeaver 0-Day Flaw Actively Exploited to Deploy Webshells appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Windows Shellcode开发
从CVE-2025-30208到CVE-2025-31125再到CVE-2025-31486
Netskope One enhancements cover a broad range of AI security use cases
Netskope announced expansion of the Netskope One platform to cover more AI security use cases, including enhanced protections for private applications and data security posture management (DSPM) attributes. While other vendors focus on enabling safe user access to AI applications, Netskope capabilities go much further by managing new risks introduced by the adoption and building of AI applications, providing a deep understanding of sensitive data being fed into large language models (LLMs) and assessing risk … More →
The post Netskope One enhancements cover a broad range of AI security use cases appeared first on Help Net Security.
2025年Solar应急响应公益月赛-3月
CVE-2022-23515 | Loofah URI cross site scripting (ID 101 / Nessus ID 207898)
CVE-2022-42856 | Apple tvOS up to 16.1.1 WebKit type confusion (HT213535)
CVE-2022-42856 | Apple macOS up to 13.0 WebKit type confusion (HT213532)
CVE-2022-42856 | Apple Safari up to 16.1 WebKit type confusion (HT213537)
CVE-2022-39253 | Apple Xcode up to 14.0 Git information disclosure (HT213496 / Nessus ID 211059)
Trend Micro helps organizations secure AI-driven workloads
Trend Micro announced new AI-powered threat detection capabilities designed specifically for enterprises embracing AI at scale. This effort brings together Trend’s security expertise with NVIDIA accelerated computing and NVIDIA AI Enterprise software, leveraging AWS infrastructure to support scalable, enterprise-ready deployment. The solution is built to help organizations secure AI-driven workloads and business processes without compromising performance or flexibility. As enterprises scale their AI ambitions from GenAI to agentic AI, new attack surfaces emerge, including threats … More →
The post Trend Micro helps organizations secure AI-driven workloads appeared first on Help Net Security.