Aggregator
Under the cloak of UEFI Secure Boot: Introducing CVE-2024-7344
11 months ago
The story of a signed UEFI application allowing a UEFI Secure Boot bypass
Windows内核漏洞分析与EXP编写技巧
11 months ago
详解典型CVE内核漏洞,手把手教你掌握Windows内核漏洞分析、EXP编写与调试技巧
Palo Alto Networks Expedition 工具曝关键漏洞,明文密码或泄露
11 months ago
Palo Alto Networks Expedition 迁移工具曝多个关键漏洞,攻击者可利用这些漏洞执行任意命令并访问敏感防火墙凭证
【Windows 内核基础篇】-内核入门-段基础
11 months ago
看雪论坛作者ID:Gushang
Windows内核漏洞分析与EXP编写技巧
11 months ago
内核,是一个操作系统的核心。是基于硬件的第一层软件扩充,提供操作系统的最基本的功能;是操作系统工作的基础,负责管理系统的进程、内存、设备驱动程序、文件和网络系统,决定着系统的性能和稳定性。本课程讲师,
Palo Alto Networks Expedition 工具曝关键漏洞,明文密码或泄露
11 months ago
Palo Alto Networks 近日披露了其 Expedition 迁移工具中的多个关键安全漏洞,这些漏洞可能使攻击者能够执行任意命令并访问敏感的防火墙凭证。这些漏洞包括一个操作系统命令注入漏洞
【Windows 内核基础篇】-内核入门-段基础
11 months ago
保护模式下通过段划分内存的权限以及访问的权限。x86 和 x64都有六个段寄存器(Segment Register):DS: Data Segment 数据段 可读可写不可执行CS: Code Seg
Цена романа с Брэдом Питтом: €830 000 за разбитое сердце
11 months ago
ИИ помог украсть сотни тысяч у доверчивой женщины.
В России разработан ИИ для деанонимизации в мессенджерах
11 months ago
Технология безопасности раскрывает цифровые следы в мессенджере.
Defensie over op 100% duurzame elektriciteit
11 months ago
2025 begint duurzaam voor Defensie. Het ministerie is overgestapt op elektriciteit die volledig duurzaam op Nederlandse bodem is opgewekt, bijvoorbeeld met windmolens en zonnepanelen. Het gaat om ongeveer 365.000 megawatt voor heel Defensie. Dit komt voort uit een grote aanbesteding van de rijksoverheid.
PlugX malware deleted from thousands of systems by FBI
11 months ago
The FBI says it has removed PlugX malware from thousands of infected co
Proton CEO 拥抱特朗普引发争议
11 months ago
在苹果、Meta 等美国科技巨头 CEO 都向当选总统特朗普示好之后,以隐私为卖点的邮件服务和 VPN 提供商 Proton CEO Andy Yen 也公开表达了对特朗普的“敬意”。在引
Proton CEO 拥抱特朗普引发争议
11 months ago
在苹果、Meta 等美国科技巨头 CEO 都向当选总统特朗普示好之后,以隐私为卖点的邮件服务和 VPN 提供商 Proton CEO Andy Yen 也公开表达了对特朗普的“敬意”。在引发争议之后,相关贴文被删除。Andy Yen 认为共和党如今在为小人物挺身而出,对科技巨头们开展的反垄断诉讼是始于特朗普的第一个任期。他称,10 年前共和党是代表大企业,而民主党是代表小人物,如今完全颠倒过来了。
CVE-2011-4958 | SilverStripe up to 2.4.5 SSViewer.php process cross site scripting (EDB-36226 / SA46390)
11 months ago
A vulnerability was found in SilverStripe and classified as problematic. Affected by this issue is the function process of the file SSViewer.php. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2011-4958. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-0489 | Fanli2012 native-php-cms 1.0 friendlink_dodel.php id sql injection
11 months ago
A vulnerability classified as critical was found in Fanli2012 native-php-cms 1.0. This vulnerability affects unknown code of the file /fladmin/friendlink_dodel.php. The manipulation of the argument id leads to sql injection.
This vulnerability was named CVE-2025-0489. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-0490 | Fanli2012 native-php-cms 1.0 article_dodel.php id sql injection
11 months ago
A vulnerability, which was classified as critical, has been found in Fanli2012 native-php-cms 1.0. This issue affects some unknown processing of the file /fladmin/article_dodel.php. The manipulation of the argument id leads to sql injection.
The identification of this vulnerability is CVE-2025-0490. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-0491 | Fanli2012 native-php-cms 1.0 /fladmin/cat_dodel.php id sql injection
11 months ago
A vulnerability, which was classified as critical, was found in Fanli2012 native-php-cms 1.0. Affected is an unknown function of the file /fladmin/cat_dodel.php. The manipulation of the argument id leads to sql injection.
This vulnerability is traded as CVE-2025-0491. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-0492 | D-Link DIR-823X 240126/240802 FUN_00412244 null pointer dereference
11 months ago
A vulnerability has been found in D-Link DIR-823X 240126/240802 and classified as critical. Affected by this vulnerability is the function FUN_00412244. The manipulation leads to null pointer dereference.
This vulnerability is known as CVE-2025-0492. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-41453 | Process Maker pm4core-docker 4.1.21-RC7 Name cross site scripting
11 months ago
A vulnerability was found in Process Maker pm4core-docker 4.1.21-RC7 and classified as problematic. This issue affects some unknown processing. The manipulation of the argument Name leads to cross site scripting.
The identification of this vulnerability is CVE-2024-41453. The attack may be initiated remotely. There is no exploit available.
vuldb.com