Aggregator
纽创信安邀您参加2025 RISC-V中国峰会,共筑后量子时代芯片级安全底座!
中国在建太阳能风电装机容量占全球四分之三
2025-07-11 HW情报分享(四)
CVE-2025-2523 | Honeywell C300 PCNT02 Control Data Access integer underflow (EUVD-2025-21063)
CVE-2025-53637 | Meshtastic Firmware up to 2.6.5 GitHub Action main_matrix.yml os command injection (EUVD-2025-21075)
CVE-2025-48891 | Advantech iView CUtils.checkSQLInjection sql injection (icsa-25-191-08 / EUVD-2025-21082)
CVE-2025-31267 | Apple App Store Connect up to 2.x User Information improper authentication (EUVD-2025-21072)
CVE-2025-6200 | GeoDirectory Plugin up to 2.8.119 on WordPress Shortcode Attribute cross site scripting (EUVD-2025-21113)
CVE-2025-30023 | Axis Camera Station Pro/Camera Station/Device Manager Communication Protocol deserialization (EUVD-2025-21112)
CVE-2025-30024 | Axis Device Manager Communication Protocol certificate validation (EUVD-2025-21111)
CVE-2025-30025 | Axis Device Manager/Camera Station Pro/Camera Station Communication Protocol deserialization (EUVD-2025-21110)
CVE-2025-30026 | Axis Camera Station Pro/Camera Station authentication bypass (EUVD-2025-21109)
Hackers Actively Exploiting CitrixBleed 2 Vulnerability in the Wild
Researchers have observed widespread exploitation attempts targeting a critical memory disclosure vulnerability in Citrix NetScaler devices, designated as CVE-2025-5777 and dubbed “CitrixBleed 2.” This pre-authentication flaw enables attackers to craft malicious requests that leak uninitialized memory from affected NetScaler ADC and Gateway devices, potentially exposing sensitive data, including session tokens, passwords, and configuration values. The […]
The post Hackers Actively Exploiting CitrixBleed 2 Vulnerability in the Wild appeared first on Cyber Security News.
Cyber Security expert, Difesa, Legioni e Milizie.
【开放注册公告】吾爱破解论坛2025年7月21日暑假开放注册公告
【开放注册公告】吾爱破解论坛2025年7月21日暑假开放注册公告
Critical D-Link Vulnerability Lets Remote Attackers Crash Servers Without Authentication
Security researchers have discovered a critical stack-based buffer overflow vulnerability in D-Link DIR-825 Rev.B 2.10 routers that allows remote attackers to crash servers without requiring authentication. The vulnerability, designated as CVE-2025-7206, affects the router’s httpd binary and can be exploited by manipulating the language parameter in the switch_language.cgi script. This flaw poses significant risks to […]
The post Critical D-Link Vulnerability Lets Remote Attackers Crash Servers Without Authentication appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.