Aggregator
CVE-2023-49001 | Indi Browser 12.11.23 com.example.gurry.kvbrowswer.webview code injection
CVE-2023-50578 | Mingsoft MCMS 5.2.9 /content/list.do categoryType sql injection
CVE-2023-52266 | ehttp up to 1.0.5 epoll_socket.cpp read_func use after free (Issue 38)
CVE-2024-8105 | Multiple Vendor Product Platform Key PKfail hard-coded key (BRLY-2024-005)
octoscan: A static vulnerability scanner for GitHub action workflows
Octoscan Octoscan is a static vulnerability scanner for GitHub action workflows. Usage download remote workflows Octoscan can be run against a local git repository or you can download all the workflows with the dl action: analyze...
The post octoscan: A static vulnerability scanner for GitHub action workflows appeared first on Penetration Testing Tools.
Data of nearly 300,000 exposed in Avis cyberattack
以色列科研人员设计了一种新方法,利用来自内存总线的无线电信号从隔离系统中窃取数据
JVN: 複数のアルプスシステムインテグレーション製品およびそのOEM製品におけるクロスサイトリクエストフォージェリの脆弱性
AHWT: Hardening tool for Windows operating systems
AHWT – another hardening tool for Windows operating systems The program is a script generator with a collection of parameters and recommendations from CIS Benchmarks and DoD STIGs with some adjustments. All parameters are...
The post AHWT: Hardening tool for Windows operating systems appeared first on Penetration Testing Tools.
0909 | 排名·香港·中国网络安全科技商业评级
Java反序列化漏洞浅析与应对|大湾区金融安全专刊·安全村
HyperDbg: open-source, hypervisor-assisted user-mode, and kernel-mode Windows debugger
HyperDbg Debugger HyperDbg debugger is an open-source, hypervisor-assisted user-mode, and kernel-mode Windows debugger with a focus on using modern hardware technologies. It is a debugger designed for analyzing, fuzzing, and reversing. HyperDbg is designed...
The post HyperDbg: open-source, hypervisor-assisted user-mode, and kernel-mode Windows debugger appeared first on Penetration Testing Tools.
openappsec: machine learning security engine to prevents threats against Web Application & APIs
openappsec open-appsec (openappsec.io) builds on machine learning to provide preemptive web app & API threat protection against OWASP-Top-10 and zero-day attacks. It can be deployed as an add-on to Kubernetes Ingress, NGINX, Envoy (soon), and API Gateways....
The post openappsec: machine learning security engine to prevents threats against Web Application & APIs appeared first on Penetration Testing Tools.