Aggregator
DragonForce
1 year ago
cohenido
Teen Boys at Risk of Sextortion as 74% Lack Basic Awareness
1 year ago
The UK’s National Crime Agency has launched a new campaign designed to raise awareness of sextortion among teenage boys
CVE-2012-2208 | Piwigo 2.3.3 upgrade.php Language path traversal (EDB-18782 / XFDB-75185)
1 year ago
A vulnerability classified as critical has been found in Piwigo 2.3.3. This affects an unknown part of the file upgrade.php. The manipulation of the argument Language leads to path traversal.
This vulnerability is uniquely identified as CVE-2012-2208. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-2686 | mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 Backend /admin/ doFilter Request access control (IBTS25)
1 year ago
A vulnerability has been found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as critical. Affected by this vulnerability is the function doFilter of the file /admin/ of the component Backend. The manipulation of the argument Request leads to improper access controls.
This vulnerability is known as CVE-2025-2686. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-2687 | PHPGurukul eLearning System 1.0 Image /user/index.php unrestricted upload
1 year ago
A vulnerability classified as critical has been found in PHPGurukul eLearning System 1.0. Affected is an unknown function of the file /user/index.php of the component Image Handler. The manipulation leads to unrestricted upload.
This vulnerability is traded as CVE-2025-2687. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-2689 | yiisoft Yii2 up to 2.0.45 SortableIterator.php getIterator deserialization
1 year ago
A vulnerability, which was classified as critical, has been found in yiisoft Yii2 up to 2.0.45. Affected by this issue is the function getIterator of the file symfony\finder\Iterator\SortableIterator.php. The manipulation leads to deserialization.
This vulnerability is handled as CVE-2025-2689. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-2690 | yiisoft Yii2 up to 2.0.39 MockClass.php generate deserialization
1 year ago
A vulnerability, which was classified as critical, was found in yiisoft Yii2 up to 2.0.39. This affects the function Generate of the file phpunit\src\Framework\MockObject\MockClass.php. The manipulation leads to deserialization.
This vulnerability is uniquely identified as CVE-2025-2690. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-2699 | GetmeUK ContentTools up to 1.6.16 Image onload cross site scripting
1 year ago
A vulnerability was found in GetmeUK ContentTools up to 1.6.16. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Image Handler. The manipulation of the argument onload leads to cross site scripting.
This vulnerability is handled as CVE-2025-2699. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-2700 | michelson Dante Editor up to 0.4.4 Insert Link cross site scripting
1 year ago
A vulnerability classified as problematic has been found in michelson Dante Editor up to 0.4.4. This affects an unknown part of the component Insert Link Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-2700. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
奢侈品拥抱 AI 背后:一场技术与场景的双向奔赴
1 year ago
让产品和技术回归到解决现实问题的本质。
速通秘籍来咯!VMProtect虚拟机逆向入门
1 year ago
零基础也能学!掌握VMProtect加密原理与逆向实战技巧
600万条数据泄漏?Oracle(甲骨文)坚称未遭入侵
1 year ago
黑客攻击Oracle云服务,六百万数据被窃取,Oracle官方否认
CVE-2023-2598 内核提权详细分析
1 year ago
看雪论坛作者ID:默文
青藤成为国资国企安全运营生态合作企业
1 year ago
青藤成为国资国企安全运营生态合作企业
1 year ago
青藤成为国资国企安全运营生态合作企业
1 year ago
青藤成为国资国企安全运营生态合作企业
1 year ago
青藤成为国资国企安全运营生态合作企业
1 year ago
青藤成为国资国企安全运营生态合作企业
1 year ago