Aggregator
CVE-2025-4545 | CTCMS Content Management System 2.1.2 File Tpl.php del path traversal
CVE-2025-25427 | TP-Link TL-WR841N up to 4.19 Web Interface cross site scripting (EUVD-2025-11808)
CVE-2025-30138 | G-Net Dashcam BB GONX Setting improper authorization (EUVD-2025-6707)
CVE-2025-30140 | G-Net Dashcam BB GONX Domain Name origin validation (EUVD-2025-6712)
CVE-2024-56524 | Radware Cloud Web Application Firewall Special Character access control (VU#722229 / EUVD-2025-14309)
CVE-2024-56523 | Radware Cloud Web Application Firewall HTTP GET Request access control (VU#722229 / EUVD-2025-14310)
CVE-2025-26841 | WPEVEREST Everest Forms up to 3.0.8 File Upload cross site scripting (EUVD-2025-14307)
CVE-2025-2141 | IBM System Storage Virtualization Engine TS7700 8.54.2.17/8.60.0.115/8.60.0.115 cross site scripting (EUVD-2025-19624)
CVE-2025-36056 | IBM System Storage Virtualization Engine TS7700 8.54.2.17/8.60.0.115/8.60.0.115 Web UI cross site scripting (EUVD-2025-19623)
CVE-2025-53003 | JanssenProject jans up to 1.7.x Config API information disclosure (ID 11575 / EUVD-2025-19625)
CVE-2024-23928 | Pioneer DMH-WT7600NEX Telematics certificate validation (ZDI-24-1045 / EUVD-2024-21358)
CVE-2024-23929 | Pioneer DMH-WT7600NEX Telematics path traversal (ZDI-24-1044 / EUVD-2024-21359)
CVE-2024-23937 | Silicon Labs Gecko OS Debug Interface format string (EUVD-2024-21367)
谷歌推出Chrome紧急更新v138.0.7204.97修复已经被黑客利用的高危漏洞
12306 余票监控工具:支持 飞书、企业微信、Bark推送、Telegram、Email 通知[Windows]
Kimsuky Hackers Using ClickFix Technique to Execute Malicious Scripts on Victim Machines
The notorious North Korean threat group Kimsuky has adopted a sophisticated social engineering tactic known as “ClickFix” to deceive users into executing malicious scripts on their own systems. Originally introduced by Proofpoint researchers in April 2024, this deceptive technique tricks victims into believing they need to troubleshoot browser errors or verify security documents, ultimately leading […]
The post Kimsuky Hackers Using ClickFix Technique to Execute Malicious Scripts on Victim Machines appeared first on Cyber Security News.
AI 上新|这个应用,让苏格拉底和尼采手把手教我「哲学」
AI 上新|这个应用,让苏格拉底和尼采手把手教我「哲学」
Stealthy WordPress Malware Uncovered: Multi-Stage RAT Injects via Header.php, Hides Traces
Cybercriminals have launched a new wave of attacks targeting WordPress websites—so meticulously concealed that the campaign was only recently uncovered. Security experts at Sucuri have discovered that compromised websites are being used as silent...
The post Stealthy WordPress Malware Uncovered: Multi-Stage RAT Injects via Header.php, Hides Traces appeared first on Penetration Testing Tools.