Aggregator
CVE-2026-26337 | Hyland Alfresco Transformation Service/Alfresco Community absolute path traversal
CVE-2019-25444 | Phpscriptsmall Fiverr Clone Script 1.2.2 page sql injection (Exploit 46637)
CVE-2026-24892 | openITCOCKPIT up to 5.3.x Changelog Entries unserialize deserialization (GHSA-g83p-vvjm-g39x)
CVE-2019-25438 | LabCollector 5.423 login.php Login sql injection (Exploit 47460 / EDB-47460)
CVE-2026-26338 | Hyland Alfresco Transformation Service/Alfresco Community server-side request forgery
CVE-2026-25896 | NaturalIntelligence fast-xml-parser up to 5.3.4 incorrect regex (GHSA-m7jm-9gc2-mpf2 / Nessus ID 299725)
CVE-2026-27474 | SPIP up to 4.4.8 echappe_anti_xss cross site scripting (Nessus ID 299646)
CVE-2025-71242 | SPIP up to 4.1.19/4.2.16/4.3.5 improper authentication (Nessus ID 299651)
CVE-2025-71241 | SPIP up to 4.1.19/4.2.16/4.3.5 cross site scripting (Nessus ID 299649)
CVE-2026-23226 | Linux Kernel up to 6.18.10/6.19.0 ksmbd lookup_chann_list use after free (Nessus ID 299441 / WID-SEC-2026-0462)
CVE-2026-2452 | pretix pretix-newsletter up to 1.x/2.0.0 Placeholder dynamic variable evaluation (EUVD-2026-6095)
Encrypted Deception: Cisco Talos Unmasks “Dohdoor” and the Stealthy UAT-10027 Campaign Targeting Healthcare
Since the twilight of 2025, Cisco Talos has been vigilantly tracking a malicious campaign directed against educational and
The post Encrypted Deception: Cisco Talos Unmasks “Dohdoor” and the Stealthy UAT-10027 Campaign Targeting Healthcare appeared first on Penetration Testing Tools.
The Great Dispersal: How the Fall of the RAMP Forum Birthed a New Breed of Ransomware Enclaves
In late January 2026, American law enforcement agencies dismantled a prominent platform that had served for years as
The post The Great Dispersal: How the Fall of the RAMP Forum Birthed a New Breed of Ransomware Enclaves appeared first on Penetration Testing Tools.
The End of PGP? How “Linux ID” is Revolutionizing Kernel Trust in the Wake of xz Utils
“Who are you, and why should the Linux kernel trust you?” Within the kernel development community, this query
The post The End of PGP? How “Linux ID” is Revolutionizing Kernel Trust in the Wake of xz Utils appeared first on Penetration Testing Tools.
一个好玩儿的系统上线了!!!
Ask Master: The “EncystPHP” Web Shell is Silently Annexing Global FreePBX Telephony Servers
A mundane telephony vulnerability has metamorphosed into a comprehensive server capitulation. Cybersecurity specialists have unearthed a pernicious web
The post Ask Master: The “EncystPHP” Web Shell is Silently Annexing Global FreePBX Telephony Servers appeared first on Penetration Testing Tools.