Aggregator
CVE-2009-3806 | DeDeCMS 5.1 feedback_js.php arcurl sql injection (EDB-9876)
2 months 3 weeks ago
A vulnerability has been found in DeDeCMS 5.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file feedback_js.php. The manipulation of the argument arcurl leads to sql injection.
This vulnerability is known as CVE-2009-3806. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Have We Reached a Distroless Tipping Point?
2 months 3 weeks ago
There’s a virtuous cycle in technology that pushes the boundaries of what’s being built and how it’s being used. A new technology development emerges and captures the world's attention. People start experimenting and discover novel applications, use cases, and approaches to maximize the innovation's potential. These use cases generate significant value, fueling demand for the next iteration of
The Hacker News
NetworkMiner 3.0 Released
2 months 3 weeks ago
I am very proud to announce the release of NetworkMiner 3.0 today! This version brings several new protocols as well as user interface improvements to NetworkMiner. We have also made significant changes under the hood, such as altering the default location to where NetworkMiner extracts files from n[...]
Erik Hjelmvik
«Извините, вы уволены, вас заменил алгоритм» — реальность для 40% рабочих мест
2 months 3 weeks ago
Кто не успел — того автоматизировали.
CVE-2025-24200
2 months 3 weeks ago
Currently trending CVE - Hype Score: 1 - An authorization issue was addressed with improved state management. This issue is fixed in iPadOS 17.7.5, iOS 18.3.1 and iPadOS 18.3.1. A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an ...
CVE-2025-22871
2 months 3 weeks ago
Currently trending CVE - Hype Score: 1
CVE-2025-24085
2 months 3 weeks ago
Currently trending CVE - Hype Score: 1 - A use after free issue was addressed with improved memory management. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue ...
CVE-2025-30208
2 months 3 weeks ago
Currently trending CVE - Hype Score: 30 - Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite serving allow list. Adding `?raw??` or `?import&raw??` to the URL bypasses this limitation and ...
CVE-2025-24201
2 months 3 weeks ago
Currently trending CVE - Hype Score: 1 - An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in visionOS 2.3.2, iOS 18.3.2 and iPadOS 18.3.2, macOS Sequoia 15.3.2, Safari 18.3.1. Maliciously crafted web content may be able to break out of Web Content ...
Qilin
2 months 3 weeks ago
cohenido
Qilin
2 months 3 weeks ago
cohenido
Qilin
2 months 3 weeks ago
cohenido
Chinese State Hackers Exploiting Newly Disclosed Ivanti Flaw
2 months 3 weeks ago
Mandiant warned that Chinese espionage actor UNC5221 is actively exploiting a critical Ivanti vulnerability, which can lead to remote code execution
Critical flaw in Apache Parquet’s Java Library allows remote code execution
2 months 3 weeks ago
Experts warn of a critical vulnerability impacting Apache Parquet’s Java Library that could allow remote code execution. Apache Parquet’s Java Library is a software library for reading and writing Parquet files in the Java programming language. Parquet is a columnar storage file format that is optimized for use with large-scale data processing frameworks, such as […]
Pierluigi Paganini
После X — вся индустрия: ЕС запускает машину тотального контроля
2 months 3 weeks ago
Миллиардный штраф для X перекроит правила игры в соцсетях.
PE攻击之傀儡进程与重定位
2 months 3 weeks ago
看雪论坛作者ID:mb_zelrqyxa
PE攻击之傀儡进程与重定位
2 months 3 weeks ago
看雪论坛作者ID:mb_zelrqyxa
PE攻击之傀儡进程与重定位
2 months 3 weeks ago
看雪论坛作者ID:mb_zelrqyxa
CVE-2006-2723 | Mozilla Firefox 2.0 denial of service (EDB-1867 / XFDB-26898)
2 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Mozilla Firefox 2.0. Affected is an unknown function. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2006-2723. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com