Aggregator
Оптические трюки вместо камуфляжа: что делало корабли Первой мировой неуязвимыми
4 months ago
Загадка столетней давности наконец разгадана.
DeepSeek 们为什么选择飞书?
4 months ago
大模型公司都在用飞书,但用飞书的 AI 公司不只在做大模型。
充电 5 分钟、续航 400 公里,比亚迪甩出终结燃油车时代的「王炸」
4 months ago
「电动爹难伺候」的标签,正在被比亚迪撕掉。
Expose Android Malware in Seconds: ANY.RUN Sandbox Now Supports Real-Time APK Analysis
4 months ago
It’s here! The news security teams have been waiting for: ANY.RUN now fully supports Android OS in its interactive sandbox! Now, you can investigate Android malware in a real ARM-based sandbox, exactly as it would behave on an actual mobile device. No more blind spots or unreliable analysis. With this release, ANY.RUN allows SOC teams, […]
The post Expose Android Malware in Seconds: ANY.RUN Sandbox Now Supports Real-Time APK Analysis appeared first on ANY.RUN's Cybersecurity Blog.
ANY.RUN
Южная Корея бьёт тревогу: хакеры атакуют производителей дронов
4 months ago
Разведка предупреждает о новых рисках для оборонного потенциала страны.
Apache Tomcat 漏洞在公开披露仅30小时后便遭疯狂利用
4 months ago
安全客
CVE-2024-27952 | WP Codeus Advanced Sermons Plugin up to 3.2 on WordPress cross site scripting
4 months ago
A vulnerability has been found in WP Codeus Advanced Sermons Plugin up to 3.2 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-27952. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-2420 | 猫宁i Morning up to bc782730c74ff080494f145cc363a0b4f43f7d3e cross-site request forgery (IBRVMX)
4 months ago
A vulnerability classified as problematic was found in 猫宁i Morning up to bc782730c74ff080494f145cc363a0b4f43f7d3e. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2025-2420. The attack can be launched remotely. Furthermore, there is an exploit available.
This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.
vuldb.com
CVE-2025-2471 | PHPGurukul Boat Booking System 1.0 /boat-details.php bid sql injection
4 months ago
A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. Affected is an unknown function of the file /boat-details.php. The manipulation of the argument bid leads to sql injection.
This vulnerability is traded as CVE-2025-2471. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-2472 | PHPGurukul Apartment Visitors Management System 1.0 Sign In /index.php username sql injection
4 months ago
A vulnerability has been found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Sign In. The manipulation of the argument username leads to sql injection.
This vulnerability is known as CVE-2025-2472. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-2473 | PHPGurukul Company Visitor Management System 2.0 Sign In /index.php username sql injection
4 months ago
A vulnerability was found in PHPGurukul Company Visitor Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /index.php of the component Sign In. The manipulation of the argument username leads to sql injection.
This vulnerability is handled as CVE-2025-2473. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-29912 | NASA CryptoLib up to 1.3.3 Crypto_TC_ProcessSecurity fl heap-based overflow (GHSA-3f5x-r59x-p8cf)
4 months ago
A vulnerability was found in NASA CryptoLib up to 1.3.3. It has been declared as very critical. This vulnerability affects the function Crypto_TC_ProcessSecurity. The manipulation of the argument fl leads to heap-based buffer overflow.
This vulnerability was named CVE-2025-29912. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-29913 | NASA CryptoLib up to 1.3.3 Crypto_TC_Prep_AAD out-of-bounds (GHSA-q4v2-fvrv-qrf6)
4 months ago
A vulnerability, which was classified as critical, has been found in NASA CryptoLib up to 1.3.3. Affected by this issue is the function Crypto_TC_Prep_AAD. The manipulation leads to out-of-bounds read.
This vulnerability is handled as CVE-2025-29913. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-29911 | NASA CryptoLib up to 1.3.3 Crypto_AOS_ProcessSecurity heap-based overflow (GHSA-7g6g-9gj4-8c68)
4 months ago
A vulnerability was found in NASA CryptoLib up to 1.3.3. It has been rated as very critical. This issue affects the function Crypto_AOS_ProcessSecurity. The manipulation leads to heap-based buffer overflow.
The identification of this vulnerability is CVE-2025-29911. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-2262 | samdani Logo Slider Plugin up to 3.7.3 on WordPress Shortcode do_shortcode authorization
4 months ago
A vulnerability has been found in samdani Logo Slider Plugin up to 3.7.3 on WordPress and classified as critical. This vulnerability affects the function do_shortcode of the component Shortcode Handler. The manipulation leads to missing authorization.
This vulnerability was named CVE-2025-2262. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-24306 | Fuji Soft +F FS010M prior 2.0.0_1101 os command injection
4 months ago
A vulnerability was found in Fuji Soft +F FS010M and classified as critical. This issue affects some unknown processing. The manipulation leads to os command injection.
The identification of this vulnerability is CVE-2025-24306. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-25220 | Fuji Soft +F FS010M prior 2.0.1_1101 os command injection
4 months ago
A vulnerability was found in Fuji Soft +F FS010M. It has been classified as critical. Affected is an unknown function. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2025-25220. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-0755 | MongoDB libbson/Server bson_append functions heap-based overflow
4 months ago
A vulnerability was found in MongoDB libbson and Server. It has been declared as critical. Affected by this vulnerability is the function bson_append functions. The manipulation leads to heap-based buffer overflow.
This vulnerability is known as CVE-2025-0755. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-13176 | OpenSSL up to 3.4.0 ECDSA Signature covert timing channel (Nessus ID 214984)
4 months ago
A vulnerability, which was classified as problematic, was found in OpenSSL up to 3.4.0. This affects an unknown part of the component ECDSA Signature Handler. The manipulation leads to covert timing channel.
This vulnerability is uniquely identified as CVE-2024-13176. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com