Aggregator
Hunters
10 months 3 weeks ago
cohenido
Linux 内核高危漏洞致系统面临权限提升攻击
10 months 3 weeks ago
安全客
Submit #560790: Netgear EX6200 1.0.3.94 Buffer Overflow [Accepted]
10 months 3 weeks ago
Submit #560790 / VDB-306634
54357
Submit #560789: Netgear EX6200 1.0.3.94 Buffer Overflow [Accepted]
10 months 3 weeks ago
Submit #560789 / VDB-306633
54357
Submit #560788: Netgear EX6200 1.0.3.94 Buffer Overflow [Accepted]
10 months 3 weeks ago
Submit #560788 / VDB-306632
54357
Submit #560787: Netgear EX6120 1.0.0.68 Buffer Overflow [Duplicate]
10 months 3 weeks ago
Submit #560787 / VDB-306631
54357
Submit #560786: Netgear EX6120 1.0.0.68 Buffer Overflow [Duplicate]
10 months 3 weeks ago
Submit #560786 / VDB-306631
54357
Submit #560785: Netgear EX6120 1.0.0.68 Buffer Overflow [Accepted]
10 months 3 weeks ago
Submit #560785 / VDB-306631
54357
CVE-2025-3341 | codeprojects Online Restaurant Management System 1.0 reservation_view.php ID sql injection
10 months 3 weeks ago
A vulnerability, which was classified as critical, was found in codeprojects Online Restaurant Management System 1.0. This affects an unknown part of the file /admin/reservation_view.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-3341. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
ResolverRAT 通过复杂的网络钓鱼攻击医疗保健和制药行业
10 months 3 weeks ago
安全客
Streamlining Global Automotive Cybersecurity Governance to Accelerate Innovation, Assurance, and Compliance
10 months 3 weeks ago
Bringing streamable HTTP transport and Python language support to MCP servers
10 months 3 weeks ago
We're continuing to make it easier for developers to bring their services into the AI ecosystem with the Model Context Protocol (MCP) with two new updates.
Jeremy Morrell
Revived CryptoJS library is a crypto stealer in disguise
10 months 3 weeks ago
An illicit npm package called 'crypto-encrypt-ts' may appear to revive the unmaintained but vastly popular CryptoJS library, but what it actually does is peek into your crypto wallet and exfiltrate your secrets to threat actors.
The post Revived CryptoJS library is a crypto stealer in disguise appeared first on Security Boulevard.
Ax Sharma
VeriSource 数据泄露影响了 400 万个人
10 months 3 weeks ago
安全客
France links Russian APT28 to attacks on dozen French entities
10 months 3 weeks ago
France blames Russia-linked APT28 for cyberattacks targeting or compromising a dozen French government bodies and other entities. The Russia-linked APT28 group has targeted or compromised a dozen government organizations and other French entities, the French Government states. In 2024, it was observed attacking OT organizations and linked to cyberattacks on 60 entities in Asia and […]
Pierluigi Paganini
Silent
10 months 3 weeks ago
cohenido
DARPA Highlights Critical Infrastructure Security Challenges
10 months 3 weeks ago
Leaders at federal research organizations DARPA, ARPA-I, and ARPA-H discussed the myriad obstacles in addressing critical infrastructure security at RSAC Conference 2025.
Alexander Culafi, Senior News Writer, Dark Reading
CVE-2025-3342 | codeprojects Online Restaurant Management System 1.0 /admin/payment_save.php ID sql injection
10 months 3 weeks ago
A vulnerability has been found in codeprojects Online Restaurant Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/payment_save.php. The manipulation of the argument ID leads to sql injection.
This vulnerability was named CVE-2025-3342. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-3345 | codeprojects Online Restaurant Management System 1.0 /admin/combo.php del sql injection
10 months 3 weeks ago
A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/combo.php. The manipulation of the argument del leads to sql injection.
This vulnerability is known as CVE-2025-3345. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com