Aggregator
专题·漏洞生态 | 人工智能赋能的智能化漏洞治理研究
Meer militaire medische professionals na 25-jarige ‘ziekenhuisrelatie’
CVE-2025-14538 | yangshare warehouseManager 仓库管理系统 1.1.0 CustomerManageHandler.java addCustomer Name cross site scripting (ID9NAU)
Submit #703743: yangshare 技术杨工 WarehouseManager 仓库管理系统 v1.1.0 - Remove CAPTCHA Authentication Bypass Issues [Duplicate]
Submit #703736: gitee WarehouseManager v1.1.0 - Remove CAPTCHA Improper Neutralization of Alternate XSS Syntax [Accepted]
【安全圈】安全公司调查全球最大容器镜像库 Docker Hub,发现 10000+ 镜像泄露敏感密钥
【安全圈】Windows Defender 防火墙服务漏洞可致攻击者泄露敏感数据
【安全圈】GitLab高危XSS漏洞(CVE-2025-12716)可通过恶意Wiki页面劫持用户会话
【安全圈】“信息贩子”终落网,“捞金欲梦”终成空
Бой на скорости 510 км/ч: КСИР показал дрон, работающий на пределе возможностей малой авиации
GitLab Patches Multiple Vulnerabilities that Allows Attackers to Trigger XSS and DoS Attack
Critical security patches on December 10, 2025, addressing ten significant vulnerabilities across its Community Edition and Enterprise Edition platforms. GitLab has released updated versions 18.6.2, 18.5.4, and 18.4.6 to address multiple high-severity security issues. High-Severity Threats Identified Four vulnerabilities received high-severity ratings and require immediate remediation. The vulnerability landscape includes four high-severity flaws, five medium-severity […]
The post GitLab Patches Multiple Vulnerabilities that Allows Attackers to Trigger XSS and DoS Attack appeared first on Cyber Security News.
The Year in Review 2025: AI, APIs, and a Whole Lot of Audacity
WIRTE Leverages AshenLoader Sideloading to Install the AshTag Espionage Backdoor
High-Severity Jenkins Vulnerability Allows Unauthenticated DoS via HTTP CLI
Patches released by Jenkins address a significant denial-of-service (DoS) vulnerability affecting millions of organizations. That rely on the popular automation server for continuous integration and deployment pipelines. A high-severity vulnerability in Jenkins versions 2.540 and earlier (LTS 2.528.2 and earlier). Enables unauthenticated attackers to trigger denial of service attacks through the HTTP-based command-line interface. Vulnerability […]
The post High-Severity Jenkins Vulnerability Allows Unauthenticated DoS via HTTP CLI appeared first on Cyber Security News.