Aggregator
CVE-2025-64498 | Enalean Tuleap Community Edition/Tuleap Enterprise Edition cross-site request forgery (GHSA-vxfh-h8p6-p5rg)
CVE-2025-64497 | Enalean Tuleap Community Edition/Tuleap Enterprise Edition authorization (GHSA-v6vm-6rxf-7p2v)
CVE-2025-66202 | withastro up to 5.15.7 non-canonical url paths for authorization decisions (GHSA-ggxq-hp9w-j794 / CNNVD-202512-1079)
CVE-2025-65962 | Enalean Tuleap Community Edition/Tuleap Enterprise Edition cross-site request forgery (GHSA-9hgc-cm68-rrgc / CNNVD-202512-1081)
CVE-2025-64760 | Enalean Tuleap Community Edition/Tuleap Enterprise Edition cross-site request forgery (GHSA-f2xv-x3g6-4j9p)
CVE-2025-64499 | Enalean Tuleap Community Edition/Tuleap Enterprise Edition cross-site request forgery (GHSA-9h47-jg7r-ww7x)
CVE-2025-14249 | code-projects Online Ordering System 1.0 /user_school.php product_id sql injection (EUVD-2025-201712)
CVE-2025-14250 | code-projects Online Ordering System 1.0 /user_contact.php Name sql injection (EUVD-2025-201729)
CVE-2025-67640 | Jenkins Git Client Plugin up to 6.4.0 os command injection (Nessus ID 278130)
CVE-2025-67641 | Jenkins Coverage Plugin up to 2.3054.ve1ff7b_a_a_123b_ REST API cross site scripting (Nessus ID 278130)
Микроволновка на высоте 18 км. NASA начало крупнейшую в истории США воздушную кампанию по картированию земных ресурсов
Teamwork is failing in slow motion and security feels it
Security leaders often track threats in code, networks, and policies. But a quieter risk is taking shape in the everyday work of teams. Collaboration is getting harder even as AI use spreads across the enterprise. That tension creates openings for mistakes, shadow tools, and uncontrolled data flows. A recent Forrester study shows how this break in teamwork forms and how leaders can respond before it grows. Teamwork is central to enterprise outcomes Forrester’s research found … More →
The post Teamwork is failing in slow motion and security feels it appeared first on Help Net Security.
CVE-2024-35970 | Linux Kernel up to 5.15.155/6.1.86/6.6.27/6.8.6 af_unix file descriptor consumption (WID-SEC-2025-2711)
CVE-2023-40130 | Google Android CallRedirectionProcessor.java onBindingDied permission (WID-SEC-2025-2711)
CVE-2025-59030 | PowerDNS up to 5.1.8/5.2.6/5.3.2 denial of service (EUVD-2025-201912 / Nessus ID 277742)
CVE-2025-66287 | WebKitGTK Web Content buffer overflow (EUVD-2025-201244 / Nessus ID 277489)
CVE-2025-13502 | WebKitGTK/WPE WebKit GLib Remote Inspector Server integer overflow (EUVD-2025-199556 / Nessus ID 276745)
CVE-2025-59029 | PowerDNS 5.3.0/5.3.1 denial of service (EUVD-2025-201911 / Nessus ID 277741)
DllShimmer: The Stealth Tool for Weaponizing DLL Hijacking without Detection
DllShimmer Weaponize DLL hijacking easily. Backdoor any function in any DLL without disrupting normal process operation. How it
The post DllShimmer: The Stealth Tool for Weaponizing DLL Hijacking without Detection appeared first on Penetration Testing Tools.