Aggregator
Microsoft’s December Security Update of High-Risk Vulnerability Notice for Multiple Products
Overview On December 10, NSFOCUS CERT detected that Microsoft released the December Security Update patch, which fixed 57 security issues involving widely used products such as Windows, Microsoft Office, Microsoft Exchange Server, Azure, etc., including high-risk vulnerability types such as privilege escalation and remote code execution. Among the vulnerabilities fixed by Microsoft’s monthly update this […]
The post Microsoft’s December Security Update of High-Risk Vulnerability Notice for Multiple Products appeared first on NSFOCUS, Inc., a global network and cyber security leader, protects enterprises and carriers from advanced cyber attacks..
The post Microsoft’s December Security Update of High-Risk Vulnerability Notice for Multiple Products appeared first on Security Boulevard.
CVE-2025-64898 | Adobe ColdFusion up to 2021.22/2023.16/2025.4 insufficiently protected credentials (apsb25-105 / CNNVD-202512-1749)
CVE-2025-61813 | Adobe ColdFusion up to 2021.22/2023.16/2025.4 xml external entity reference (apsb25-105 / CNNVD-202512-1750)
CVE-2025-61811 | Adobe ColdFusion up to 2021.22/2023.16/2025.4 access control (apsb25-105 / CNNVD-202512-1752)
CVE-2025-67499 | containernetworking plugins up to 1.8.x access control (GHSA-jv3w-x3r3-g6rm / Nessus ID 278132)
Chrome Targeted by Active In-the-Wild Exploit Tied to Undisclosed High-Severity Flaw
Typhon: 一种 pyjail 自动化绕过的思路及其粗略实现
CVE-2025-67738 | Webmin up to 2.599 Squid squid/cachemgr.cgi os command injection (EUVD-2025-202665 / WID-SEC-2025-2813)
CVE-2025-14522 | baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c upload_json.php imgFile unrestricted upload
CVE-2025-14521 | baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c download filename path traversal
CVE-2025-14520 | baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c delfile filename path traversal
CVE-2025-14519 | baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c advtext add cross site scripting
Больше не нужно кричать в баре. Придумали наушники, которые сами «выключают» лишний шум.
印度提议对 AI 公司用版权作品训练模型收取费用
Submit #702950: GitHub hfly 1.0 Stored Cross-Site Scripting [Accepted]
Submit #702949: GitHub hfly 1.0 Arbitrary file reading [Accepted]
Submit #702948: GitHub hfly 1.0 Arbitrary file deleteing [Accepted]
Submit #702943: GitHub hfly 1.0 Stored Cross-Site Scripting [Accepted]
40 open-source tools redefining how security teams secure the stack
Open source security software has become a key way for teams to get flexibility, transparency, and capability without licensing costs. The free tools in this roundup address problems security teams deal with, from managing large environments to catching misconfigurations and understanding how new technologies change threat exposure. Aegis Authenticator: Free, open-source 2FA app for Android Aegis Authenticator is an open-source 2FA app for Android that helps you manage login codes for your online accounts. Arkime: … More →
The post 40 open-source tools redefining how security teams secure the stack appeared first on Help Net Security.