Aggregator
DEF CON 32 – Fitness of Physical Red Teamers
10 months ago
Authors/Presenters: Lucas Rooyakkers & Billy Graydon
Our sincere appreciation to DEF CON, and the Authors/Presenters for publishing their erudite DEF CON 32 content. Originating from the conference’s events located at the Las Vegas Convention Center; and via the organizations YouTube channel.
The post DEF CON 32 – Fitness of Physical Red Teamers appeared first on Security Boulevard.
Marc Handelman
SecWiki News 2025-02-15 Review
10 months ago
今日暂未更新资讯~
更多最新文章,请访问SecWiki
更多最新文章,请访问SecWiki
CVE-2025-1360 | Internet Web Solutions Sublime CRM up to 20250207 HTTP POST Request /crm/inicio.php msg_to cross site scripting
10 months ago
A vulnerability, which was classified as problematic, was found in Internet Web Solutions Sublime CRM up to 20250207. Affected is an unknown function of the file /crm/inicio.php of the component HTTP POST Request Handler. The manipulation of the argument msg_to leads to cross site scripting.
This vulnerability is traded as CVE-2025-1360. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
Submit #496469: Internet Web Solutions Sublime CRM N/A Cross Site Scripting [Accepted]
10 months ago
Submit #496469 / VDB-295968
6h4ack
CVE-2025-1359 | SIAM Industria de Automação e Monitoramento 2.0 /qrcode.jsp url cross site scripting
10 months ago
A vulnerability, which was classified as problematic, has been found in SIAM Industria de Automação e Monitoramento SIAM 2.0. This issue affects some unknown processing of the file /qrcode.jsp. The manipulation of the argument url leads to cross site scripting.
The identification of this vulnerability is CVE-2025-1359. The attack may be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
Meta 将建造世界最长的海底光缆
10 months ago
Meta 宣布了长 5 万公里的海底光缆项目 Waterworth,这将是世界最长的海底光缆项目,耗资数十亿美元,连接美国、巴西、印度、南非等重要地区。Waterworth 将使用 24 对光纤,将在沿海高风险地区使用新的铺设技术,以防止船锚等风险。Meta 目前拥有 16 个海底光缆网络,Waterworth 将是该公司首个全资拥有的全球光缆系统。
CVE-2025-1358 | Pix Software Vivaz 6.0.10 cross-site request forgery
10 months ago
A vulnerability classified as problematic was found in Pix Software Vivaz 6.0.10. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2025-1358. The attack can be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-1357 | Seventh D-Guard up to 20250206 HTTP GET Request path traversal
10 months ago
A vulnerability classified as problematic has been found in Seventh D-Guard up to 20250206. This affects an unknown part of the component HTTP GET Request Handler. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2025-1357. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
It is recommended to apply restrictive firewalling.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
Submit #496171: SIAM Industria de Automação e Monitoramento Ltda. SIAM 2.0 Reflected Cross-Site Scripting [Accepted]
10 months ago
Submit #496171 / VDB-295967
Stux
CVE-2025-1356 | needyamin Library Card System 1.0 card.php id sql injection
10 months ago
A vulnerability was found in needyamin Library Card System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file card.php. The manipulation of the argument id leads to sql injection.
This vulnerability is handled as CVE-2025-1356. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-1355 | needyamin Library Card System 1.0 Add Picture /signup.php unrestricted upload
10 months ago
A vulnerability was found in needyamin Library Card System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /signup.php of the component Add Picture. The manipulation leads to unrestricted upload.
This vulnerability is known as CVE-2025-1355. The attack can be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
Submit #496141: Pix Software Vivaz 6.0.10 Cross-Site Request Forgery [Accepted]
10 months ago
Submit #496141 / VDB-295966
Stux
Submit #496137: Seventh D-Guard NA Path Traversal [Accepted]
10 months ago
Submit #496137 / VDB-295965
c4ng4c3ir0
CVE-2025-1354 | Asus RT-N12E 2.0.0.19 sysinfo.asp SSID cross site scripting
10 months ago
A vulnerability was found in Asus RT-N12E 2.0.0.19. It has been classified as problematic. Affected is an unknown function of the file sysinfo.asp. The manipulation of the argument SSID leads to cross site scripting.
This vulnerability is traded as CVE-2025-1354. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
Submit #496087: Needyamin Library-Card-System 1.0 SQL Injection [Accepted]
10 months ago
Submit #496087 / VDB-295964
MaloyRoyOrko
Submit #496075: Needyamin Library-Card-System 1.0 Unrestricted File Upload [Accepted]
10 months ago
Submit #496075 / VDB-295963
MaloyRoyOrko
Attackers exploit recently disclosed Palo Alto Networks PAN-OS firewalls bug
10 months ago
Threat actors are exploiting a recently disclosed vulnerability, tracked as CVE-2025-0108, in Palo Alto Networks PAN-OS firewalls. Researchers warn that threat actors are exploiting a recently disclosed vulnerability, tracked as CVE-2025-0108, in Palo Alto Networks PAN-OS firewalls. The Shadowserver Foundation researchers observed several CVE-2025-0108 attempts since 4 am UTC 2024-02-13 in their honeypots. The experts said […]
Pierluigi Paganini
Submit #496013: ASUS RT-N12E 2.0.0.19 Cross Site Scripting [Accepted]
10 months ago
Submit #496013 / VDB-295962
Fergod
CVE-2025-1353 | Kong Insomnia up to 10.3.0 profapi.dll untrusted search path
10 months ago
A vulnerability was found in Kong Insomnia up to 10.3.0 and classified as critical. This issue affects some unknown processing in the library profapi.dll. The manipulation leads to untrusted search path.
The identification of this vulnerability is CVE-2025-1353. An attack has to be approached locally. There is no exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com