Aggregator
CVE-2025-3413 | opplus springboot-admin up to a2d5310f44fd46780a8686456cf2f9001ab8f024 SysGeneratorController.java code Tables deserialization
8 months 3 weeks ago
A vulnerability has been found in opplus springboot-admin up to a2d5310f44fd46780a8686456cf2f9001ab8f024 and classified as critical. Affected by this vulnerability is the function code of the file SysGeneratorController.java. The manipulation of the argument Tables leads to deserialization.
This vulnerability is known as CVE-2025-3413. The attack can be launched remotely. Furthermore, there is an exploit available.
This product does not use versioning. This is why information about affected and unaffected releases are unavailable.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-3412 | mymagicpower AIAS 20250308 InferController.java url server-side request forgery
8 months 3 weeks ago
A vulnerability, which was classified as critical, was found in mymagicpower AIAS 20250308. Affected is an unknown function of the file 2_training_platform/train-platform/src/main/java/top/aias/training/controller/InferController.java. The manipulation of the argument url leads to server-side request forgery.
This vulnerability is traded as CVE-2025-3412. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-3411 | mymagicpower AIAS 20250308 AsrController.java url server-side request forgery
8 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in mymagicpower AIAS 20250308. This issue affects some unknown processing of the file 3_api_platform/api-platform/src/main/java/top/aias/platform/controller/AsrController.java. The manipulation of the argument url leads to server-side request forgery.
The identification of this vulnerability is CVE-2025-3411. The attack may be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-3410 | mymagicpower AIAS 20250308 LocalStorageController.java File unrestricted upload
8 months 3 weeks ago
A vulnerability classified as critical was found in mymagicpower AIAS 20250308. This vulnerability affects unknown code of the file training_platform/train-platform/src/main/java/top/aias/training/controller/LocalStorageController.java. The manipulation of the argument File leads to unrestricted upload.
This vulnerability was named CVE-2025-3410. The attack can be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
PoisonSeed Campaign uses stolen email credentials to spread crypto seed scams and and empty wallets
8 months 3 weeks ago
A campaign named PoisonSeed uses stolen CRM and bulk email credentials to send crypto seed scams, aiming to empty victims’ digital wallets. Silent Push researchers warn of a malicious PoisonSeed campaign that uses stolen CRM and bulk email provider credentials to send crypto seed phrase spam. Victims are tricked into importing compromised seed phrases into […]
Pierluigi Paganini
Голод на чипы в $16 млрд: китайские гиганты сметают со складов ускорители NVIDIA H20
8 months 3 weeks ago
Как компания балансирует между санкциями США и интересами клиентов?
Submit #545374: https://github.com/opplus/springboot-admin springboot-admin 1 RCE [Accepted]
8 months 3 weeks ago
Submit #545374 / VDB-303691
maple14711
Скопировать, вставить, опомниться: хакеры взламывают отели в два клика
8 months 3 weeks ago
Доверие к Booking.com — ахиллесова пята безопасности гостиничного бизнеса.
Submit #544289: AIAS 20250308 Server-Side Request Forgery [Accepted]
8 months 3 weeks ago
Submit #544289 / VDB-303690
Submit #544288: AIAS 20250308 Server-Side Request Forgery [Accepted]
8 months 3 weeks ago
Submit #544288 / VDB-303689
Submit #544243: aias 20250308 Incomplete Identification of Uploaded File Variables [Accepted]
8 months 3 weeks ago
Submit #544243 / VDB-303688
CVE-2025-3409 | Nothings stb up to f056911 stb_include_string path_to_includes stack-based overflow
8 months 3 weeks ago
A vulnerability classified as critical has been found in Nothings stb up to f056911. This affects the function stb_include_string. The manipulation of the argument path_to_includes leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2025-3409. It is possible to initiate the attack remotely. There is no exploit available.
This product does not use versioning. This is why information about affected and unaffected releases are unavailable.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-3408 | Nothings stb up to f056911 stb_dupreplace integer overflow
8 months 3 weeks ago
A vulnerability was found in Nothings stb up to f056911. It has been rated as critical. Affected by this issue is the function stb_dupreplace. The manipulation leads to integer overflow.
This vulnerability is handled as CVE-2025-3408. The attack may be launched remotely. There is no exploit available.
Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-3407 | Nothings stb up to f056911 stbhw_build_tileset_from_image h_count/v_count out-of-bounds
8 months 3 weeks ago
A vulnerability was found in Nothings stb up to f056911. It has been declared as critical. Affected by this vulnerability is the function stbhw_build_tileset_from_image. The manipulation of the argument h_count/v_count leads to out-of-bounds read.
This vulnerability is known as CVE-2025-3407. The attack can be launched remotely. There is no exploit available.
This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-3406 | Nothings stb up to f056911 Header Array stbhw_build_tileset_from_image w out-of-bounds
8 months 3 weeks ago
A vulnerability was found in Nothings stb up to f056911. It has been classified as problematic. Affected is the function stbhw_build_tileset_from_image of the component Header Array Handler. The manipulation of the argument w leads to out-of-bounds read.
This vulnerability is traded as CVE-2025-3406. It is possible to launch the attack remotely. There is no exploit available.
This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
【安全圈】警惕!虚假通行费短信借 Lucid 平台窃取登录信息
8 months 3 weeks ago
关键词网络钓鱼近几个月来,一场针对移动用户的欺骗性网络钓鱼活动显著加剧,该活动以虚假的未支付通行费通知为诱饵,
【安全圈】新的 Sakura RAT 出现在 GitHub 上,成功逃避 AV 和 EDR 保护
8 months 3 weeks ago
关键词网络攻击一种名为 Sakura 的新型远程访问木马 (RAT) 已在 GitHub 上发布。
【安全圈】ChatGPT-4o五分钟生成假护照:传统验证机制面临危机
8 months 3 weeks ago
Security Theater: Vanity Metrics Keep You Busy - and Exposed
8 months 3 weeks ago
After more than 25 years of mitigating risks, ensuring compliance, and building robust security programs for Fortune 500 companies, I’ve learned that looking busy isn’t the same as being secure.
It’s an easy trap for busy cybersecurity leaders to fall into. We rely on metrics that tell a story of the tremendous efforts we’re expending - how many vulnerabilities we patched, how fast we
The Hacker News