Aggregator
CVE-2025-8965 | linlinjava litemall up to 1.8.0 Endpoint AdminStorageController.java create File unrestricted upload
CVE-2025-9138 | Scada-LTS 2.7.8.1 pointHierarchy/new/ Title cross site scripting (EUVD-2025-25165)
CVE-2025-9139 | Scada-LTS 2.7.8.1 WatchListDwr.init.dwr information disclosure
CVE-2025-9143 | Scada-LTS 2.7.8.1 mailing_lists.shtm name/userList/address cross site scripting (EUVD-2025-25186)
CVE-2025-9144 | Scada-LTS 2.7.8.1 publisher_edit.shtm Name cross site scripting (EUVD-2025-25187)
CVE-2025-8974 | linlinjava litemall up to 1.8.0 JSON Web Token JwtHelper.java SECRET hard-coded credentials (Issue 568)
CVE-2025-7729 | Scada-LTS up to 2.7.8.1 usersProfiles.shtm Username cross site scripting (EUVD-2025-21755)
CVE-2025-7728 | Scada-LTS up to 2.7.8.1 users.shtm Username cross site scripting
openSUSE 将禁用 bcachefs
Submit #644037: Emlog Emlog Pro 2.5.19 Cross Site Scripting [Duplicate]
CVE-2025-10274 | erjinzhi 10OA 1.0 /trial/mvc/item Name cross site scripting
CVE-2025-10273 | erjinzhi 10OA 1.0 /view/file.aspx File path traversal
CVE-2025-10272 | erjinzhi 10OA 1.0 /trial/mvc/catalogue Name cross site scripting
CVE-2025-10271 | erjinzhi 10OA 1.0 /trial/mvc/finder Name cross site scripting
Why Cyber Resilience Starts With People, Not Just Tools
Fletcher Heisler, CEO of Authentik Security, covers the evolution of Identity and Access Management (IAM) and its significance in modern security. Fletcher also emphasizes a careful approach to AI integration, prioritizing human coding. Heisler, who has been working in tech since his early days experimenting with security in less-than-sanctioned ways, shares his journey into the..
The post Why Cyber Resilience Starts With People, Not Just Tools appeared first on Security Boulevard.
«Я выиграл 250 тысяч!» А потом потерял ещё больше. Как работает масштабная афера в Telegram
Submit #643076: Emlog Emlog Pro 2.5.19 Cross Site Scripting [Duplicate]
Akira
You must login to view this content
L7 DDoS Botnet Hijacked 5.76M Devices to Launch Massive Attacks
In early March 2025, security teams first observed an unprecedented L7 DDoS botnet targeting web applications across multiple sectors. The botnet, rapidly expanding from an initial 1.33 million compromised devices, employed HTTP GET floods to exhaust server resources and circumvent traditional rate limiting. By mid-May, the threat escalated as the botnet grew to 4.6 million […]
The post L7 DDoS Botnet Hijacked 5.76M Devices to Launch Massive Attacks appeared first on Cyber Security News.