Aggregator
[80]个反序列化漏洞全景合集 (3) | 介绍一个 ViewState 反序列化不常见的知识点
5 months 3 weeks ago
当前环境出现异常,需完成验证后方可继续访问。
[80]个反序列化漏洞全景合集 (2) | 回答一个 .NET 反序列化漏洞载荷的问题
5 months 3 weeks ago
当前环境异常,请完成验证后继续访问。
[80]个反序列化漏洞全景系列 (1) | 一个大多数人都容易忽视的 Ysoserial.Net 使用误区
5 months 3 weeks ago
当前环境出现异常,请完成验证后继续访问。
INC
5 months 3 weeks ago
You must login to view this content
cohenido
INC
5 months 3 weeks ago
You must login to view this content
cohenido
【2026合作伙伴巡礼】与您分享平航Telegram取证一站式解决方案!
5 months 3 weeks ago
有些事不管多难是一定要坚持做的..
Qilin
5 months 3 weeks ago
You must login to view this content
cohenido
Three Critical Facts About Cyber Risk Management
5 months 3 weeks ago
For CISOs responsible for cyber risk management, these three insights will help build a strong and reliable foundation for your proactive security strategy.
An MDR Analysis of the AMOS Stealer Campaign Targeting macOS via ‘Cracked’ Apps
5 months 3 weeks ago
Trend™ Research analyzed a campaign distributing Atomic macOS Stealer (AMOS), a malware family targeting macOS users. Attackers disguise the malware as “cracked” versions of legitimate apps, luring users into installation.
Buddy Tancio
25,000 IPs Scanned Cisco ASA Devices — New Vulnerability Potentially Incoming
5 months 3 weeks ago
GreyNoise observed two scanning surges against Cisco Adaptive Security Appliance (ASA) devices in late August including more than 25,000 unique IPs in a single burst. This activity represents a significant elevation above baseline, typically registering at less than 500 IPs per day.
为什么需要企业级智能体开发平台
5 months 3 weeks ago
成熟平台是智能体在企业中成功落地的关键。
CVE-2025-8612 | AOMEI Backupper Workstation link following
5 months 3 weeks ago
A vulnerability was found in AOMEI Backupper Workstation and classified as critical. Affected by this issue is some unknown functionality. Executing manipulation can lead to link following.
This vulnerability appears as CVE-2025-8612. The attack requires local access. There is no available exploit.
vuldb.com
CVE-2025-57811 | Craft CMS up to 4.16.5/5.8.6 Twig special elements used in a template engine
5 months 3 weeks ago
A vulnerability was found in Craft CMS up to 4.16.5/5.8.6 and classified as problematic. This impacts an unknown function of the component Twig Handler. Such manipulation leads to improper neutralization of special elements used in a template engine.
This vulnerability is traded as CVE-2025-57811. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-9491 | Microsoft Windows LNK File clickjacking (ZDI-25-148)
5 months 3 weeks ago
A vulnerability was found in Microsoft Windows. It has been classified as problematic. This impacts an unknown function of the component LNK File Handler. The manipulation leads to clickjacking.
This vulnerability is listed as CVE-2025-9491. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2025-7776 | Citrix NetScaler ADC/NetScaler Gateway up to 37.240/47.47/55.329/59.21 memory corruption (CTX694938 / Nessus ID 255232)
5 months 3 weeks ago
A vulnerability marked as critical has been reported in Citrix NetScaler ADC and NetScaler Gateway up to 37.240/47.47/55.329/59.21. Affected by this vulnerability is an unknown functionality of the component Gateway. This manipulation causes memory corruption.
The identification of this vulnerability is CVE-2025-7776. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-9433 | mtons mblog up to 3.5.0 Admin Panel /admin/user/list Name cross site scripting (ICPMMW)
5 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in mtons mblog up to 3.5.0. The impacted element is an unknown function of the file /admin/user/list of the component Admin Panel. Performing manipulation of the argument Name results in cross site scripting.
This vulnerability was named CVE-2025-9433. The attack may be initiated remotely. In addition, an exploit is available.
vuldb.com
CVE-2025-9461 | diyhi bbs up to 6.8 File Compression FilePackageManageAction.java idGroup information disclosure
5 months 3 weeks ago
A vulnerability identified as problematic has been detected in diyhi bbs up to 6.8. The impacted element is an unknown function of the file src/main/java/cms/web/action/filePackage/FilePackageManageAction.java of the component File Compression Handler. This manipulation of the argument idGroup causes information disclosure.
This vulnerability is registered as CVE-2025-9461. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
vuldb.com
CVE-2025-8447 | GitHub Enterprise Server up to 3.14.16/3.15.11/3.16.7/3.17.4 Compare/Diff authorization (WID-SEC-2025-1903)
5 months 3 weeks ago
A vulnerability has been found in GitHub Enterprise Server up to 3.14.16/3.15.11/3.16.7/3.17.4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Compare/Diff. Performing manipulation results in authorization bypass.
This vulnerability is reported as CVE-2025-8447. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2025-1142 | IBM Edge Application Manager 4.5 server-side request forgery
5 months 3 weeks ago
A vulnerability has been found in IBM Edge Application Manager 4.5 and classified as critical. This impacts an unknown function. The manipulation leads to server-side request forgery.
This vulnerability is listed as CVE-2025-1142. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
vuldb.com