Aggregator
PinTheft Linux Vulnerability Let Attackers Gain Root Access – PoC Released
4 weeks 1 day ago
A proof-of-concept (PoC) exploit was published for a new Linux Local Privilege Escalation (LPE) vulnerability dubbed “PinTheft.” Discovered by Aaron Esau of the V12 security team, the flaw allows local attackers to gain root access by exploiting an RDS zerocopy double-free bug. A kernel patch is currently available, prompting the researchers to release their PoC […]
The post PinTheft Linux Vulnerability Let Attackers Gain Root Access – PoC Released appeared first on Cyber Security News.
Guru Baran
Microsoft security advisory (AV26-489)
4 weeks 1 day ago
Canadian Centre for Cyber Security
CVE-2023-5637 | ArslanSoft Education Portal up to 1.0 Setting unrestricted upload
4 weeks 1 day ago
A vulnerability described as problematic has been identified in ArslanSoft Education Portal up to 1.0. The impacted element is an unknown function of the component Setting Handler. The manipulation results in unrestricted upload.
This vulnerability is cataloged as CVE-2023-5637. The attack must originate from the local network. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2023-5636 | ArslanSoft Education Portal up to 1.0 unrestricted upload
4 weeks 1 day ago
A vulnerability, which was classified as critical, has been found in ArslanSoft Education Portal up to 1.0. Affected is an unknown function. Performing a manipulation results in unrestricted upload.
This vulnerability is reported as CVE-2023-5636. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2023-5806 | Mergen Quality Management System up to 1.1 sql injection
4 weeks 1 day ago
A vulnerability, which was classified as critical, has been found in Mergen Quality Management System up to 1.1. The affected element is an unknown function. This manipulation causes sql injection.
This vulnerability is registered as CVE-2023-5806. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2023-7081 | POSTAHSİL Online Payment System prior 14.02.2024 sql injection
4 weeks 1 day ago
A vulnerability marked as critical has been reported in POSTAHSİL Online Payment System. This affects an unknown function. The manipulation leads to sql injection.
This vulnerability is listed as CVE-2023-7081. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2023-7103 | ZKSoftware Biometric Security Solutions UFace 5 up to 12022024 authentication bypass
4 weeks 1 day ago
A vulnerability labeled as very critical has been found in ZKSoftware Biometric Security Solutions UFace 5 up to 12022024. This issue affects some unknown processing. Such manipulation leads to authentication bypass by primary weakness.
This vulnerability is documented as CVE-2023-7103. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2023-6153 | TeoSOFT TeoBASE up to 20240327 authentication bypass
4 weeks 1 day ago
A vulnerability was found in TeoSOFT TeoBASE up to 20240327. It has been classified as very critical. The impacted element is an unknown function. The manipulation leads to authentication bypass by primary weakness.
This vulnerability is documented as CVE-2023-6153. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2023-6173 | TeoSOFT TeoBASE up to 27032024 sql injection
4 weeks 1 day ago
A vulnerability was found in TeoSOFT TeoBASE up to 27032024. It has been declared as critical. This affects an unknown function. The manipulation results in sql injection.
This vulnerability is reported as CVE-2023-6173. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2023-6437 | TP-Link EX20v AX1800/Archer C5v AC1200/TD-W9970/TD-W9970v3 os command injection
4 weeks 1 day ago
A vulnerability marked as critical has been reported in TP-Link EX20v AX1800, Archer C5v AC1200, TD-W9970 and TD-W9970v3 up to 2024.03.28. This vulnerability affects unknown code. The manipulation leads to os command injection.
This vulnerability is uniquely identified as CVE-2023-6437. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2023-6191 | Egehan Security WebPDKS up to 20240329 sql injection
4 weeks 1 day ago
A vulnerability, which was classified as critical, has been found in Egehan Security WebPDKS up to 20240329. This affects an unknown part. The manipulation leads to sql injection.
This vulnerability is listed as CVE-2023-6191. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2023-6047 | Algoritim E-Commerce Software up to 20240329 cross site scripting
4 weeks 1 day ago
A vulnerability was found in Algoritim E-Commerce Software up to 20240329 and classified as problematic. Impacted is an unknown function. Such manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2023-6047. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2023-6522 | ExtremePacs Extreme XDS up to 3913 privileges management
4 weeks 1 day ago
A vulnerability, which was classified as critical, has been found in ExtremePacs Extreme XDS up to 3913. Affected by this issue is some unknown functionality. Performing a manipulation results in improper privilege management.
This vulnerability is identified as CVE-2023-6522. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2023-6523 | ExtremePacs Extreme XDS up to 3914 authorization
4 weeks 1 day ago
A vulnerability, which was classified as very critical, was found in ExtremePacs Extreme XDS up to 3914. This affects an unknown part. Executing a manipulation can lead to authorization bypass.
This vulnerability is tracked as CVE-2023-6523. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
vuldb.com
告别正则堆砌:一种基于信息熵与词汇占比的 JS 硬编码高精度发现方案
4 weeks 1 day ago
基于多维度统计特征的轻量级硬编码密钥检测算法,通过归一化香农熵、语义占比及动态阈值策略,在不依赖外部模型与网络的前提下,实现前端代码中敏感信息的高召回识别。
重大安全信号藏在这场国际会议的“行动指南”里
4 weeks 1 day ago
易安联零信任
Microsoft Open-Sources RAMPART and Clarity to Secure AI Agents During Development
4 weeks 1 day ago
Microsoft has unveiled two new open-source tools called RAMPART and Clarity to assist developers in better testing the security of artificial intelligence (AI) agents.
RAMPART, short for Risk Assessment and Measurement Platform for Agentic Red Teaming, functions as a Pytest-native safety and security testing framework for writing and running safety and security tests for AI agents, covering
The Hacker News
契约锁电子签章系统登录接口组合漏洞挖掘
4 weeks 1 day ago
在契约锁电子签章系统的安全审计中,通过分析官方补丁包发现一处逻辑漏洞:短信验证码校验可被绕过,导致任意用户注册。尽管登录环节设置了短信验证码及多项参数校验,但由于短信发送条件判断存在歧义,且注册与登录流程过度耦合,形成了一条完整的攻击路径。
2026数字中国创新大赛网络安全赛道部分wp
4 weeks 1 day ago
本文是有关2026数字中国创新大赛网络安全赛道(北京赛区)部分wp