Aggregator
Secure Your Spot at RSAC 2026 Conference
1 month 2 weeks hence
CVE-2024-37301 | adfinis document-merge-service up to 6.5.1 Template special elements used in a template engine (GHSA-v5gf-r78h-55q6)
55 minutes 21 seconds ago
A vulnerability was found in adfinis document-merge-service up to 6.5.1 and classified as critical. This vulnerability affects unknown code of the component Template Handler. The manipulation results in improper neutralization of special elements used in a template engine.
This vulnerability is reported as CVE-2024-37301. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2025-22890 | Humming Heads Defense Platform Home Edition up to 3.9.51.x unnecessary privileges
55 minutes 21 seconds ago
A vulnerability identified as critical has been detected in Humming Heads Defense Platform Home Edition up to 3.9.51.x. This affects an unknown part. This manipulation causes execution with unnecessary privileges.
This vulnerability is registered as CVE-2025-22890. The attack needs to be launched locally. No exploit is available.
vuldb.com
CVE-2025-23236 | Humming Heads Defense Platform Home Edition up to 3.9.51.x buffer overflow
55 minutes 21 seconds ago
A vulnerability labeled as critical has been found in Humming Heads Defense Platform Home Edition up to 3.9.51.x. This vulnerability affects unknown code. Such manipulation leads to buffer overflow.
This vulnerability is documented as CVE-2025-23236. The attack needs to be performed locally. There is not any exploit available.
vuldb.com
CVE-2025-20094 | Humming Heads Defense Platform Home Edition up to 3.9.51.x Message shatter
55 minutes 21 seconds ago
A vulnerability described as critical has been identified in Humming Heads Defense Platform Home Edition up to 3.9.51.x. Impacted is an unknown function of the component Message Handler. Executing a manipulation can lead to unprotected windows messaging channel.
This vulnerability appears as CVE-2025-20094. The attack requires local access. There is no available exploit.
vuldb.com
CVE-2025-22894 | Humming Heads Defense Platform Home Edition up to 3.9.51.x Message shatter
55 minutes 21 seconds ago
A vulnerability classified as problematic has been found in Humming Heads Defense Platform Home Edition up to 3.9.51.x. The affected element is an unknown function of the component Message Handler. The manipulation leads to unprotected windows messaging channel.
This vulnerability is traded as CVE-2025-22894. An attack has to be approached locally. There is no exploit available.
vuldb.com
CVE-2022-50536 | Linux Kernel up to 6f226ffe4458ea3b8c33287cb8c86f87dc198dce sock_put use after free (WID-SEC-2025-2229)
55 minutes 21 seconds ago
A vulnerability labeled as critical has been found in Linux Kernel up to 6f226ffe4458ea3b8c33287cb8c86f87dc198dce. Impacted is the function sock_put. Executing a manipulation can lead to use after free.
This vulnerability is tracked as CVE-2022-50536. The attack is only possible within the local network. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2022-50537 | Linux Kernel up to 5.10.162/5.15.85/6.0.15/6.1.1 rpi_firmware_probe memory leak (WID-SEC-2025-2229)
55 minutes 21 seconds ago
A vulnerability was found in Linux Kernel up to 5.10.162/5.15.85/6.0.15/6.1.1. It has been rated as critical. Affected by this vulnerability is the function rpi_firmware_probe. This manipulation causes memory leak.
This vulnerability is handled as CVE-2022-50537. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2024-23334 | aio-libs aiohttp up to 3.9.1 Symbolic Links path traversal (GHSA-5h86-8mv2-jq9f / Nessus ID 212515)
55 minutes 21 seconds ago
A vulnerability identified as critical has been detected in aio-libs aiohttp up to 3.9.1. This affects an unknown function of the component Symbolic Links Handler. The manipulation leads to path traversal.
This vulnerability is traded as CVE-2024-23334. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2025-24514 | Kubernetes ingress-nginx up to 1.11.4/1.12.0 IngressNightmare input validation (Issue 131006 / WID-SEC-2025-0629)
55 minutes 21 seconds ago
A vulnerability was found in Kubernetes ingress-nginx up to 1.11.4/1.12.0 and classified as very critical. This issue affects some unknown processing. Such manipulation leads to improper input validation.
This vulnerability is referenced as CVE-2025-24514. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2025-1097 | Kubernetes ingress-nginx up to 1.11.4/1.12.0 auth-tls-match-cn Ingress Annotation IngressNightmare input validation (Issue 131007 / Nessus ID 233357)
55 minutes 21 seconds ago
A vulnerability classified as very critical was found in Kubernetes ingress-nginx up to 1.11.4/1.12.0. Affected by this vulnerability is an unknown functionality of the component auth-tls-match-cn Ingress Annotation. Executing a manipulation can lead to improper input validation.
This vulnerability is handled as CVE-2025-1097. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2025-1098 | Kubernetes ingress-nginx up to 1.11.4/1.12.0 Ingress Annotation IngressNightmare input validation (Issue 131008 / Nessus ID 233357)
55 minutes 21 seconds ago
A vulnerability, which was classified as very critical, has been found in Kubernetes ingress-nginx up to 1.11.4/1.12.0. Affected by this issue is some unknown functionality of the component Ingress Annotation Handler. The manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2025-1098. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
记一次EDU证书站挖掘
2 hours 45 minutes ago
记一次EDU证书站边缘资产挖掘
Dokploy 漏洞挖掘记录(2RCE+1 目录穿越)
2 hours 48 minutes ago
Dokploy 漏洞挖掘记录(2RCE+1 目录穿越)
Splunk security advisory (AV26-088)
2 hours 48 minutes ago
Canadian Centre for Cyber Security
CrewAI FileWriterTool + PickleHandler 组合漏洞链 RCE 漏洞分析
2 hours 48 minutes ago
CrewAI FileWriterTool + PickleHandler 组合漏洞链 RCE 漏洞分析
Raw Socket 隐蔽通信实战:从 0 实现 ICMP 隧道
2 hours 48 minutes ago
在渗透测试和内网穿透场景中,ICMP 隧道是一种经典的隐蔽通信手段。市面上已经有不少成熟工具,比如 icmpsh、PingTunnel、icmptunnel 等,它们功能完善、开箱即用。但在实际使用中,我逐渐发现了一个问题:这些工具都是"黑盒"——你能用它们完成任务,却很难理解它们是如何工作的,更无法根据实际需求定制协议细节或调整流量特征。
结合真实案例讲解OWASP Top 10 for Agentic Applications for 2026
2 hours 49 minutes ago
结合自己发现和公开的案例来讲解这十大风险
第四届阿里CTF官方writeup
2 hours 49 minutes ago
第四届阿里CTF官方writeup