Aggregator
Secure Your Spot at RSAC 2026 Conference
1 day 5 hours hence
CVE-2024-21320
1 hour 5 minutes ago
Currently trending CVE - Hype Score: 5 - Windows Themes Spoofing Vulnerability
CVE-2026-21962
1 hour 5 minutes ago
Currently trending CVE - Hype Score: 8 - Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, ...
CVE-2025-43520
1 hour 5 minutes ago
Currently trending CVE - Hype Score: 23 - A memory corruption issue was addressed with improved memory handling. This issue is fixed in watchOS 26.1, iOS 18.7.2 and iPadOS 18.7.2, macOS Tahoe 26.1, visionOS 26.1, tvOS 26.1, macOS Sonoma 14.8.2, macOS Sequoia 15.7.2, iOS 26.1 and iPadOS 26.1. A malicious application may ...
CVE-2025-24257
1 hour 5 minutes ago
Currently trending CVE - Hype Score: 11 - An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to cause unexpected system termination or write kernel memory.
CVE-2025-66376
1 hour 5 minutes ago
Currently trending CVE - Hype Score: 6 - Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
CVE-2025-55184
1 hour 5 minutes ago
Currently trending CVE - Hype Score: 18 - A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The ...
CVE-2025-55182
1 hour 5 minutes ago
Currently trending CVE - Hype Score: 1 - A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code ...
CVE-2025-9961
1 hour 5 minutes ago
Currently trending CVE - Hype Score: 7 - An authenticated attacker may remotely execute arbitrary code via the CWMP binary on the devices AX10 and AX1500.
The exploit can only be conducted via a Man-In-The-Middle (MITM) attack.
This issue affects AX10 V1/V1.2/V2/V2.6/V3/V3.6: before 1.2.1; AX1500 ...
CVE-2025-6218
1 hour 5 minutes ago
Currently trending CVE - Hype Score: 17 - RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a ...
CVE-2025-31324
1 hour 5 minutes ago
Currently trending CVE - Hype Score: 8 - SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, ...
某公交系统漏洞分析
4 hours 23 minutes ago
HisModules ERP 系统存在的严重安全缺陷
FLYTEAM第一届新年CTF Web方向部分wp
4 hours 27 minutes ago
ez_SSTI打法1看代码:碰见这种题目,先看路由以及对应函数名称,看他实现了什么功能目标是/ssti路由下的模板渲染漏洞,要求用户不是admin且钱大于等于10000元怎么得到非admin用户呢?就要用到注册路由/register,注意输入格式那么金额的问题怎么办呢,我们再看看别的路由漏洞主要出现在这里:非admin用户给别人转账不花钱,且转账不用知道密码,那思路就明确了:用admin给刚刚新建
2026软件系统安全赛 writeup
4 hours 31 minutes ago
为积极响应国家关于加强软件工程学科建设与系统安全人才培养的战略部署,特举办软件系统安全赛。本赛事面向大学生,聚焦大型工业软件、关键基础软件等核心领域软件漏洞的挖掘、攻击与修复,通过模拟真实场景的攻防对抗,全面提升大学生在软件系统安全领域的实战能力。
通过此项科技创新活动,有效提高学生的软件系统安全攻防水平、创新意识与团队协作精神,加强高校间的学术交流,推动软件工程与网络安全人才培养体系的深化改革和
Cursor 代码审计 Skill 编写指南
4 hours 32 minutes ago
本文基于一套经过实战验证的安全审计 Skill 体系的设计与重构经验,系统讲解如何编写高质量的代码审计 Skill。
2026软件系统安全赛traffic_hunt
4 hours 33 minutes ago
溯源流量题目:traffic_hunt
Security Affairs newsletter Round 568 by Pierluigi Paganini – INTERNATIONAL EDITION
4 hours 34 minutes ago
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. WorldLeaks ransomware group breached the City of Los Angels PolyShell flaw exposes Magento and Adobe Commerce […]
Pierluigi Paganini
CVE-2026-24291-Windows权限提升漏洞“RegPwn”复现分析
4 hours 41 minutes ago
前言这个漏洞是英国 MDSecLabs 的 Filip Dragovic 发现的,据作者讲述,这个漏洞由于很巧妙,它们在红队评估中从2025年1月就开始使用,直到2026年2月报告给微软后,才在3月的补丁星期二修复,这么看也用够本了,原文只是讲了漏洞的核心部分,本文会讲清楚这个漏洞涉及的概念、如何形成的,如何利用它原文地址:https://www.mdsec.co.uk/2026/03/rip-r
分享一下最近挖的两个0Day的思路
4 hours 41 minutes ago
分享一下最近挖的两个0Day的思路