ru
Feedback
Sec WriteUp ~ CVE Alert

Sec WriteUp ~ CVE Alert

Открыть в Telegram

NOTIFICATIONS CHANNEL. 🔴 Security_WriteUp: #Medium #CyberSecurity #Hacker_News 🔴 CVE Reports #CVEfeed #Tenable #VulDb 🔴 Exploit Database #Exploit_DB #CXSECURITY #Sploitus Academy : @HackTheBox_Academy

Больше
472
Подписчики
Нет данных24 часа
Нет данных7 дней
-1030 дней
Архив постов
‼️ CVE ALERT ‼️ *************** 🗓Date: Fri, 06 Jun 2025 22:03:55 +0200 *************** ✏️Title: CVE-2025-29877 | QNAP File Station 5.5.6.4741/5.5.6.4791 null pointer dereference (qsa-25-16) *************** 📎Link: https://vuldb.com/?id.311564 *************** ⚙️Information: #Vendor: QNAP #Product: File Station #Risk: problematic #Local: No #Remote: Yes #Exploit: No #Countermeasures: Upgrade *************** ♦️Join: @HackTheBox_Academy ♦️Join: @HackTheBox_Security

‼️ CVE ALERT ‼️ *************** 🗓Date: Fri, 06 Jun 2025 22:04:11 +0200 *************** ✏️Title: CVE-2025-30279 | QNAP File Station 5.5.6.4847 certificate validation (qsa-25-16) *************** 📎Link: https://vuldb.com/?id.311565 *************** ⚙️Information: #Vendor: QNAP #Product: File Station #Risk: critical #Local: No #Remote: Yes #Exploit: No #Countermeasures: Upgrade *************** ♦️Join: @HackTheBox_Academy ♦️Join: @HackTheBox_Security

‼️ CVE ALERT ‼️ *************** 🗓Date: Fri, 06 Jun 2025 22:04:25 +0200 *************** ✏️Title: CVE-2025-33031 | QNAP File Station 5.5.6.4741/5.5.6.4791 certificate validation (qsa-25-16) *************** 📎Link: https://vuldb.com/?id.311566 *************** ⚙️Information: #Vendor: QNAP #Product: File Station #Risk: critical #Local: No #Remote: Yes #Exploit: No #Countermeasures: Upgrade *************** ♦️Join: @HackTheBox_Academy ♦️Join: @HackTheBox_Security

‼️ CVE ALERT ‼️ *************** 🗓Date: Fri, 06 Jun 2025 22:04:40 +0200 *************** ✏️Title: CVE-2025-33035 | QNAP File Station 5.5.6.4847 path traversal (qsa-25-16) *************** 📎Link: https://vuldb.com/?id.311567 *************** ⚙️Information: #Vendor: QNAP #Product: File Station #Risk: critical #Local: No #Remote: Yes #Exploit: No #Countermeasures: Upgrade *************** ♦️Join: @HackTheBox_Academy ♦️Join: @HackTheBox_Security

‼️ CVE ALERT ‼️ *************** 🗓Date: Fri, 06 Jun 2025 22:04:48 +0200 *************** ✏️Title: CVE-2025-49011 | authzed spicedb up to 1.44.1 security check (GHSA-cwwm-hr97-qfxm) *************** 📎Link: https://vuldb.com/?id.311568 *************** ⚙️Information: #Vendor: authzed #Product: spicedb #Risk: problematic #Local: No #Remote: Yes #Exploit: No #Countermeasures: Upgrade *************** ♦️Join: @HackTheBox_Academy ♦️Join: @HackTheBox_Security

‼️ CVE ALERT ‼️ *************** 🗓Date: Fri, 06 Jun 2025 22:06:28 +0200 *************** ✏️Title: CVE-2025-47950 | CoreDNS up to 1.12.1 allocation of resources (GHSA-cvx7-x8pj-x2gw) *************** 📎Link: https://vuldb.com/?id.311569 *************** ⚙️Information: #Product: CoreDNS #Risk: critical #Local: No #Remote: Yes #Exploit: No #Countermeasures: Upgrade *************** ♦️Join: @HackTheBox_Academy ♦️Join: @HackTheBox_Security

‼️ CVE ALERT ‼️ *************** 🗓Date: Fri, 06 Jun 2025 22:06:45 +0200 *************** ✏️Title: CVE-2025-5749 | WOLFBOX Level 2 EV Charger BLE Encryption uninitialized variable (ZDI-25-328) *************** 📎Link: https://vuldb.com/?id.311570 *************** ⚙️Information: #Vendor: WOLFBOX #Product: Level 2 EV Charger #Risk: critical #Local: No #Remote: Partially #Exploit: No #Countermeasures: Unknown *************** ♦️Join: @HackTheBox_Academy ♦️Join: @HackTheBox_Security

‼️ CVE ALERT ‼️ *************** 🗓Date: Fri, 06 Jun 2025 22:06:59 +0200 *************** ✏️Title: CVE-2025-49599 | Huawei EG8141A5/EG8145V5/EG8145V5-V2 authorization *************** 📎Link: https://vuldb.com/?id.311571 *************** ⚙️Information: #Vendor: Huawei #Product: EG8141A5/EG8145V5/EG8145V5_V2 #Risk: problematic #Local: No #Remote: Partially #Exploit: No #Countermeasures: Unknown *************** ♦️Join: @HackTheBox_Academy ♦️Join: @HackTheBox_Security

‼️ CVE ALERT ‼️ *************** 🗓Date: Fri, 06 Jun 2025 22:07:13 +0200 *************** ✏️Title: CVE-2025-5750 | WOLFBOX Level 2 EV Charger tuya_svc_devos_activate_result_parse secKey/localKey/stdTimeZone/devId heap-based overflow (ZDI-25-329) *************** 📎Link: https://vuldb.com/?id.311572 *************** ⚙️Information: #Vendor: WOLFBOX #Product: Level 2 EV Charger #Risk: critical #Local: No #Remote: Partially #Exploit: No #Countermeasures: Upgrade *************** ♦️Join: @HackTheBox_Academy ♦️Join: @HackTheBox_Security

‼️ CVE ALERT ‼️ *************** 🗓Date: Fri, 06 Jun 2025 22:07:30 +0200 *************** ✏️Title: CVE-2025-5751 | WOLFBOX Level 2 EV Charger hard-coded credentials (ZDI-25-330) *************** 📎Link: https://vuldb.com/?id.311573 *************** ⚙️Information: #Vendor: WOLFBOX #Product: Level 2 EV Charger #Risk: critical #Local: Partially #Remote: No #Exploit: No #Countermeasures: Unknown *************** ♦️Join: @HackTheBox_Academy ♦️Join: @HackTheBox_Security

‼️ CVE ALERT ‼️ *************** 🗓Date: Fri, 06 Jun 2025 22:08:06 +0200 *************** ✏️Title: CVE-2024-13087 | QNAP QuRouter 2.4.3.103/2.4.4.106/2.4.5.032 QHora os command injection (qsa-25-15) *************** 📎Link: https://vuldb.com/?id.311574 *************** ⚙️Information: #Vendor: QNAP #Product: QuRouter #Type: Router Operating System #Risk: problematic #Local: Partially #Remote: No #Exploit: No #Countermeasures: Upgrade *************** ♦️Join: @HackTheBox_Academy ♦️Join: @HackTheBox_Security

‼️ CVE ALERT ‼️ *************** 🗓Date: Fri, 06 Jun 2025 22:08:22 +0200 *************** ✏️Title: CVE-2024-13088 | QNAP QuRouter 2.4.3.103/2.4.4.106/2.4.5.032/2.4.6.028 QHora improper authentication (qsa-25-15) *************** 📎Link: https://vuldb.com/?id.311575 *************** ⚙️Information: #Vendor: QNAP #Product: QuRouter #Type: Router Operating System #Risk: critical #Local: Partially #Remote: No #Exploit: No #Countermeasures: Upgrade *************** ♦️Join: @HackTheBox_Academy ♦️Join: @HackTheBox_Security

‼️ CVE ALERT ‼️ *************** 🗓Date: Fri, 06 Jun 2025 22:08:34 +0200 *************** ✏️Title: CVE-2025-29871 | QNAP File Station 5.5.6.4741/5.5.6.4791 out-of-bounds (qsa-25-16) *************** 📎Link: https://vuldb.com/?id.311576 *************** ⚙️Information: #Vendor: QNAP #Product: File Station #Risk: problematic #Local: Yes #Remote: No #Exploit: No #Countermeasures: Upgrade *************** ♦️Join: @HackTheBox_Academy ♦️Join: @HackTheBox_Security

‼️ CVE ALERT ‼️ *************** 🗓Date: Fri, 06 Jun 2025 22:08:51 +0200 *************** ✏️Title: CVE-2024-50406 | QNAP License Center up to 1.9.48 cross site scripting (qsa-25-11) *************** 📎Link: https://vuldb.com/?id.311577 *************** ⚙️Information: #Vendor: QNAP #Product: License Center #Risk: problematic #Local: No #Remote: Yes #Exploit: No #Countermeasures: Upgrade *************** ♦️Join: @HackTheBox_Academy ♦️Join: @HackTheBox_Security

‼️ CVE ALERT ‼️ *************** 🗓Date: Fri, 06 Jun 2025 22:09:30 +0200 *************** ✏️Title: CVE-2025-5814 | State Restorationinfo Profiler Plugin up to 1.0.0 on WordPress wpsd_plugin_control missing authentication *************** 📎Link: https://vuldb.com/?id.311578 *************** ⚙️Information: #Vendor: State Restorationinfo #Product: Profiler Plugin #Type: WordPress Plugin #Risk: critical #Local: No #Remote: Yes #Exploit: No #Countermeasures: Unknown *************** ♦️Join: @HackTheBox_Academy ♦️Join: @HackTheBox_Security

‼️ CVE ALERT ‼️ *************** 🗓Date: Fri, 06 Jun 2025 22:17:03 +0200 *************** ✏️Title: CVE-2025-5836 | Tenda AC9 15.03.02.13 POST Request /goform/SetIPTVCfg formSetIptv list command injection *************** 📎Link: https://vuldb.com/?id.311579 *************** ⚙️Information: #Vendor: Tenda #Product: AC9 #Type: Router Operating System #Risk: critical #Local: No #Remote: Yes #Exploit: Yes #Countermeasures: Unknown *************** ♦️Join: @HackTheBox_Academy ♦️Join: @HackTheBox_Security

‼️ CVE ALERT ‼️ *************** 🗓Date: Fri, 06 Jun 2025 22:19:31 +0200 *************** ✏️Title: CVE-2025-5837 | PHPGurukul Employee Record Management System 1.3 /admin/allemployees.php delid sql injection *************** 📎Link: https://vuldb.com/?id.311580 *************** ⚙️Information: #Vendor: PHPGurukul #Product: Employee Record Management System #Risk: critical #Local: No #Remote: Yes #Exploit: Yes #Countermeasures: Unknown *************** ♦️Join: @HackTheBox_Academy ♦️Join: @HackTheBox_Security

‼️ CVE ALERT ‼️ *************** 🗓Date: Fri, 06 Jun 2025 22:19:33 +0200 *************** ✏️Title: CVE-2025-5838 | PHPGurukul Employee Record Management System 1.3 /admin/adminprofile.php AdminName sql injection *************** 📎Link: https://vuldb.com/?id.311581 *************** ⚙️Information: #Vendor: PHPGurukul #Product: Employee Record Management System #Risk: critical #Local: No #Remote: Yes #Exploit: Yes #Countermeasures: Unknown *************** ♦️Join: @HackTheBox_Academy ♦️Join: @HackTheBox_Security

‼️ CVE ALERT ‼️ *************** 🗓Date: Fri, 06 Jun 2025 22:21:47 +0200 *************** ✏️Title: CVE-2025-5839 | Tenda AC9 15.03.02.13 POST Request /goform/AdvSetLanip fromadvsetlanip lanMask buffer overflow *************** 📎Link: https://vuldb.com/?id.311582 *************** ⚙️Information: #Vendor: Tenda #Product: AC9 #Type: Router Operating System #Risk: critical #Local: No #Remote: Yes #Exploit: Yes #Countermeasures: Unknown *************** ♦️Join: @HackTheBox_Academy ♦️Join: @HackTheBox_Security

‼️ CVE ALERT ‼️ *************** 🗓Date: Fri, 06 Jun 2025 22:23:26 +0200 *************** ✏️Title: CVE-2025-5840 | SourceCodester Client Database Management System 1.0 user_update_customer_order.php uploaded_file unrestricted upload *************** 📎Link: https://vuldb.com/?id.311583 *************** ⚙️Information: #Vendor: SourceCodester #Product: Client Database Management System #Risk: critical #Local: No #Remote: Yes #Exploit: No #Countermeasures: Unknown *************** ♦️Join: @HackTheBox_Academy ♦️Join: @HackTheBox_Security