zoomeye_team Twitter Update ! 博主: zoomeye_team 推文: ⚠ 印度电网遭受了”Operation Sindoor”的精准打击——这次攻击针对的是ICS系统。为什么这不仅仅是印度的问题?过时的系统、远程访问以及供应商集中化已将关键基础设施变成了高风险区域。工业控制系统中长期被忽视的弱点终于爆发了。👇 阅读这一警钟背后的完整故事。#ICS #印度 #电力 #网络安全 #信息安全 #OSINT 链接: https:/ 2025-07-11 推特监控 #zoomeye_team
CVE-2025-32756 描述: A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiVoice versions 7.2.0, 7.0.0 through 7.0.6, 6.4.0 through 6.4.10, FortiRecorder versions 7.2.0 through 7.2.3, 7.0.0 through 7. 2025-07-11 其他 #attackerkb.com
CVE-2024-21888 描述: A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator. T 2025-07-11 其他 #attackerkb.com
Pre-Auth SQL Injection to RCE - Fortinet FortiWeb Fabric Connector (CVE-2025-25257) 描述: Welcome back to yet another day in this parallel universe of security. This time, we’re looking at Fortinet’s FortiWeb Fabric Connector. “What is that?” we hear you say. That’s a great question; n 2025-07-11 安全博客 #labs.watchtowr.com
CVE-2024-50623 描述: In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution. CVE-2024-50623 2025-07-11 其他 #attackerkb.com
CVE-2025-6543 描述: Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP P 2025-07-11 其他 #attackerkb.com
The GB Forms DB plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 链接: https://github.com/advisories/GHSA-h6cx-vg54-8g9q CVSS 评分: 9.8 参考链接: https://nvd.nist.gov/vuln/detail/CVE-2025-5392 https://plugins.trac.wordpress.org/browser/gb-forms-db/trunk/core/functions.ph 2025-07-11 安全公告 #Github Advisory
CVE-2025-3933 Regular expression Denial of Service - ReDoS in huggingface/transformers 链接: https://huntr.com/bounties/25282953-5827-4384-bb6f-5790d275721b 2025-07-11 其他 #huntr.com
CVE-2025-5777 描述: Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server Based on two public a 2025-07-11 其他 #attackerkb.com
Apache Dubbo JavaNative反序列化漏洞 漏洞信息漏洞名称: Apache Dubbo JavaNative反序列化漏洞 漏洞编号: CVE: CVE-2023-23638 漏洞类型: 反序列化 漏洞等级: 高危 漏洞描述: Apache Dubbo是一个高性能的、轻量级的开源Java RPC框架,广泛应用于分布式服务架构中,支持服务治理、负载均衡、服务降级等功能,是企业级微服务架构中的重要组件。该漏洞存在于Dubbo框架中,涉及Ja 2025-07-11 Github Poc #反序列化 #CVE-2023:github search