8080 подписчиков
213 видео
Google Chrome: Heap buffer overflow in WebAudio (CVE-2024-4559)
Introduction to SQL Injection
Understanding SQL Injection
Python URL Parser: Improper Input Validation in Python URL Parser (CVE-2025-0938)
ESP32: hidden HCI commands allowing unauthorized access (CVE-2025-27840)
Chrome: Use-after-free in Media Stream component (CVE-2025-8292)
Chrome: Type confusion in V8 JavaScript engine in Google Chrome (CVE-2025-10585)
TBK DVR: Critical OS command injection in TBK DVR-4104 and DVR-4216 via /device...(CVE-2024-3721)
Python requests library: Incorrect control flow implementation (CVE-2024-35195)
Django: Denial of Service in django.utils.text.wrap (CVE-2025-26699)
chrome: Out-of-bounds write in V8 in Google Chrome (CVE-2025-9132)
Chrome V8: Type confusion in V8 engine leading to arbitrary read/write (CVE-2025-6554)
WSUS: Deserialization of untrusted data in Windows Server Update Service (WSUS...(CVE-2025-59287)
Chrome: Out of bounds read and write in V8 engine (CVE-2025-5419)
Chrome: Insufficient policy enforcement in WebView tag handler in Google Chrome...(CVE-2026-0628)
firefox: integer overflow in the Web Open Fonts Format (WOFF) decoder of Mozill...(CVE-2010-1028)
setuptools: path traversal in setuptools PackageIndex (CVE-2025-47273)
python-future: arbitrary code execution via unintended import of test.py in Py...(CVE-2025-50817)
Zyxel USG FLEX H: incorrect permission assignment in PostgreSQL commands leadin...(CVE-2025-1731)
Kubernetes clusters: NodeRestriction admission controller incorrect auth...(CVE-2025-5187)
Kubernetes clusters: NodeRestriction admission controller incorrect authorizati...(CVE-2025-5187)
Zyxel USG FLEX H: local privilege escalation via incorrect permission assignmen...(CVE-2025-1731)
Chrome: Insufficient policy enforcement in Loader in Google Chrome (CVE-2025-4664)
vBulletin: Unauthenticated access to protected API controllers in vBull...(CVE-2025-48827)
node.js: node.js drive name handler (CVE-2025-23084)
Veeam Backup Enterprise Manager: authentication bypass (CVE-2024-29849)
Web Help Desk: unauthenticated AjaxProxy deserialization remote code execution (CVE-2025-26399)
Introduction to Advanced Persistent Threats (APT)
Docker Desktop: container escape via Docker Engine API exposure (CVE-2025-9074)
Chrome: sandbox escape in Mojo (CVE-2025-2783)
expat: libexpat resource allocation vulnerability (CVE-2025-59375)
Windows SMB client: Improper access control in Windows SMB allowing privilege ...(CVE-2025-33073)
Google Chrome: use after free in Visuals (CVE-2024-4671)
OpenSSH: OpenSSH VerifyHostKeyDNS issue (CVE-2025-26465)
Intel CPUs: Information Disclosure in Intel Processors...(CVE-2024-28956) (CVE-2024-28956)
vCenter Server: heap-overflow in VMware vCenter Server DCERPC implementation (CVE-2024-37079)
Python b64decode: improper validation in Python base64.b64decode allowing padde...(CVE-2026-3446)
Cleo software: JavaScript Injection and unrestricted file upload/download (CVE-2024-50623)
vBulletin: vBulletin template engine arbitrary PHP code execution (CVE-2025-48828)
VMware Tools: CISA Urgent Patch for VMware Tools Zero-Day
ASP.NET Core & VS 2022: HTTP request/response smuggling in ASP.NET Core (C...(CVE-2025-55315)
commons-beanutils: Improper Access Control in Apache Commons BeanUtils allowin...(CVE-2025-48734)
AMD processors & SUSE Xen: transient execution side-channel information le...(CVE-2024-36350)
Apple OS image parsing: out-of-bounds write in Apple image processing (CVE-2025-43300)
Critical Security Updates for Adobe, Apple, Google and Microsoft, and Emerging Threats
Veeam Backup products: TLS certificate validation failure (CVE-2025-23114)
FortiCloud SSO: FortiCloud SSO authentication bypass (CVE-2026-24858) (CVE-2026-24858)
Apex One: OS Command Injection in Trend Micro Apex One management console (CVE-2025-54948)
CentreStack: Gladinet CentreStack deserialization RCE via hardcoded mac...(CVE-2025-30406)