PTT NetSecurity Bot
Improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a PostgreSQL database and calls pg_insert_id() with user-suppl...
### Summary A serious vulnerability has been identified in the Erlang/OTP SSH server that may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SS...
# Description I found a Remote Command Execution (RCE) vulnerability in PyTorch. When loading model using torch.load with weights_only=True, it can still achieve RCE. # Background knowledge ...
CVE-2025-23016 - Exploiting the FastCGI library
Get the lowdown on the industry’s latest changes, the biggest of which is the shift to a 47-day SSL/TLS certificate validity period.
Improper input validation in AWS SSM Agent's plugin ID exposes systems to path traversal and privilege escalation attacks.
AWS patched an EC2 SSM Agent flaw on March 5, 2025, preventing privilege escalation via plugin ID path traversal.