Posts

Showing posts from June, 2025

CVE-2024-12915 - Devinim Software Library Cross-site Scripting (XSS)

CVE ID : CVE-2024-12915 Published : June 30, 2025, 4:15 p.m. | 1 hour, 43 minutes ago Description : Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Devinim Software Library Software allows Reflected XSS.This issue affects Library Software: before 24.11.02. Severity: 4.6 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/BdiU3Ql via IFTTT

CVE-2025-6867 - SourceCodester Simple Company Website SQL Injection Vulnerability

CVE ID : CVE-2025-6867 Published : June 29, 2025, 7:15 p.m. | 40 minutes ago Description : A vulnerability was found in SourceCodester Simple Company Website 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/services/manage.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Severity: 4.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/VFsOSfZ via IFTTT

CVE-2025-6866 - Simple Forum PathTraversal

CVE ID : CVE-2025-6866 Published : June 29, 2025, 6:15 p.m. | 1 hour, 40 minutes ago Description : A vulnerability has been found in code-projects Simple Forum 1.0 and classified as critical. This vulnerability affects unknown code of the file /forum_downloadfile.php. The manipulation of the argument filename leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/TW4JIhP via IFTTT

CVE-2025-6865 - DaiCuo Cross-Site Request Forgery (CSRF) Vulnerability

CVE ID : CVE-2025-6865 Published : June 29, 2025, 5:15 p.m. | 43 minutes ago Description : A vulnerability, which was classified as problematic, was found in DaiCuo up to 1.3.13. This affects an unknown part of the file /admin.php/addon/index. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/1a9mXkR via IFTTT

CVE-2025-6864 - SeaCMS Cross-Site Request Forgery Vulnerability

CVE ID : CVE-2025-6864 Published : June 29, 2025, 4:15 p.m. | 1 hour, 43 minutes ago Description : A vulnerability, which was classified as problematic, has been found in SeaCMS up to 13.2. Affected by this issue is some unknown functionality of the file /admin_type.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/j1pDVKt via IFTTT

CVE-2023-28902 - Skoda MIB3 Infotainment Unit Integer Underflow Denial-of-Service Vulnerability

CVE ID : CVE-2023-28902 Published : June 28, 2025, 4:15 p.m. | 1 hour, 37 minutes ago Description : An integer underflow in the image processing binary of the MIB3 infotainment unit allows an attacker with local access to the vehicle to cause denial-of-service of the infotainment system. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources. Severity: 3.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/TKn1PpX via IFTTT

CVE-2025-50367 - PhpGurukul Medical Card Generation System Stored Blind XSS

CVE ID : CVE-2025-50367 Published : June 27, 2025, 4:15 p.m. | 1 hour, 36 minutes ago Description : A stored blind XSS vulnerability exists in the Contact Page of the Phpgurukul Medical Card Generation System 1.0 mcgs/contact.php. The name field fails to properly sanitize user input, allowing an attacker to inject malicious JavaScript. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/tnN8H57 via IFTTT

CVE-2024-11739 - Case Informatics Case ERP SQL Injection

CVE ID : CVE-2024-11739 Published : June 27, 2025, 4:15 p.m. | 1 hour, 36 minutes ago Description : Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Case Informatics Case ERP allows SQL Injection.This issue affects Case ERP: before V2.0.1. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/fkDdsS0 via IFTTT

CVE-2025-49603 - Northern.tech Mender Server Unauthenticated Remote Code Execution

CVE ID : CVE-2025-49603 Published : June 26, 2025, 6:15 p.m. | 1 hour, 32 minutes ago Description : Northern.tech Mender Server before 3.7.11 and 4.x before 4.0.1 has Incorrect Access Control. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/Ppwr9IB via IFTTT

CVE-2025-20264 - Cisco ISE SAML SSO Authorization Bypass Vulnerability

CVE ID : CVE-2025-20264 Published : June 25, 2025, 4:15 p.m. | 1 hour, 28 minutes ago Description : A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions. This vulnerability is due to insufficient authorization enforcement mechanisms for users created by SAML SSO integration with an external identity provider. An attacker could exploit this vulnerability by submitting a series of specific commands to an affected device. A successful exploit could allow the attacker to modify a limited number of system settings, including some that would result in a system restart. In single-node Cisco ISE deployments, devices that are not authenticated to the network will not be able to authenticate until the Cisco ISE system comes back online.  Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details...

CVE-2024-57708 - OneTrust SDK Prototype Pollution

CVE ID : CVE-2024-57708 Published : June 25, 2025, 4:15 p.m. | 1 hour, 28 minutes ago Description : An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __proto__, and Object.assign components Severity: 5.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/xpCbF7r via IFTTT

CVE-2025-23260 - NVIDIA AIStore Kubernetes ClusterRole Escalation of Privilege

CVE ID : CVE-2025-23260 Published : June 24, 2025, 6:15 p.m. | 1 hour, 25 minutes ago Description : NVIDIA AIStore contains a vulnerability in the AIS Operator where a user may gain elevated k8s cluster access by using the ServiceAccount attached to the ClusterRole. A successful exploit of this vulnerability may lead to information disclosure. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/jmOpAwF via IFTTT

CVE-2024-56916 - Netbox Community XSS: Cross-Site Scripting in Configuration History

CVE ID : CVE-2024-56916 Published : June 24, 2025, 6:15 p.m. | 1 hour, 25 minutes ago Description : In Netbox Community 4.1.7, once authenticated, Configuration History > Add`is vulnerable to cross-site scripting (XSS) due to the `current value` field rendering user supplied html. An authenticated attacker can leverage this to add malicious JavaScript to the any banner field. Once a victim edits a Configuration History version or attempts to Add a new version, the XSS payload will trigger. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/UIXN8iY via IFTTT

CVE-2025-49144 - Notepad++ Privilege Escalation Vulnerability

CVE ID : CVE-2025-49144 Published : June 23, 2025, 7:15 p.m. | 2 hours, 22 minutes ago Description : Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insecure executable search paths. An attacker could use social engineering or clickjacking to trick users into downloading both the legitimate installer and a malicious executable to the same directory (typically Downloads folder - which is known as Vulnerable directory). Upon running the installer, the attack executes automatically with SYSTEM privileges. This issue has been fixed and will be released in version 8.8.2. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/K3xrPso via IFTTT

CVE-2023-47029 - NCR Terminal Handler Remote Code Execution and Information Disclosure

CVE ID : CVE-2023-47029 Published : June 23, 2025, 6:15 p.m. | 1 hour, 22 minutes ago Description : An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted POST request to the UserService component Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/kKaFvzE via IFTTT

CVE-2025-6482 - "Simple Pizza Ordering System SQL Injection Vulnerability"

CVE ID : CVE-2025-6482 Published : June 22, 2025, 4:15 p.m. | 1 hour, 18 minutes ago Description : A vulnerability, which was classified as critical, was found in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown function of the file /edituser-exec.php. The manipulation of the argument userid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/9cCIYb8 via IFTTT

CVE-2025-6410 - PHPGurukul Art Gallery Management System SQL Injection

CVE ID : CVE-2025-6410 Published : June 21, 2025, 5:15 p.m. | 2 hours, 12 minutes ago Description : A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been classified as critical. Affected is an unknown function of the file /admin/edit-art-medium-detail.php. The manipulation of the argument editid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/O6qopBe via IFTTT

CVE-2025-6407 - Campcodes Online Hospital Management System SQL Injection Vulnerability

CVE ID : CVE-2025-6407 Published : June 21, 2025, 3:15 p.m. | 2 hours, 12 minutes ago Description : A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. This affects an unknown part of the file /user-login.php. The manipulation of the argument Username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Severity: 7.3 | HIGH

CVE-2025-44635 - H3C Router Remote Command Execution Vulnerability

CVE ID : CVE-2025-44635 Published : June 20, 2025, 5:15 p.m. | 2 hours, 8 minutes ago Description : There are multiple unauthorized remote command execution vulnerabilities in the H3C ER2200G2, ERG2-450W, ERG2-1200W, ERG2-1350W, NR1200W series routers before ERG2AW-MNW100-R1117; H3C ER3100G2, ER3200G2, ER3260G2, ER5100G2, ER5200G2, ER6300G2, ER8300G2, ER8300G2-X series routers before ERHMG2-MNW100-R1126; GR3200, GR5200, GR8300 and other series routers before MiniGR1B0V100R018L50; GR-1800AX before MiniGRW1B0V100R009L50; GR-3000AX before SWBRW1A0V100R007L50; and GR-5400AX before SWBRW1B0V100R009L50. Attackers can bypass authentication by including specially crafted text in the request URL or message header, and then inject arbitrary malicious commands into some fields related to ACL access control list and user group functions and execute to obtain the highest ROOT privileges of remote devices, thereby completely taking over the remote target devices. Severity: 0.0 | NA

World's Biggest Data Leak: 16 billion passwords

Image
A massive data breach has resulted in the leak of over 16 billion passwords from major platforms like Apple , Google , and Facebook . This unprecedented incident raises significant cybersecurity concerns, prompting experts to advise users to change their passwords immediately.  Overview of the Data Leak: The leak is considered the largest in history, with 16 billion login credentials exposed. Researchers from Cybernews discovered 30 datasets containing billions of records each, with some datasets holding over 3.5 billion records. The compromised data includes credentials from social media, VPNs, developer portals, and various online services.    Implications of the Leak:    - The leaked credentials are a goldmine for cybercriminals, enabling: Account Takeovers : Hijacking of social media, banking, and corporate accounts. Identity Theft : Using personal details for fraud or impersonation. Targeted Phishing : Crafting convincing scams based on leaked data. Rans...

CVE-2025-49014 - jq Heap Use After Free Vulnerability

CVE ID : CVE-2025-49014 Published : June 19, 2025, 3:15 p.m. | 2 hours, 2 minutes ago Description : jq is a command-line JSON processor. In version 1.8.0 a heap use after free vulnerability exists within the function f_strflocaltime of /src/builtin.c. This issue has been patched in commit 499c91b, no known fix version exists at time of publication. Severity: 0.0 | NA

CVE-2025-48886 - Cardano Hydra L1 Event Finality Vulnerability

CVE ID : CVE-2025-48886 Published : June 19, 2025, 3:15 p.m. | 2 hours, 2 minutes ago Description : Hydra is a layer-two scalability solution for Cardano. Prior to version 0.22.0, the process assumes L1 event finality and does not consider failed transactions. Currently, Cardano L1 is monitored for certain events which are necessary for state progression. At the moment, Hydra considers those events as finalized as soon as they are recognized by the node participants making such transactions the target of re-org attacks. The system does not currently consider the fact that failed transactions on the Cardano L1 can indeed appear in blocks because these transactions are so infrequent. This issue has been patched in version 0.22.0. Severity: 4.8 | MEDIUM

CVE-2024-54172 - IBM Sterling B2B Integrator and IBM Sterling File Gateway Cross-Site Request Forgery

Image
CVE ID : CVE-2024-54172 Published : June 18, 2025, 5:15 p.m. | 1 hour, 43 minutes ago Description : IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. Severity: 4.3 | MEDIUM

CVE-2025-45878 - Miliaris Amigdala XSS

Image
CVE ID : CVE-2025-45878 Published : June 17, 2025, 5:15 p.m. | 2 hours, 1 minute ago Description : A cross-site scripting (XSS) vulnerability in the report manager function of Miliaris Amigdala v2.2.6 allows attackers to execute arbitrary HTML in the context of a user's browser via a crafted payload. Severity: 6.1 | MEDIUM

CVE-2025-2327 - NetApp FlashArray Keystroke Vulnerability

Image
CVE ID : CVE-2025-2327 Published : June 16, 2025, 5:15 p.m. | 2 hours ago Description : A flaw exists in FlashArray whereby the Key Encryption Key (KEK) is logged during key rotation when RDL is configured. Severity: 0.0 | NA

CVE-2025-5964 - M-Files Server Path Traversal Vulnerability

Image
CVE ID : CVE-2025-5964 Published : June 15, 2025, 8:15 p.m. | 55 minutes ago Description : A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server. Severity: 0.0 | NA

CVE-2025-5990 - Crafty Controller Stored XSS Vulnerability

Image
CVE ID : CVE-2025-5990 Published : June 15, 2025, 6:15 p.m. | 55 minutes ago Description : An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a remote, authenticated attacker to perform stored XSS via malicious form input. Severity: 7.6 | HIGH

CVE-2025-6091 - H3C GR-3000AX Buffer Overflow Vulnerability

Image
CVE ID : CVE-2025-6091 Published : June 15, 2025, 5:15 p.m. | 1 hour, 55 minutes ago Description : A vulnerability was found in H3C GR-3000AX V100R007L50. It has been classified as critical. Affected is the function UpdateWanParamsMulti/UpdateIpv6Params of the file /routing/goform/aspForm. The manipulation of the argument param leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor confirms the existence of this issue. Because they assess the risk as low, they do not have immediate plans for remediation. Severity: 8.8 | HIGH

CVE-2025-21085 - PingFederate PostgreSQL OAuth2 Memory Exhaustion

Image
CVE ID : CVE-2025-21085 Published : June 15, 2025, 3:15 p.m. | 1 hour, 55 minutes ago Description : PingFederate OAuth2 grant duplication in PostgreSQL persistent storage allows OAuth2 requests to use excessive memory utilization. Severity: 0.0 | NA

CVE-2025-1411 - IBM Security Verify Directory Container Privilege Escalation Vulnerability

Image
CVE ID : CVE-2025-1411 Published : June 15, 2025, 1:15 p.m. | 1 hour, 55 minutes ago Description : IBM Security Verify Directory Container 10.0.0.0 through 10.0.3.1 could allow a local user to execute commands as root due to execution with unnecessary privileges. Severity: 7.8 | HIGH

CVE-2025-49583 - XWiki Cross-Site Notification Vulnerability

Image
CVE ID : CVE-2025-49583 Published : June 13, 2025, 5:15 p.m. | 1 hour, 54 minutes ago Description : XWiki is a generic wiki platform. When a user without script right creates a document with an `XWiki.Notifications.Code.NotificationEmailRendererClass` object, and later an admin edits and saves that document, the email templates in this object will be used for notifications. No malicious code can be executed, though, as while these templates allow Velocity code, the existing generic analyzer already warns admins before editing Velocity code. The main impact would thus be to send spam, e.g., with phishing links to other users or to hide notifications about other attacks. Note that warnings before editing documents with dangerous properties have only been introduced in XWiki 15.9, before that version, this was a known issue and the advice was simply to be careful. This has been patched in XWiki 16.10.2, 16.4.7 and 15.10.16 by adding an analysis for the respective XClass prop...

CVE-2025-49582 - XWiki Macro Execution Remote Code Execution

Image
CVE ID : CVE-2025-49582 Published : June 13, 2025, 5:15 p.m. | 1 hour, 54 minutes ago Description : XWiki is a generic wiki platform. When editing content that contains "dangerous" macros like malicious script macros that were authored by a user with fewer rights, XWiki warns about the execution of these macros since XWiki 15.9RC1. These required rights analyzers that trigger these warnings are incomplete, allowing an attacker to hide malicious content. For most macros, the existing analyzers don't consider non-lowercase parameters. Further, most macro parameters that can contain XWiki syntax like titles of information boxes weren't analyzed at all. Similarly, the "source" parameters of the content and context macro weren't anylzed even though they could contain arbitrary XWiki syntax. In the worst case, this could allow a malicious to add malicious script macros including Groovy or Python macros to a page that are then executed after another user w...

Breaking News: LockBit Ransomware Admin Panel Hacked, SQL Database Leaked

Image
On May 7, 2025 , a significant breach occurred within the notorious LockBit Ransomware as a Service (RaaS) ecosystem. An anonymous actor successfully hacked the LockBit admin panel , replacing their TOR website with a bold message: “ Don’t do crime CRIME IS BAD xoxo from Prague. ” Alongside this defacement, the hacker shared a SQL dump of the admin panel database in an archived file named ‘ paneldb_dump.zip .’ This incident follows a similar event that took place just a month earlier, where the Everest RaaS TOR site was also defaced with a comparable message, indicating a potential trend in targeting ransomware operations. The individual behind the alias ' xoxo from Prague ' remains shrouded in mystery, but their apparent mission is to disrupt and apprehend malicious ransomware threat actors. The defacement of a major ransomware organization's website, particularly the compromise of its administrative panel, is a rare occurrence in the cybersecurity landscape. The leaked SQ...

Script and Tools | Real Estate Management System V 1.0 | userdelete.php | IDOR

Image
Hi All,  I am Maloy Roy Orko Recently in one of my pentest research, I found a Real-Estate-Management-System  application By Script and Tools which is an open source Real Estate Management System in PHP Curious to explore its functionalities, I downloaded and set it up in my local system.  After fiddling with the source code, I found that the userdelete.php file is vulnerable to IDOR ! It can lead into: - Unauthorized Data Access - Data Manipulation - Account Takeover - Privilege Escalation - Denial of Service (DoS) - Reputation Damage - Regulatory Consequences The Main Thing Is, If any NON-IT personal uses this template,he will fall into this vulnerability and his companies reputation can be lost too.Thats why I am trying to inform everyone about this. Title of the Vulnerability:  Script and Tools | Real Estate Management System V 1.0 | userdelete.php | IDOR  CVE : CVE-2025-6329 CWE : 639 Vulnerability Class: Insecure Direct Object Reference (IDOR) Product N...

CVE-2024-55567 - Insyde H2O UsbCoreDxe SMM Call Out Vulnerability

Image
CVE ID : CVE-2024-55567 Published : June 12, 2025, 5:15 p.m. | 1 hour, 43 minutes ago Description : Improper input validation was discovered in UsbCoreDxe in Insyde InsydeH2O kernel 5.4 before 05.47.01, 5.5 before 05.55.01, 5.6 before 05.62.01, and 5.7 before 05.71.01. The SMM module has an SMM call out vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SMM level. Severity: 7.5 | HIGH

CVE-2023-45256 - PrestaShop EuroInformation MoneticoPaiement SQL Injection Vulnerability

Image
CVE ID : CVE-2023-45256 Published : June 12, 2025, 5:15 p.m. | 1 hour, 43 minutes ago Description : Multiple SQL injection vulnerabilities in the EuroInformation MoneticoPaiement module before 1.1.1 for PrestaShop allow remote attackers to execute arbitrary SQL commands via the TPE, societe, MAC, reference, or aliascb parameter to transaction.php, validation.php, or callback.php. Severity: 0.0 | NA

CVE-2025-1698 - "Xperia Fingerprint Sensor Null Pointer Denial of Service"

Image
CVE ID : CVE-2025-1698 Published : June 11, 2025, 5:15 p.m. | 1 hour, 30 minutes ago Description : Null pointer exception vulnerabilities were reported in the fingerprint sensor service that could allow a local attacker to cause a denial of service. Severity: 2.8 | LOW

CVE-2025-5978 - Tenda FH1202 Stack-Based Buffer Overflow Vulnerability

Image
CVE ID : CVE-2025-5978 Published : June 10, 2025, 9:15 p.m. | 1 hour, 28 minutes ago Description : A vulnerability was found in Tenda FH1202 1.2.0.14. It has been classified as critical. Affected is the function fromVirtualSer of the file /goform/VirtualSer. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Severity: 8.8 | HIGH Click This Link To Support Us: https://otieu.com/4/9451361

CVE-2025-35940 - ArchiverSpaApi JWT Signing Key Hard-Coded Vulnerability

Image
CVE ID : CVE-2025-35940 Published : June 10, 2025, 9:15 p.m. | 1 hour, 28 minutes ago Description : The ArchiverSpaApi ASP.NET application uses a hard-coded JWT signing key. An unauthenticated remote attacker can generate and use a verifiable JWT token to access protected ArchiverSpaApi URL endpoints. Severity: 8.1 | HIGH