Aggregator
Please support the site operations by clicking ads.
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
1 month 1 week hence
[Virtual Event] Building a Secure AI Strategy for the Enterprise
5 days 5 hours hence
CVE-2025-62178 | LabRedesCefetRJ WeGIA up to 3.5.0 cadastro_atendido_parentesco_pessoa_nova.php idatendido cross site scripting (ID 1181)
5 hours 7 minutes ago
A vulnerability described as problematic has been identified in LabRedesCefetRJ WeGIA up to 3.5.0. This vulnerability affects unknown code of the file /html/atendido/cadastro_atendido_parentesco_pessoa_nova.php. Executing a manipulation of the argument idatendido can lead to cross site scripting.
The identification of this vulnerability is CVE-2025-62178. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-42939 | SAP S4HANA 4CORE 104 up to 108 Manage Processing Rules authorization (EUVD-2025-34118 / CNNVD-202510-2076)
5 hours 7 minutes ago
A vulnerability marked as critical has been reported in SAP S4HANA 4CORE 104 up to 108. Impacted is an unknown function of the component Manage Processing Rules. The manipulation leads to incorrect authorization.
This vulnerability is uniquely identified as CVE-2025-42939. The attack is possible to be carried out remotely. No exploit exists.
Applying a patch is the recommended action to fix this issue.
vuldb.com
CVE-2025-62386 | Ivanti Endpoint Manager sql injection (WID-SEC-2025-2264)
5 hours 7 minutes ago
A vulnerability marked as critical has been reported in Ivanti Endpoint Manager. This affects an unknown function. This manipulation causes sql injection.
This vulnerability is handled as CVE-2025-62386. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2025-40755 | Siemens SINEC NMS up to 4.0 Endpoint getTotalAndFilterCounts sql injection (ssa-318832)
5 hours 7 minutes ago
A vulnerability, which was classified as critical, has been found in Siemens SINEC NMS up to 4.0. The impacted element is the function getTotalAndFilterCounts of the component Endpoint. Performing a manipulation results in sql injection.
This vulnerability was named CVE-2025-40755. The attack may be initiated remotely. There is no available exploit.
To fix this issue, it is recommended to deploy a patch.
vuldb.com
CVE-2025-20717 | MediaTek MT7986 WLAN AP Driver stack-based overflow
5 hours 7 minutes ago
A vulnerability marked as critical has been reported in MediaTek MT6890, MT7615, MT7622, MT7663, MT7915, MT7916, MT7981 and MT7986. The affected element is an unknown function of the component WLAN AP Driver. This manipulation causes stack-based buffer overflow.
This vulnerability appears as CVE-2025-20717. The attack requires local access. There is no available exploit.
Applying a patch is the recommended action to fix this issue.
vuldb.com
CVE-2025-11720 | Mozilla Firefox up to 143 on Android Focus UI ui layer (WID-SEC-2025-2275)
5 hours 7 minutes ago
A vulnerability classified as problematic has been found in Mozilla Firefox up to 143 on Android. This vulnerability affects unknown code of the component Focus UI. This manipulation causes improper restriction of rendered ui layers.
This vulnerability appears as CVE-2025-11720. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-11717 | Mozilla Firefox up to 143 on Android denial of service (WID-SEC-2025-2275)
5 hours 7 minutes ago
A vulnerability, which was classified as problematic, has been found in Mozilla Firefox up to 143 on Android. Impacted is an unknown function. Performing a manipulation results in denial of service.
This vulnerability is known as CVE-2025-11717. Attacking locally is a requirement. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-11718 | Mozilla Firefox up to 143 on Android Address Bar clickjacking (WID-SEC-2025-2275)
5 hours 7 minutes ago
A vulnerability, which was classified as problematic, was found in Mozilla Firefox up to 143 on Android. The affected element is an unknown function of the component Address Bar. Executing a manipulation can lead to clickjacking.
This vulnerability is handled as CVE-2025-11718. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2025-10242 | Ivanti Endpoint Manager Mobile prior 12.4.0.4/12.5.0.4/12.6.0.2 os command injection (EUVD-2025-34213 / Nessus ID 270691)
5 hours 7 minutes ago
A vulnerability categorized as critical has been discovered in Ivanti Endpoint Manager Mobile. This issue affects some unknown processing. The manipulation results in os command injection.
This vulnerability is identified as CVE-2025-10242. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-37147 | HPE ArubaOS up to 10.7.1.1 Secure Boot authentication spoofing
5 hours 7 minutes ago
A vulnerability identified as critical has been detected in HPE ArubaOS up to 8.10.0.18/8.12.0.5/8.13.0.1/10.4.1.8/10.7.1.1. This impacts an unknown function of the component Secure Boot. Performing a manipulation results in authentication bypass by spoofing.
This vulnerability is identified as CVE-2025-37147. The attack is only possible with local access. There is not any exploit available.
vuldb.com
CVE-2025-37138 | HPE ArubaOS up to 10.7.1.1 Command Line Interface command injection
5 hours 7 minutes ago
A vulnerability identified as critical has been detected in HPE ArubaOS up to 8.10.0.18/8.12.0.5/8.13.0.1/10.4.1.8/10.7.1.1. Affected by this issue is some unknown functionality of the component Command Line Interface. The manipulation leads to command injection.
This vulnerability is referenced as CVE-2025-37138. It is possible to launch the attack on the physical device. No exploit is available.
vuldb.com
CVE-2025-59497 | Microsoft Defender for Endpoint on Linux toctou (EUVD-2025-34266)
5 hours 7 minutes ago
A vulnerability classified as critical was found in Microsoft Defender for Endpoint on Linux. Affected by this vulnerability is an unknown functionality. The manipulation results in time-of-check time-of-use.
This vulnerability is reported as CVE-2025-59497. The attack requires a local approach. No exploit exists.
A patch should be applied to remediate this issue.
vuldb.com
CVE-2025-34267 | FlowiseAI Flowise up to 3.0.7 command injection (GHSA-5w3r-f6gm-c25w)
5 hours 7 minutes ago
A vulnerability classified as critical was found in FlowiseAI Flowise up to 3.0.7. This impacts an unknown function. The manipulation results in command injection.
This vulnerability is cataloged as CVE-2025-34267. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
5 hours 39 minutes ago
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
CVE-2025-11597 | code-projects E-Commerce Website 1.0 product_add_qty.php prod_id sql injection (EUVD-2025-33860)
5 hours 44 minutes ago
A vulnerability identified as critical has been detected in code-projects E-Commerce Website 1.0. The impacted element is an unknown function of the file /pages/product_add_qty.php. The manipulation of the argument prod_id leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-11597. The attack is possible to be carried out remotely. Moreover, an exploit is present.
vuldb.com
CVE-2025-11611 | SourceCodester Simple Inventory System 1.0 /user.php uemail sql injection (EUVD-2025-33873)
5 hours 44 minutes ago
A vulnerability, which was classified as critical, has been found in SourceCodester Simple Inventory System 1.0. Impacted is an unknown function of the file /user.php. This manipulation of the argument uemail causes sql injection.
This vulnerability is tracked as CVE-2025-11611. The attack is possible to be carried out remotely. Moreover, an exploit is present.
vuldb.com
CVE-2025-8593 | GSheetConnector for Gravity Forms Plugin up to 1.3.27 on WordPress Plugin Installation install_plugin authorization (EUVD-2025-33844)
5 hours 44 minutes ago
A vulnerability classified as critical has been found in GSheetConnector for Gravity Forms Plugin up to 1.3.27 on WordPress. The impacted element is the function install_plugin of the component Plugin Installation Handler. Performing a manipulation results in missing authorization.
This vulnerability is known as CVE-2025-8593. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com