Aggregator
CVE-2018-17240 | Netwave IP Camera Network Configuration //proc/kcore information disclosure
1 year 5 months ago
A vulnerability classified as problematic has been found in Netwave IP Camera. This affects an unknown part of the file //proc/kcore of the component Network Configuration Handler. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2018-17240. The attack can only be initiated within the local network. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-55972 | Chris Carvache eTemplates Plugin up to 0.2.1 on WordPress sql injection
1 year 5 months ago
A vulnerability was found in Chris Carvache eTemplates Plugin up to 0.2.1 on WordPress. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection.
This vulnerability is known as CVE-2024-55972. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2022-28108 | Selenium Server up to 3.x Non-JSON Content Type cross-site request forgery
1 year 5 months ago
A vulnerability was found in Selenium Server up to 3.x. It has been declared as problematic. This vulnerability affects unknown code of the component Non-JSON Content Type Handler. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2022-28108. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-12431 | GitLab Community Edition/Enterprise Edition up to 17.5.4/17.6.2/17.7.0 Public Project authorization (Nessus ID 213577)
1 year 5 months ago
A vulnerability has been found in GitLab Community Edition and Enterprise Edition up to 17.5.4/17.6.2/17.7.0 and classified as problematic. This vulnerability affects unknown code of the component Public Project Handler. The manipulation leads to missing authorization.
This vulnerability was named CVE-2024-12431. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-54010 | HPE AOS-CX Firewall access control
1 year 5 months ago
A vulnerability, which was classified as problematic, was found in HPE AOS-CX. This affects an unknown part of the component Firewall. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2024-54010. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2025-22145 | CarbonPHP carbon up to 2.72.5/3.8.3 Carbon::setLocale filename control
1 year 5 months ago
A vulnerability, which was classified as critical, has been found in CarbonPHP carbon up to 2.72.5/3.8.3. Affected by this issue is the function Carbon::setLocale. The manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is handled as CVE-2025-22145. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52869 | Teradata account-handling code up to 2024-11-04 access control
1 year 5 months ago
A vulnerability classified as critical was found in Teradata account-handling code up to 2024-11-04. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2024-52869. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2025-0349 | Tenda AC6 15.03.05.16 GetParentControlInfo src stack-based overflow
1 year 5 months ago
A vulnerability classified as critical has been found in Tenda AC6 15.03.05.16. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument src leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2025-0349. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
Other parameters might be affected as well.
vuldb.com
Black Widow Team Claims Breach of Israeli Fiber Optics Company Flash Fiber
1 year 5 months ago
cohenido
CVE-2025-0348 | CampCodes DepEd Equipment Inventory System 1.0 /data/add_employee.php data cross site scripting
1 year 5 months ago
A vulnerability was found in CampCodes DepEd Equipment Inventory System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /data/add_employee.php. The manipulation of the argument data leads to cross site scripting.
The identification of this vulnerability is CVE-2025-0348. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Ivanti warns of new Connect Secure flaw used in zero-day attacks
1 year 5 months ago
Ivanti is warning that a new Connect Secure remote code execution vulnerability tracked as CVE-2025-0282 was exploited in zero-day attacks to install malware on appliances. [...]
Lawrence Abrams
CVE-2025-0347 | code-projects Admission Management System 1.0 Login index.php u_id sql injection
1 year 5 months ago
A vulnerability was found in code-projects Admission Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file index.php of the component Login. The manipulation of the argument u_id leads to sql injection.
This vulnerability was named CVE-2025-0347. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Akira
1 year 5 months ago
cohenido
CVE-2025-0346 | code-projects Content Management System 1.0 Publish News Page /admin/publishnews.php image unrestricted upload
1 year 5 months ago
A vulnerability was found in code-projects Content Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/publishnews.php of the component Publish News Page. The manipulation of the argument image leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2025-0346. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #477048: tenda AC6 V15.03.05.16 Buffer Overflow [Accepted]
1 year 5 months ago
Submit #477048 / VDB-290862
WY596
Submit #476908: CampCodes DepEd Equipment Inventory System 1.0 Stored Cross-Site Scripting (XSS) [Accepted]
1 year 5 months ago
Submit #476908 / VDB-290861
John Correche
CVE-2025-0345 | leiyuxi cy-fast 1.0 /sys/menu/listData order sql injection
1 year 5 months ago
A vulnerability was found in leiyuxi cy-fast 1.0 and classified as critical. Affected by this issue is the function listData of the file /sys/menu/listData. The manipulation of the argument order leads to sql injection.
This vulnerability is handled as CVE-2025-0345. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-0344 | leiyuxi cy-fast 1.0 /commpara/listData order sql injection
1 year 5 months ago
A vulnerability has been found in leiyuxi cy-fast 1.0 and classified as critical. Affected by this vulnerability is the function listData of the file /commpara/listData. The manipulation of the argument order leads to sql injection.
This vulnerability is known as CVE-2025-0344. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Akira Ransomware Negotiation
1 year 5 months ago
Ransomware Negotiation Between Akira and a Withheld Victim
Dark Web Informer - Cyber Threat Intelligence