Spanish Guardia Civil have dismantled the "GXC Team" cybercrime syndicate and arrested its alleged leader, a 25-year-old Brazilian known as "GoogleXcoder." [...]
A vulnerability categorized as critical has been discovered in RainyGao DocSys up to 2.02.36. Affected by this vulnerability is an unknown functionality of the file /Doc/deleteDoc.do. Executing manipulation of the argument path can lead to path traversal.
This vulnerability is tracked as CVE-2025-11631. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in RainyGao DocSys up to 2.02.36. It has been rated as critical. Affected is the function updateRealDoc of the file /Doc/uploadDoc.do of the component File Upload. Performing manipulation of the argument path results in path traversal.
This vulnerability is identified as CVE-2025-11630. The attack can be initiated remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in RainyGao DocSys up to 2.02.36. It has been declared as critical. This impacts the function getUserList of the file /Manage/getUserList.do. Such manipulation leads to sql injection.
This vulnerability is referenced as CVE-2025-11629. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in jimit105 Project-Online-Shopping-Website up to 7d892f442bd8a96dd242dbe2b9bd5ed641e13e64. It has been classified as critical. This affects an unknown function of the file /delete.php of the component Product Inventory Handler. This manipulation of the argument product_code causes sql injection.
The identification of this vulnerability is CVE-2025-11628. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Huawei HarmonyOS 5.0.1/5.1.0 and classified as problematic. The impacted element is an unknown function of the component Office Service. The manipulation results in path traversal: '/../filedir'.
This vulnerability was named CVE-2025-58286. The attack needs to be approached locally. There is no available exploit.
A vulnerability has been found in Huawei HarmonyOS 5.0.1/5.1.0 and classified as critical. The affected element is an unknown function of the component Development Framework Module. The manipulation leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2025-58295. Local access is required to approach this attack. No exploit exists.
A vulnerability, which was classified as problematic, was found in Huawei HarmonyOS 5.0.1/5.1.0. Impacted is an unknown function of the component Office Service. Executing manipulation can lead to path traversal: 'dir/../../filename'.
This vulnerability is handled as CVE-2025-58292. It is possible to launch the attack on the local host. There is not any exploit available.
A vulnerability, which was classified as problematic, has been found in Huawei HarmonyOS 5.0.1/5.1.0. This issue affects some unknown processing of the component Office Service. Performing manipulation results in path traversal: '\..\filename'.
This vulnerability is known as CVE-2025-58291. Attacking locally is a requirement. No exploit is available.
A vulnerability classified as problematic was found in Huawei HarmonyOS 5.0.1/5.1.0. This vulnerability affects unknown code of the component Office Service. Such manipulation leads to improper resolution of path equivalence.
This vulnerability is traded as CVE-2025-58290. An attack has to be approached locally. There is no exploit available.
A vulnerability classified as critical has been found in Huawei HarmonyOS 5.0.1/5.1.0. This affects an unknown part of the component Office Service. This manipulation causes permission issues.
This vulnerability appears as CVE-2025-58288. The attack requires local access. There is no available exploit.
A vulnerability described as critical has been identified in Huawei HarmonyOS 5.0.1/5.1.0. Affected by this issue is some unknown functionality of the component Office Service. The manipulation results in permission issues.
This vulnerability is reported as CVE-2025-58287. The attack requires a local approach. No exploit exists.
A vulnerability marked as critical has been reported in Huawei HarmonyOS 5.1.0. Affected by this vulnerability is an unknown functionality of the component Sensor Service. The manipulation leads to stack-based buffer overflow.
This vulnerability is documented as CVE-2025-58297. The attack needs to be performed locally. There is not any exploit available.
A vulnerability labeled as critical has been found in Huawei HarmonyOS 5.0.1/5.1.0. Affected is an unknown function of the component Storage Management Module. Executing manipulation can lead to use after free.
This vulnerability is registered as CVE-2025-58299. The attack needs to be launched locally. No exploit is available.