A vulnerability, which was classified as problematic, has been found in Heat-On HSWeb 2.0. This impacts an unknown function of the file /cgi/. The manipulation leads to information disclosure (Path).
This vulnerability is traded as CVE-2001-0200. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability was found in Martin Hamilton Roads 2.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file search.pl. Executing manipulation with the input <filename>$software_input_value can lead to information disclosure (File).
This vulnerability is registered as CVE-2001-0215. It is possible to launch the attack remotely. Furthermore, an exploit is available.
It is suggested to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in Silverplatter WebSPIRS 3.3.1. This affects an unknown function of the file webspirs.cgi. This manipulation of the argument sp.nextform with the input .. causes path traversal.
This vulnerability is tracked as CVE-2001-0211. The attack is possible to be carried out remotely. Moreover, an exploit is present.
It is advisable to upgrade the affected component.
A vulnerability was found in MnSCU-PALS WebPALS 1.0. It has been classified as critical. Affected by this issue is some unknown functionality of the file pals-cgi. The manipulation of the argument documentName leads to improper privilege management.
This vulnerability is documented as CVE-2001-0216. The attack can be initiated remotely. Additionally, an exploit exists.
Signal and Rights Groups Urge Berlin to Reject CSAM Proposal Ahead of Key EU Vote The German federal government is under pressure to withdraw support for a European Union content scanning proposal that critics argue poses large-scale privacy risks. The EU Justice and Home Affairs Council is set to vote Oct. 14 on a regulation called Chat Control.
Email Security Acquisition Aims to Bring Cross-Platform Data to Phishing Defense Kaseya’s acquisition of Inky reflects the need for broader platform integration in email security. With phishing attacks becoming more subtle, founder and CEO Dave Baggett says access to login data and other platform signals is critical for threat detection.
A vulnerability was found in SourceCodester Hotel and Lodge Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /del_curr.php. Such manipulation of the argument ID leads to sql injection.
This vulnerability is listed as CVE-2025-11402. The attack may be performed from remote. In addition, an exploit is available.
A vulnerability was found in SourceCodester Hotel and Lodge Management System 1.0. It has been classified as critical. Affected by this issue is some unknown functionality of the file /del_booking.php. Performing manipulation of the argument ID results in sql injection.
This vulnerability is cataloged as CVE-2025-11403. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability categorized as problematic has been discovered in kaifangqian kaifangqian-base up to 7b3faecda13848b3ced6c17c7423b76c5b47b8ab. This issue affects the function getAllUsers of the file kaifangqian-parent/kaifangqian-system/src/main/java/com/kaifangqian/modules/system/controller/SysUserController.java. The manipulation results in information disclosure.
This vulnerability is reported as CVE-2025-11406. The attack can be launched remotely. Moreover, an exploit is present.
This product does not use versioning. This is why information about affected and unaffected releases are unavailable.
A vulnerability described as critical has been identified in Campcodes Advanced Online Voting Management System 1.0. This affects an unknown function of the file /admin/voters_add.php. Executing manipulation of the argument firstname can lead to sql injection.
This vulnerability is handled as CVE-2025-11410. The attack can be executed remotely. Additionally, an exploit exists.
Other parameters might be affected as well.
A vulnerability has been found in code-projects Online Course Registration 1.0 and classified as critical. Impacted is an unknown function of the file /admin/manage-students.php. This manipulation of the argument ID causes sql injection.
This vulnerability is handled as CVE-2025-11329. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability was found in PHPGurukul Beauty Parlour Management System 1.1 and classified as critical. The affected element is an unknown function of the file /admin/sales-reports-detail.php. Such manipulation of the argument fromdate/todate leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-11330. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability was found in IdeaCMS up to 1.8. It has been classified as critical. The impacted element is an unknown function of the file app/common/logic/admin/Config.php of the component Website Name Handler. Performing manipulation of the argument 网站名称 results in command injection.
This vulnerability was named CVE-2025-11331. The attack may be initiated remotely. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability marked as critical has been reported in vLLM up to 0.10.2. This issue affects some unknown processing of the component API. This manipulation causes improper authentication.
This vulnerability is handled as CVE-2025-59425. The attack can only be done within the local network. There is not any exploit available.
It is suggested to upgrade the affected component.