Aggregator
CVE-2006-5108 | Devellion CubeCart up to 2.0.6 /admin/print_order.php site_name cross site scripting (EDB-28703 / XFDB-29177)
9 months 2 weeks ago
A vulnerability marked as problematic has been reported in Devellion CubeCart up to 2.0.6. This issue affects some unknown processing of the file /admin/print_order.php. This manipulation of the argument site_name causes basic cross site scripting.
This vulnerability is registered as CVE-2006-5108. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
vuldb.com
CVE-2006-5108 | CubeCart view_order.php order_id cross site scripting (EDB-28703 / XFDB-29177)
9 months 2 weeks ago
A vulnerability identified as problematic has been detected in CubeCart. This vulnerability affects unknown code of the file view_order.php. Performing manipulation of the argument order_id results in basic cross site scripting.
This vulnerability is identified as CVE-2006-5108. The attack can be initiated remotely. Additionally, an exploit exists.
vuldb.com
CVE-2006-4267 | Devellion CubeCart up to 3.0.11 confirmed.php x_invoice_num sql injection (EDB-2198 / Nessus ID 22231)
9 months 2 weeks ago
A vulnerability identified as critical has been detected in Devellion CubeCart up to 3.0.11. This impacts an unknown function of the file gateway/Protx/confirmed.php. Performing manipulation of the argument x_invoice_num results in sql injection.
This vulnerability is reported as CVE-2006-4267. The attack is possible to be carried out remotely. Moreover, an exploit is present.
vuldb.com
CVE-2006-4267 | CubeCart confirmed.php x_invoice_num sql injection (EDB-2198 / Nessus ID 22231)
9 months 2 weeks ago
A vulnerability was found in CubeCart. It has been rated as critical. This affects an unknown function of the file gateway/Authorize/confirmed.php. The manipulation of the argument x_invoice_num leads to sql injection.
This vulnerability is referenced as CVE-2006-4267. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2006-4267 | CubeCart admin/login.php email cross site scripting (EDB-2198 / Nessus ID 22231)
9 months 2 weeks ago
A vulnerability categorized as problematic has been discovered in CubeCart. This impacts an unknown function of the file admin/login.php. The manipulation of the argument email results in basic cross site scripting.
This vulnerability is identified as CVE-2006-4267. The attack can be executed remotely. Additionally, an exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2006-5107 | Devellion CubeCart up to 2.0.6 order_id sql injection (EDB-28695 / XFDB-29176)
9 months 2 weeks ago
A vulnerability labeled as critical has been found in Devellion CubeCart up to 2.0.6. This vulnerability affects unknown code. The manipulation of the argument order_id results in sql injection.
This vulnerability is cataloged as CVE-2006-5107. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2006-0478 | CRE Loaded 6.15 Installation files.php memory corruption (EDB-1446 / XFDB-24377)
9 months 2 weeks ago
A vulnerability classified as critical has been found in CRE Loaded 6.15. Impacted is an unknown function of the file files.php of the component Installation. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2006-0478. The attack is possible to be carried out remotely. Moreover, an exploit is present.
vuldb.com
CVE-2006-3343 | Crisoft Ricette 1.0pre15b crisoftricette file inclusion (EDB-28114 / XFDB-27472)
9 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in Crisoft Ricette 1.0pre15b. This issue affects some unknown processing. This manipulation of the argument crisoftricette causes file inclusion.
This vulnerability appears as CVE-2006-3343. The attack may be initiated remotely. In addition, an exploit is available.
vuldb.com
Russian regional airline disrupted by suspected cyberattack
9 months 2 weeks ago
Siberia-based airline KrasAvia experienced some outages to digital services in an incident that bears similarities to one that Ukraine-aligned hackers claimed in late July.
Три года разработки и восемь лет ожидания. Консорциум W3C представил WebAssembly 3.0
9 months 2 weeks ago
Новый стандарт принес 64-битную память, сборщик мусора и другие важные функции.
CVE-2025-8153 | NEC UNIVERGE IX/UNIVERGE IX-R/UNIVERGE IX-V cross site scripting (EUVD-2025-29671 / CNNVD-202509-2833)
9 months 2 weeks ago
A vulnerability described as problematic has been identified in NEC UNIVERGE IX, UNIVERGE IX-R and UNIVERGE IX-V. This vulnerability affects unknown code. Such manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-8153. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2025-8394 | Productive Style Plugin up to 1.1.23 on WordPress Shortcode display_productive_breadcrumb cross site scripting (EUVD-2025-29677 / CNNVD-202509-2832)
9 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in Productive Style Plugin up to 1.1.23 on WordPress. Affected by this issue is the function display_productive_breadcrumb of the component Shortcode Handler. Such manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2025-8394. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2025-10143 | Catch Dark Mode Plugin up to 2.0 on WordPress Shortcode catch_dark_mode file inclusion (EUVD-2025-29676 / CNNVD-202509-2835)
9 months 2 weeks ago
A vulnerability categorized as critical has been discovered in Catch Dark Mode Plugin up to 2.0 on WordPress. This issue affects the function catch_dark_mode of the component Shortcode Handler. The manipulation results in file inclusion.
This vulnerability is known as CVE-2025-10143. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2025-10166 | tw2113 Social Media Shortcodes Plugin up to 1.3.1 on WordPress Shortcode cross site scripting (EUVD-2025-29678 / CNNVD-202509-2834)
9 months 2 weeks ago
A vulnerability was found in tw2113 Social Media Shortcodes Plugin up to 1.3.1 on WordPress. It has been classified as problematic. This issue affects the function Media of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2025-10166. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2025-10050 | Developer Loggers for Simple History Plugin up to 0.5 on WordPress enabled_loggers file inclusion (EUVD-2025-29674 / CNNVD-202509-2836)
9 months 2 weeks ago
A vulnerability classified as problematic has been found in Developer Loggers for Simple History Plugin up to 0.5 on WordPress. This impacts an unknown function. The manipulation of the argument enabled_loggers leads to file inclusion.
This vulnerability is referenced as CVE-2025-10050. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
0-Click ChatGPT Agent Vulnerability Allows Sensitive Data Exfiltration from Gmail
9 months 2 weeks ago
A zero-click vulnerability discovered in ChatGPT’s Deep Research agent allowed attackers to exfiltrate sensitive data from a user’s Gmail account without any user interaction. The flaw, which OpenAI has since patched, leveraged a sophisticated form of indirect prompt injection hidden within an email, tricking the agent into leaking personal information directly from OpenAI’s cloud infrastructure. […]
The post 0-Click ChatGPT Agent Vulnerability Allows Sensitive Data Exfiltration from Gmail appeared first on Cyber Security News.
Guru Baran
Harold Liebregs aan het roer bij Koninklijke Marine in grimmige tijden
9 months 2 weeks ago
Viceadmiraal Harold Liebregs is sinds vanmiddag Commandant Zeestrijdkrachten en Admiraal Benelux. Op de marinebasis in Den Helder nam hij het bevel over de Koninklijke Marine over van ranggenoot René Tas. Op de valreep van zijn vertrek deed hij nog pittige uitspraken.
Установил VPN и лайкнул запрещенку — получи 25 лет тюрьмы. Оруэлл недооценил фантазию законодателей
9 months 2 weeks ago
Грань между нормой и запретом становится тоньше, чем когда-либо.
CVE-2022-50301 | Linux Kernel up to 6.0.2 omap2_iommu_dump_ctx len buffer overflow (Nessus ID 265266)
9 months 2 weeks ago
A vulnerability was found in Linux Kernel up to 6.0.2 and classified as critical. Affected is the function omap2_iommu_dump_ctx. The manipulation of the argument len results in buffer overflow.
This vulnerability was named CVE-2022-50301. The attack needs to be approached within the local network. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com