Aggregator
CVE-2024-56915 | Netbox Community up to 4.2.1 RSS Feed Widget cross site scripting (EUVD-2024-54704)
9 months 2 weeks ago
A vulnerability has been found in Netbox Community up to 4.2.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component RSS Feed Widget. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-56915. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-52902 | filebrowser up to 2.33.6 cross site scripting (GHSA-4wx8-5gm2-2j97 / EUVD-2025-19201)
9 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in filebrowser up to 2.33.6. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-52902. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-53007 | Espressif arduino-esp32 up to 3.2.0 HTTP Header response splitting (GHSA-5476-9jjq-563m / EUVD-2025-19198)
9 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in Espressif arduino-esp32 up to 3.2.0. This issue affects some unknown processing of the component HTTP Header Handler. The manipulation leads to http response splitting.
The identification of this vulnerability is CVE-2025-53007. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-29331 | MHSanaei 3x-ui up to 2.5.3 wget certificate validation (EUVD-2025-19195)
9 months 2 weeks ago
A vulnerability classified as problematic was found in MHSanaei 3x-ui up to 2.5.3. This vulnerability affects unknown code of the component wget Handler. The manipulation leads to improper certificate validation.
This vulnerability was named CVE-2025-29331. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-52900 | filebrowser up to 2.33.6 default permission (GHSA-jj2r-455p-5gvf / EUVD-2025-19199)
9 months 2 weeks ago
A vulnerability classified as problematic has been found in filebrowser up to 2.33.6. This affects an unknown part. The manipulation leads to incorrect default permissions.
This vulnerability is uniquely identified as CVE-2025-52900. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-52887 | yhirose cpp-httplib 0.21.0 resource consumption (GHSA-xjhg-gf59-p92h / EUVD-2025-19196)
9 months 2 weeks ago
A vulnerability was found in yhirose cpp-httplib 0.21.0. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to resource consumption.
This vulnerability is handled as CVE-2025-52887. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-53002 | hiyouga LLaMA-Factory up to 0.9.3 vhead_file path code injection (GHSA-xj56-p8mm-qmxj / EUVD-2025-19200)
9 months 2 weeks ago
A vulnerability was found in hiyouga LLaMA-Factory up to 0.9.3. It has been declared as critical. Affected by this vulnerability is the function vhead_file. The manipulation of the argument path leads to code injection.
This vulnerability is known as CVE-2025-53002. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Submit #597524: yzcheng90 X-SpringBoot master branch Path Traversal [Accepted]
9 months 2 weeks ago
Submit #597524 / VDB-314006
ShenxiuSecurity
CVE-2025-51672 | PHPGurukul Dairy Farm Shop Management System 1.3 POST Request manage-companies.php companyname sql injection (EUVD-2025-19215)
9 months 2 weeks ago
A vulnerability was found in PHPGurukul Dairy Farm Shop Management System 1.3. It has been classified as critical. Affected is an unknown function of the file manage-companies.php of the component POST Request Handler. The manipulation of the argument companyname leads to sql injection.
This vulnerability is traded as CVE-2025-51672. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-36034 | IBM InfoSphere Information Server 11.7 API Request cleartext transmission
9 months 2 weeks ago
A vulnerability was found in IBM InfoSphere Information Server 11.7 and classified as problematic. This issue affects some unknown processing of the component API Request Handler. The manipulation leads to cleartext transmission of sensitive information.
The identification of this vulnerability is CVE-2025-36034. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-51671 | PHPGurukul Dairy Farm Shop Management System 1.3 POST Request manage-categories.php categorycode sql injection (EUVD-2025-19234)
9 months 2 weeks ago
A vulnerability has been found in PHPGurukul Dairy Farm Shop Management System 1.3 and classified as critical. This vulnerability affects unknown code of the file manage-categories.php of the component POST Request Handler. The manipulation of the argument categorycode leads to sql injection.
This vulnerability was named CVE-2025-51671. The attack can be initiated remotely. There is no exploit available.
vuldb.com
Легенду превратили в ловушку: имя Флибусты — теперь приманка для жертв
9 months 2 weeks ago
Сайт пережил блокировки и смерть основателя, но не пережил вредоносных клонов.
CVE-2025-20702 | Bluetooth Custom Protocol privilege escalation
9 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Bluetooth. This affects an unknown part of the component Custom Protocol. The manipulation leads to privilege escalation.
This vulnerability is uniquely identified as CVE-2025-20702. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2025-20701 | Bluetooth BR/EDR missing authentication
9 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in Bluetooth. Affected by this issue is some unknown functionality of the component BR/EDR. The manipulation leads to missing authentication.
This vulnerability is handled as CVE-2025-20701. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2025-20700 | Bluetooth GATT Service missing authentication
9 months 2 weeks ago
A vulnerability classified as critical was found in Bluetooth. Affected by this vulnerability is an unknown functionality of the component GATT Service. The manipulation leads to missing authentication.
This vulnerability is known as CVE-2025-20700. The attack can only be done within the local network. There is no exploit available.
vuldb.com
Tappoo Group of Companies Falls Victim to Qilin Ransomware
9 months 2 weeks ago
Tappoo Group of Companies Falls Victim to Qilin Ransomware
Dark Web Informer - Cyber Threat Intelligence
Hundreds of MCP Servers at Risk of RCE and Data Leaks
9 months 2 weeks ago
Misconfigured AI-linked MCP servers are exposing users to data breaches and remote code execution threats
Notorious cybercriminal ‘IntelBroker’ arrested in France, awaits extradition to US
9 months 2 weeks ago
Kai West, a 25-year-old British national, is accused of stealing data from more than 40 organizations during a two-year spree.
The post Notorious cybercriminal ‘IntelBroker’ arrested in France, awaits extradition to US appeared first on CyberScoop.
Matt Kapko
Собеседование мечты, GitHub-проект и npm install. Три шага до того, как ваш ПК станет чужим
9 months 2 weeks ago
Тот случай, когда «удалёнка» означает удалённый доступ к вашему компьютеру.