Aggregator
Storm-0501黑客组织转向云端勒索攻击
10 months ago
安全客
CVE-2025-55177 | Facebook WhatsApp Desktop for Mac Synchronization Message authorization
10 months ago
A vulnerability marked as problematic has been reported in Facebook WhatsApp Desktop for Mac, WhatsApp Business for iOS and WhatsApp for iOS. Affected by this issue is some unknown functionality of the component Synchronization Message Handler. Performing manipulation results in incorrect authorization.
This vulnerability is reported as CVE-2025-55177. The attacker must have access to the local network to execute the attack. Moreover, an exploit is present.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-9706 | SourceCodester Water Billing System 1.0 /edit.php ID sql injection
10 months ago
A vulnerability labeled as critical has been found in SourceCodester Water Billing System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit.php. Such manipulation of the argument ID leads to sql injection.
This vulnerability is documented as CVE-2025-9706. The attack can be executed remotely. Additionally, an exploit exists.
vuldb.com
CVE-2025-9705 | SourceCodester Water Billing System 1.0 /paybill.php ID sql injection
10 months ago
A vulnerability identified as critical has been detected in SourceCodester Water Billing System 1.0. Affected is an unknown function of the file /paybill.php. This manipulation of the argument ID causes sql injection.
This vulnerability is registered as CVE-2025-9705. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
vuldb.com
CVE-2025-9704 | SourceCodester Water Billing System 1.0 /viewbill.php ID sql injection
10 months ago
A vulnerability categorized as critical has been discovered in SourceCodester Water Billing System 1.0. This impacts an unknown function of the file /viewbill.php. The manipulation of the argument ID results in sql injection.
This vulnerability is cataloged as CVE-2025-9704. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
FreePBX 服务器遭零日漏洞攻击,官方紧急发布修复方案
10 months ago
安全客
CVE-2025-9702 | SourceCodester Simple Cafe Billing System 1.0 /sales_report.php month sql injection
10 months ago
A vulnerability was found in SourceCodester Simple Cafe Billing System 1.0. It has been rated as critical. This affects an unknown function of the file /sales_report.php. The manipulation of the argument month leads to sql injection.
This vulnerability is listed as CVE-2025-9702. The attack may be initiated remotely. In addition, an exploit is available.
vuldb.com
CVE-2025-9701 | SourceCodester Simple Cafe Billing System 1.0 /receipt.php ID sql injection
10 months ago
A vulnerability was found in SourceCodester Simple Cafe Billing System 1.0. It has been declared as critical. The impacted element is an unknown function of the file /receipt.php. Executing manipulation of the argument ID can lead to sql injection.
This vulnerability is tracked as CVE-2025-9701. The attack can be launched remotely. Moreover, an exploit is present.
vuldb.com
CrowdStrike斥资2.9亿美元收购Onum,强化SIEM数据摄取能力
10 months ago
安全客
SecWiki News 2025-08-29 Review
10 months ago
院士解读具身智能(附分享报告实录) by ourren
使用生成对抗网络增强网络入侵检测性能 by ourren
攻击溯源最高境界:反控攻击者 by ourren
SANS 2025年SOC调查报告解读 by ourren
g3: 构建面向企业的通用代理解决方案 by ourren
更多最新文章,请访问SecWiki
使用生成对抗网络增强网络入侵检测性能 by ourren
攻击溯源最高境界:反控攻击者 by ourren
SANS 2025年SOC调查报告解读 by ourren
g3: 构建面向企业的通用代理解决方案 by ourren
更多最新文章,请访问SecWiki
Submit #639228: SourceCodester Water Billing System 1.0 SQL Injection [Accepted]
10 months ago
Submit #639228 / VDB-321927
xyz123
CVE-2025-55202 | Opencast up to 17.6/18.0 UI Config path traversal
10 months ago
A vulnerability was found in Opencast up to 17.6/18.0. It has been classified as problematic. The affected element is an unknown function of the component UI Config Module. Performing manipulation results in relative path traversal.
This vulnerability is identified as CVE-2025-55202. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
Submit #639226: SourceCodester Water Billing System 1.0 SQL Injection [Accepted]
10 months ago
Submit #639226 / VDB-321926
xyz123
Submit #639225: SourceCodester Water Billing System 1.0 SQL Injection [Accepted]
10 months ago
Submit #639225 / VDB-321925
xyz123
CVE-2025-5808 | OpenText Self Service Password Reset up to 4.8 Patch 2 improper validation of specified quantity in input
10 months ago
A vulnerability was found in OpenText Self Service Password Reset up to 4.8 Patch 2 and classified as critical. Impacted is an unknown function. Such manipulation leads to improper validation of specified quantity in input.
This vulnerability is referenced as CVE-2025-5808. It is possible to launch the attack remotely. No exploit is available.
Applying a patch is advised to resolve this issue.
vuldb.com
国务院部署“人工智能+”,360 All In Agent战略正逢其时
10 months ago
安全客
Microsoft to enforce MFA for Azure resource management in October
10 months ago
Starting in October, Microsoft will enforce multi-factor authentication (MFA) for all Azure resource management actions to protect Azure clients from unauthorized access attempts. [...]
Sergiu Gatlan
CVE-2025-9700 | SourceCodester Online Book Store 1.0 /publisher_list.php pubid sql injection
10 months ago
A vulnerability has been found in SourceCodester Online Book Store 1.0 and classified as critical. This issue affects some unknown processing of the file /publisher_list.php. This manipulation of the argument pubid causes sql injection.
The identification of this vulnerability is CVE-2025-9700. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #639227: SourceCodester Water Billing System 1.0 SQL Injection [Duplicate]
10 months ago
Submit #639227 / VDB-179448
xyz123