Aggregator
海南政府试点跨境加速服务
CVE-2025-5784 | PHPGurukul Employee Record Management System 1.3 /myexp.php emp3ctc sql injection
CVE-2025-5783 | PHPGurukul Employee Record Management System 1.3 /editmyexp.php emp3workduration sql injection
CVE-2025-5782 | PHPGurukul Employee Record Management System 1.3 /resetpassword.php newpassword sql injection
Submit #591205: PHPGurukul Employee Record Management System 1.3 SQL Injection [Accepted]
Submit #591203: PHPGurukul Employee Record Management System 1.3 SQL Injection [Accepted]
Submit #591202: PHPGurukul Employee Record Management System 1.3 SQL Injection [Accepted]
PoC Exploit Released for Apache Tomcat DoS Vulnerability
A critical memory leak vulnerability in Apache Tomcat’s HTTP/2 implementation (CVE-2025-31650) has been weaponized, enabling unauthenticated denial-of-service attacks through malformed priority headers. The flaw affects Tomcat versions 9.0.76–9.0.102, 10.1.10–10.1.39, and 11.0.0-M2–11.0.5, with public exploits already circulating 12. Vulnerability Mechanics and Attack Vector According to the report, the vulnerability stems from the improper cleanup of failed […]
The post PoC Exploit Released for Apache Tomcat DoS Vulnerability appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Submit #591204: PHPGurukul Employee Record Management System 1.3 SQL Injection [Duplicate]
CVE-2025-48911 | Huawei HarmonyOS 5.0.0 Note Sharing Module privileges assignment (EUVD-2025-17064)
CVE-2025-48910 | Huawei HarmonyOS 4.3.0/5.0.0 DFile Module heap-based overflow (EUVD-2025-17065)
CVE-2025-48909 | Huawei HarmonyOS 5.0.0 Device Management Channel improper authentication (EUVD-2025-17066)
CVE-2025-48908 | Huawei HarmonyOS 5.0.0 Ability Auto Startup Service unsynchronized access to shared data in a multithreaded context (EUVD-2025-17063)
CVE-2024-58114 | Huawei HarmonyOS 5.0.0 ArkUI Framework allocation of resources
Когда фишинг пахнет спецслужбой — Bitter снова в игре, и запах явно индийский
CVE-2025-5780 | code-projects Patient Record Management System 1.0 /view_dental.php itr_no sql injection
CVE-2025-5779 | code-projects Patient Record Management System 1.0 /birthing.php itr_no/comp_id sql injection
Submit #591128: code-projects Patient Record Management System 1.0 SQL Injection [Accepted]
Iranian APT ‘BladedFeline’ Stays Silent in Organizations Network for 8 Years
A sophisticated Iranian cyberespionage group has maintained undetected access to government networks across Iraq and the Kurdistan Regional Government for nearly eight years, representing one of the longest-running advanced persistent threat campaigns in the Middle East. The group, designated as BladedFeline by security researchers, has been operating since at least 2017, systematically targeting Kurdish diplomatic […]
The post Iranian APT ‘BladedFeline’ Stays Silent in Organizations Network for 8 Years appeared first on Cyber Security News.