Aggregator
CVE-2025-30985 | GNUCommerce Plugin up to 1.5.4 on WordPress deserialization
5 months 1 week ago
A vulnerability has been found in GNUCommerce Plugin up to 1.5.4 on WordPress and classified as critical. This vulnerability affects unknown code. The manipulation leads to deserialization.
This vulnerability was named CVE-2025-30985. The attack can be initiated remotely. There is no exploit available.
vuldb.com
ViperSoftX Malware Spreads Through Cracked Software, Targeting Unsuspecting Users
5 months 1 week ago
AhnLab Security Intelligence Center (ASEC) has unearthed a complex cyber campaign in which attackers, suspected to be Arabic speakers, have been distributing ViperSoftX malware to unsuspecting Korean users. This operation has employed cracked software and torrents as vectors for spreading this dangerous malware, which often disguises itself as legitimate programs. The exact method through which […]
The post ViperSoftX Malware Spreads Through Cracked Software, Targeting Unsuspecting Users appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Aman Mishra
CVE-2025-29088 | SQLite 3.49.0 SQLITE_DBCONFIG_LOOKASIDE denial of service
5 months 1 week ago
A vulnerability, which was classified as problematic, was found in SQLite 3.49.0. This affects an unknown part of the component SQLITE_DBCONFIG_LOOKASIDE. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2025-29088. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-32391 | HedgeDoc up to 1.10.2 Content-Disposition Parser /uploads cross site scripting (GHSA-3983-rrqh-mvx5)
5 months 1 week ago
A vulnerability, which was classified as problematic, has been found in HedgeDoc up to 1.10.2. Affected by this issue is some unknown functionality of the file /uploads of the component Content-Disposition Parser. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-32391. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-43035 | IBM Sterling Control Center 6.2.1/6.3.1/6.4.0 web browser cache containing sensitive information
5 months 1 week ago
A vulnerability classified as problematic was found in IBM Sterling Control Center 6.2.1/6.3.1/6.4.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to use of web browser cache containing sensitive information.
This vulnerability is known as CVE-2023-43035. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-29150 | BlueCMS 1.6 /publish.php?act=del ID denial of service
5 months 1 week ago
A vulnerability classified as problematic has been found in BlueCMS 1.6. Affected is an unknown function of the file /publish.php?act=del. The manipulation of the argument ID leads to denial of service.
This vulnerability is traded as CVE-2025-29150. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2025-32395 | vitejs vite up to 4.5.12/5.4.17/6.0.14/6.1.4/6.2.5 information disclosure (GHSA-356w-63v5-8wf4)
5 months 1 week ago
A vulnerability was found in vitejs vite up to 4.5.12/5.4.17/6.0.14/6.1.4/6.2.5. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2025-32395. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-32382 | Metabase up to 52.17.1/53.9.5/54.1.5 log file (GHSA-832j-56xw-5p7f)
5 months 1 week ago
A vulnerability was found in Metabase up to 52.17.1/53.9.5/54.1.5. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to sensitive information in log files.
This vulnerability was named CVE-2025-32382. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-24866 | Mattermost up to 9.11.8/10.4.x /api/v4/audits authorization
5 months 1 week ago
A vulnerability was found in Mattermost up to 9.11.8/10.4.x. It has been classified as problematic. This affects an unknown part of the file /api/v4/audits. The manipulation leads to incorrect authorization.
This vulnerability is uniquely identified as CVE-2025-24866. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-0362 | GitLab Community Edition/Enterprise Edition up to 17.8.6/17.9.5/17.10.3 ui layer (Issue 512425 / Nessus ID 234127)
5 months 1 week ago
A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 17.8.6/17.9.5/17.10.3 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improper restriction of rendered ui layers.
This vulnerability is handled as CVE-2025-0362. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-32383 | 1Panel-dev MaxKB 1.9.0 code injection (GHSA-fjf6-6cvf-xr72)
5 months 1 week ago
A vulnerability has been found in 1Panel-dev MaxKB 1.9.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to code injection.
This vulnerability is known as CVE-2025-32383. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-32743 | ConnMan up to 1.44 DNS Response dnsproxy.c ns_resolv lookup error condition
5 months 1 week ago
A vulnerability, which was classified as problematic, was found in ConnMan up to 1.44. Affected is the function ns_resolv of the file dnsproxy.c of the component DNS Response Handler. The manipulation of the argument lookup leads to missing report of error condition.
This vulnerability is traded as CVE-2025-32743. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-43037 | IBM Maximo Application Suite 8.11/9.0 improper authorization
5 months 1 week ago
A vulnerability, which was classified as critical, has been found in IBM Maximo Application Suite 8.11/9.0. This issue affects some unknown processing. The manipulation leads to improper authorization.
The identification of this vulnerability is CVE-2023-43037. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-42007 | IBM Sterling Control Center 6.2.1/6.3.1/6.4.0 Web UI cross site scripting
5 months 1 week ago
A vulnerability classified as problematic was found in IBM Sterling Control Center 6.2.1/6.3.1/6.4.0. This vulnerability affects unknown code of the component Web UI. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2023-42007. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-32027 | yiisoft yii up to 1.1.30 cross site scripting (GHSA-7r2v-8wxr-3ch5)
5 months 1 week ago
A vulnerability classified as problematic has been found in yiisoft yii up to 1.1.30. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-32027. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-29017 | CodeAstro Internet Banking System 2.0.0 pages_view_client.php profile_pic unrestricted upload
5 months 1 week ago
A vulnerability was found in CodeAstro Internet Banking System 2.0.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file pages_view_client.php. The manipulation of the argument profile_pic leads to unrestricted upload.
This vulnerability is handled as CVE-2025-29017. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-2469 | GitLab Community Edition/Enterprise Edition up to 17.9.5/17.10.3 debug messages revealing unnecessary information (Issue 525374 / Nessus ID 234130)
5 months 1 week ago
A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 17.9.5/17.10.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to debug messages revealing unnecessary information.
This vulnerability is known as CVE-2025-2469. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
LeakedData
5 months 1 week ago
cohenido
CVE-2022-4362 | Popup Maker Plugin up to 1.16.8 on WordPress Shortcode Attribute cross site scripting
5 months 1 week ago
A vulnerability has been found in Popup Maker Plugin up to 1.16.8 on WordPress and classified as problematic. This vulnerability affects unknown code of the component Shortcode Attribute Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2022-4362. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com