Aggregator
CVE-2025-6122 | code-projects Restaurant Order System 1.0 /table.php ID sql injection (EUVD-2025-18395)
CVE-2025-6124 | code-projects Restaurant Order System 1.0 /tablelow.php ID sql injection (EUVD-2025-18397)
CVE-2025-6153 | PHPGurukul Hostel Management System 1.0 /admin/students.php search_box sql injection (EUVD-2025-18446)
CVE-2025-6154 | PHPGurukul Hostel Management System 1.0 /includes/login.inc.php student_roll_no sql injection (EUVD-2025-18444)
CVE-2025-6133 | Projectworlds Life Insurance Management System 1.0 /insertagent.php agent_id sql injection
CVE-2025-6125 | PHPGurukul Rail Pass Management System 1.0 /admin/aboutus.php pagedes cross site scripting (EUVD-2025-18402)
CVE-2025-6126 | PHPGurukul Rail Pass Management System 1.0 /contact.php Name cross site scripting (EUVD-2025-18404)
CVE-2025-6127 | PHPGurukul Nipah Virus Testing Management System 1.0 /search-report.php serachdata cross site scripting (EUVD-2025-18405)
CVE-2025-6123 | code-projects Restaurant Order System 1.0 /payment.php tabidNoti sql injection (EUVD-2025-18411)
CVE-2025-5664 | FreeFloat FTP Server 1.0 RESTART Command buffer overflow (EUVD-2025-17004)
CVE-2025-5665 | FreeFloat FTP Server 1.0 XCWD Command buffer overflow (EUVD-2025-17003)
CVE-2025-5634 | PCMan FTP Server 2.0.7 NOOP Command buffer overflow (EUVD-2025-16959)
CVE-2025-5636 | PCMan FTP Server 2.0.7 SET Command buffer overflow (EUVD-2025-16966)
CVE-2025-5637 | PCMan FTP Server 2.0.7 SYSTEM Command buffer overflow (EUVD-2025-16965)
CVE-2025-5595 | FreeFloat FTP Server 1.0 PROGRESS Command buffer overflow (EUVD-2025-16900)
CVE-2025-5596 | FreeFloat FTP Server 1.0 REGET Command buffer overflow (EUVD-2025-16898)
CVE-2025-34033 | 5VTechnologies Blue Angel Software Suite GET Request webctrl.cgi ping_addr os command injection (Exploit 46792 / EUVD-2025-18969)
Security Advisory: Anthropic's Slack MCP Server Vulnerable to Data Exfiltration
This is a security advisory for a data leakage and exfiltration vulnerability in a popular, but now deprecated and unmaintained, Slack MCP Server from Anthropic.
If you are using this MCP server, or run an “MCP Store” that hosts it, it is advised that you analyze how this threat applies to your use case and apply a patch as needed.
Anthropic’s Slack MCP ServerWhen Anthropic introduced MCP they published reference server implementations on Github.
What Water Utilities Need to Know About HMI Security and AI Solutions
Water and Wastewater Systems are increasingly becoming soft targets for sophisticated cyber attackers. A new joint fact sheet from the EPA and CISA puts this threat front and center, warning utilities about the growing risk of internet-exposed Human Machine Interfaces (HMIs). These essential components of water system operations are now being exploited—especially by state-sponsored and […]
The post What Water Utilities Need to Know About HMI Security and AI Solutions appeared first on Security Boulevard.