Aggregator
Submit #674485: https://code-projects.org/e-commerce-website-in-php-with-source- E-COMMERCE WEBSITE V1.0 Stored/Persistent XSS [Accepted]
Submit #674484: https://code-projects.org/e-commerce-website-in-php-with-source- E-COMMERCE WEBSITE V1.0 Stored/Persistent XSS [Accepted]
Submit #674483: https://code-projects.org/e-commerce-website-in-php-with-source- E-COMMERCE WEBSITE V1.0 Stored/Persistent XSS [Accepted]
Dell security advisory (AV25-697)
CVE-2025-12332 | SourceCodester Student Grades Management System 1.0 /admin.php delete_user cross site scripting
IBM security advisory (AV25-696)
Hackers Actively Exploiting WordPress Arbitrary Installation Vulnerabilities in The Wild
Threat actors have launched a significant mass exploitation campaign targeting critical vulnerabilities in two popular WordPress plugins, GutenKit and Hunk Companion, affecting hundreds of thousands of websites globally. These vulnerabilities, discovered in September and October 2024, have resurfaced as an active threat in October 2025, demonstrating the persistent danger of unpatched installations. The attack vectors […]
The post Hackers Actively Exploiting WordPress Arbitrary Installation Vulnerabilities in The Wild appeared first on Cyber Security News.
Submit #674457: SourceCodester Student Grades Management System 1.0 Cross Site Scripting [Duplicate]
Submit #674456: Sourcecodester Student Grades Management System 1.0 Cross Site Scripting [Accepted]
72 states sign first global UN Convention against Cybercrime
The world’s first global convention to prevent and respond to cybercrime opened for signature today in Hanoi, Vietnam, and will remain open at United Nations Headquarters in New York until 31 December 2026. Adopted by the UN General Assembly in December 2024, the UN Convention against Cybercrime will enter into force 90 days after its 40th ratification. Once in force, a Conference of the States Parties will meet periodically to strengthen national capacities, enhance cooperation, … More →
The post 72 states sign first global UN Convention against Cybercrime appeared first on Help Net Security.
CVE-2025-11955 | TheGreenBow VPN Client Windows Enterprise 7.5/7.6 OCSP Certificate improper check for certificate revocation
CVE-2025-41009 | Disenno de Recursos Educativos Virtual Campus Platform POST Request /catalogo_c/catalogo.php buscame sql injection
CVE-2025-12331 | Willow CMS up to 1.4.0 /admin/images/add unrestricted upload
CVE-2025-12330 | Willow CMS up to 1.4.0 Add Post Page /admin/articles/add title/body cross site scripting (Issue 131)
Submit #674439: matthewdeaves Willow CMS v1.4.0 Remote Code Execution [Accepted]
Submit #674404: matthewdeaves Willow CMS v1.4.0 Stored Cross Site Scripting [Accepted]
Хаос в метро и $52 миллиона убытков. Вся защита Transport for London рухнула из-за двух тинейджеров
Critical HashiCorp Vault Vulnerabilities Allow Authentication Bypass and DoS Attacks
HashiCorp has disclosed two critical vulnerabilities in Vault and Vault Enterprise that could enable attackers to bypass authentication mechanisms and launch denial-of-service attacks against infrastructure. The first vulnerability, identified under Bulletin ID HCSEC-2025-31, stems from a regression in how Vault processes JSON payloads. According to HashiCorp’s disclosure published on October 23, 2025, the vulnerability allows […]
The post Critical HashiCorp Vault Vulnerabilities Allow Authentication Bypass and DoS Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.