Aggregator
Submit #589781: code-projects NEWS-BUZZ (News Management System) v1.0 SQL Injection [Accepted]
Submit #589780: code-projects NEWS-BUZZ (News Management System) v1.0 SQL Injection [Accepted]
CVE-2025-5630 | D-Link DIR-816 1.10CNB05 form2lansetup.cgi ip stack-based overflow
Submit #589782: D-Link DIR816 1.10CNB05 OS Command Injection [Duplicate]
Submit #589779: D-Link DIR816 1.10CNB05 Stack-based Buffer Overflow [Accepted]
CVE-2025-5629 | Tenda AC10 up to 15.03.06.47 HTTP /goform/SetPptpServerCfg formSetPPTPServer startIp/endIp buffer overflow
Cyber Attacks on Government Agencies: Detect and Investigate with ANY.RUN for Fast Response
Government institutions worldwide face a growing number of sophisticated cyberattacks. This case study examines how ANY.RUN’s solutions can be leveraged to detect, analyze, and mitigate cyber threats targeting government organizations. By analyzing real-world threats, we demonstrate how ANY.RUN’s Threat Intelligence Lookup, Interactive Sandbox, and YARA Search assist cybersecurity teams in identifying attack vectors, tracking malicious […]
The post Cyber Attacks on Government Agencies: Detect and Investigate with ANY.RUN for Fast Response appeared first on ANY.RUN's Cybersecurity Blog.
CVE-2025-5628 | SourceCodester Food Menu Manager 1.0 Add Menu /index.php name/description cross site scripting
CVE-2025-5627 | code-projects Patient Record Management System 1.0 /sputum_form.php itr_no sql injection
APT37 Hackers Fake Academic Forum Invites to Deliver Malicious LNK Files via Dropbox Platform
The North Korean state-sponsored hacking group APT37 has launched a sophisticated spear phishing campaign in March 2025, targeting activists focused on North Korean issues. Disguised as invitations to an academic forum hosted by a South Korean national security think tank, these emails cleverly referenced a real event titled “Trump 2.0 Era: Prospects and South Korea’s […]
The post APT37 Hackers Fake Academic Forum Invites to Deliver Malicious LNK Files via Dropbox Platform appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Submit #589424: Tenda AC10 <=V15.03.06.47 Buffer Overflow [Accepted]
CVE-2025-5626 | Campcodes Online Teacher Record Management System 1.0 edit-subjects-detail.php editid sql injection
Submit #589417: Tenda AC10 <=V15.03.06.47 Buffer Overflow [Duplicate]
Submit #589416: Tenda AC6 <= V15.03.05.19 Buffer Overflow [Duplicate]
CVE-2025-5625 | Campcodes Online Teacher Record Management System 1.0 /search-teacher.php searchteacher sql injection
Submit #589365: Sourcecodester Food Menu Manager 1.0 xss [Accepted]
Google fixes Chrome zero-day with in-the-wild exploit (CVE-2025-5419)
Google has fixed two Chrome vulnerabilities, including a zero-day flaw (CVE-2025-5419) with an in-the-wild exploit. About CVE-2025-5419 CVE-2025-5419 is a high-severity out of bounds read and write vulnerability in V8, the JavaScript and WebAssembly engine developed by Google for the Chromium and Chrome web browsers. It allows remote attackers to trigger heap corruption via a crafted HTML page. It was reported by Clément Lecigne and Benoît Sevens of Google’s Threat Analysis Group – a specialized … More →
The post Google fixes Chrome zero-day with in-the-wild exploit (CVE-2025-5419) appeared first on Help Net Security.