Aggregator
Global
5 months 2 weeks ago
You must login to view this content
cohenido
Porn-site age checks will be harder to fight after ruling on Texas law, experts say
5 months 2 weeks ago
The U.S. Supreme Court's decision in favor of Texas' law requiring age verification for porn-site users will have ripple effects across other states — and also for personal data privacy and security, experts say.
CVE-2025-6940 | TOTOLINK A702R 4.0.0-B20230721.1521 HTTP POST Request formParentControl submit-url buffer overflow (EUVD-2025-19600)
5 months 2 weeks ago
A vulnerability classified as critical was found in TOTOLINK A702R 4.0.0-B20230721.1521. Affected by this vulnerability is an unknown functionality of the file /boafrm/formParentControl of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow.
This vulnerability is known as CVE-2025-6940. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6939 | TOTOLINK A3002RU 3.0.0-B20230809.1615 HTTP POST Request /boafrm/formWlSiteSurvey submit-url buffer overflow
5 months 2 weeks ago
A vulnerability classified as critical has been found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affected is an unknown function of the file /boafrm/formWlSiteSurvey of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow.
This vulnerability is traded as CVE-2025-6939. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Escaping SOC Burnout: State of Security 2025
5 months 2 weeks ago
Michael Fanning, CISO at Splunk, shares insights on cybersecurity challenges highlighted in the Splunk State of Security report. Key issues include analyst burnout and alert fatigue, which persist over time. Fanning discusses how AI can improve efficiency and support analysts, emphasizing the need for better prioritization and event correlation in security operations to enhance effectiveness..
The post Escaping SOC Burnout: State of Security 2025 appeared first on Security Boulevard.
Alan Shimel
Germany asks Google, Apple to remove DeepSeek AI from app stores
5 months 2 weeks ago
The Berlin Commissioner for Data Protection has formally requested Google and Apple to remove the DeepSeek AI application from the application stores due to GDPR violations. [...]
Bill Toulas
Canada suspends Hikvision operations over national security concerns
5 months 2 weeks ago
Canadian Minister of Industry Mélanie Joly said in a statement that the determination was made with “information and evidence provided by Canada's security and intelligence community” and that she strongly encourages Canadians to “take note of this decision and make their own decisions accordingly.”
CVE-2025-6938 | code-projects Simple Pizza Ordering System 1.0 /editcus.php ID sql injection (EUVD-2025-19599)
5 months 2 weeks ago
A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /editcus.php. The manipulation of the argument ID leads to sql injection.
The identification of this vulnerability is CVE-2025-6938. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6937 | code-projects Simple Pizza Ordering System 1.0 /large.php ID sql injection (EUVD-2025-19596)
5 months 2 weeks ago
A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /large.php. The manipulation of the argument ID leads to sql injection.
This vulnerability was named CVE-2025-6937. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6936 | code-projects Simple Pizza Ordering System 1.0 /addpro.php ID sql injection (EUVD-2025-19593)
5 months 2 weeks ago
A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been classified as critical. This affects an unknown part of the file /addpro.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-6936. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #605861: TOTOLINK A702R V4.0.0-B20230721.1521 Buffer Overflow [Accepted]
5 months 2 weeks ago
Submit #605861 / VDB-314461
Ye Leipeng
CVE-2025-6935 | Campcodes Sales and Inventory System 1.0 /pages/payment_add.php cid sql injection (EUVD-2025-19594)
5 months 2 weeks ago
A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /pages/payment_add.php. The manipulation of the argument cid leads to sql injection.
This vulnerability is handled as CVE-2025-6935. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #605860: TOTOLINK A3002RU V3.0.0-B20230809.1615 Buffer Overflow [Accepted]
5 months 2 weeks ago
Submit #605860 / VDB-314460
Ye Leipeng
Submit #605749: Source Code & Projects Simple Pizza Ordering System V1.0 SQL Injection [Accepted]
5 months 2 weeks ago
Submit #605749 / VDB-314459
Catcheryp
Submit #605748: Source Code & Projects Simple Pizza Ordering System V1.0 SQL Injection [Accepted]
5 months 2 weeks ago
Submit #605748 / VDB-314458
Catcheryp
Submit #605728: Source Code & Projects Simple Pizza Ordering System Project V1.0 SQL Injection [Accepted]
5 months 2 weeks ago
Submit #605728 / VDB-314457
Catcheryp
CVE-2025-32463 | Todd Miller sudo 1.9.14/1.9.15/1.9.16/1.9.17 -R/--chroot access control (Nessus ID 241038)
5 months 2 weeks ago
A vulnerability has been found in Todd Miller sudo 1.9.14/1.9.15/1.9.16/1.9.17 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument -R/--chroot leads to improper access controls.
This vulnerability is known as CVE-2025-32463. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-32462 | Todd Miller sudo up to 1.9.17 -h/--host authorization (Nessus ID 240958)
5 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Todd Miller sudo up to 1.9.17. Affected is an unknown function. The manipulation of the argument -h/--host leads to incorrect authorization.
This vulnerability is traded as CVE-2025-32462. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Submit #605720: SourceCodester Campcodes Complete Sales and Inventory System v1.0 SQL Injection [Accepted]
5 months 2 weeks ago
Submit #605720 / VDB-314456
dragonghost