Aggregator
CVE-2025-25777 | Codeastro Bus Ticket Booking System 1.0 User Profile ID resource injection (EUVD-2025-11982)
CVE-2025-4806 | SourceCodester/oretnom23 Stock Management System 1.0 view_bo ID sql injection (EUVD-2025-15543)
CVE-2025-4807 | SourceCodester Online Student Clearance System 1.0 exposure of information through directory listing (EUVD-2025-15554)
CVE-2025-4101 | MultiVendorX Plugin up to 4.2.22 on WordPress delete_fpm_product improper authentication (EUVD-2025-15587)
CVE-2025-45885 | PHPGurukul Vehicle Parking Management System 1.13 /vpms/users/login.php emailcont sql injection (EUVD-2025-14172)
CVE-2025-4909 | SourceCodester Client Database Management System 1.0 exposure of information through directory listing (EUVD-2025-15652)
CVE-2025-47931 | LibreNMS up to 25.4.x /poller/groups group name cross site scripting (GHSA-hxw5-9cc5-cmw5 / EUVD-2025-15590)
CVE-2025-4923 | SourceCodester Client Database Management System 1.0 user_delivery_update.php uploaded_file_cancelled unrestricted upload (EUVD-2025-15671)
CVE-2025-4814 | Campcodes Sales and Inventory System 1.0 /pages/supplier_add.php Name sql injection (EUVD-2025-15563)
Estonia issues arrest warrant for Moroccan wanted for major pharmacy data breach
严重的 GitHub MCP 漏洞:通过 “问题 ”的提示注入使私有仓库面临人工智能劫持风险
WordPress TI WooCommerce Wishlist Plugin Vulnerability Exposes 100,000+ Websites To Cyberattack
A critical security vulnerability in the popular TI WooCommerce Wishlist plugin has left over 100,000 WordPress websites exposed to potential cyberattacks, with security researchers warning of imminent exploitation risks. The vulnerability, designated as CVE-2025-47577 and assigned the maximum CVSS score of 10.0, enables unauthenticated attackers to upload arbitrary files to affected websites, potentially leading to […]
The post WordPress TI WooCommerce Wishlist Plugin Vulnerability Exposes 100,000+ Websites To Cyberattack appeared first on Cyber Security News.
Mac 用户遭围攻: 假账本应用程序通过恶意软件窃取加密秘密
Czech Republic Accuses China of Government Hack
Microsoft OneDrive File Picker Flaw Grants Apps Full Cloud Access — Even When Uploading Just One File
数据泄露后阿迪达斯客户的个人信息面临风险
Hackers Exploit SimpleHelp RMM Tool to Deploy DragonForce Ransomware
Cybercriminals leveraged critical vulnerabilities in remote monitoring software to breach a managed service provider and attack multiple customers. Cybersecurity researchers at Sophos have revealed details of a sophisticated attack where threat actors exploited vulnerabilities in SimpleHelp remote monitoring and management (RMM) software to deploy DragonForce ransomware across multiple organizations through a managed service provider (MSP). […]
The post Hackers Exploit SimpleHelp RMM Tool to Deploy DragonForce Ransomware appeared first on Cyber Security News.