Aggregator
Sarcoma
9 months 1 week ago
cohenido
CVE-2025-4248 | SourceCodester Simple To-Do List System 1.0 /complete_task.php ID sql injection
9 months 1 week ago
A vulnerability has been found in SourceCodester Simple To-Do List System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /complete_task.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is known as CVE-2025-4248. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-4249 | PHPGurukul e-Diary Management System 1.0 /manage-categories.php ID sql injection
9 months 1 week ago
A vulnerability was found in PHPGurukul e-Diary Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /manage-categories.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is handled as CVE-2025-4249. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-2269 | Phome Empire CMS 5.1 bid sql injection (EDB-10069)
9 months 1 week ago
A vulnerability was found in Phome Empire CMS 5.1. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation of the argument bid leads to sql injection.
This vulnerability is handled as CVE-2009-2269. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Легальный Windows-файл, странный Telegram и исчезнувшие биткоины. Совпадение?
9 months 1 week ago
Что придумала Golden Chickens на этот раз.
CVE-2019-11269 | Oracle Banking Credit Facilities Process Management 14.1.0/14.3.0/14.4.0 redirect (EDB-47000)
9 months 1 week ago
A vulnerability, which was classified as critical, has been found in Oracle Banking Credit Facilities Process Management 14.1.0/14.3.0/14.4.0. Affected by this issue is some unknown functionality. The manipulation leads to open redirect.
This vulnerability is handled as CVE-2019-11269. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-11269 | Oracle Banking Liquidity Management up to 14.4.0 Common redirect (EDB-47000)
9 months 1 week ago
A vulnerability, which was classified as critical, was found in Oracle Banking Liquidity Management up to 14.4.0. This affects an unknown part of the component Common. The manipulation leads to open redirect.
This vulnerability is uniquely identified as CVE-2019-11269. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-23522 | Pixelimity 1.0 admin/setting.php Password cross-site request forgery (EDB-49519)
9 months 1 week ago
A vulnerability, which was classified as problematic, has been found in Pixelimity 1.0. This issue affects some unknown processing of the file admin/setting.php. The manipulation of the argument Password leads to cross-site request forgery.
The identification of this vulnerability is CVE-2020-23522. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2019-11269 | Oracle Banking Corporate Lending Process Management 14.1.0/14.3.0/14.4.0 redirect (EDB-47000)
9 months 1 week ago
A vulnerability classified as critical was found in Oracle Banking Corporate Lending Process Management 14.1.0/14.3.0/14.4.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to open redirect.
This vulnerability is known as CVE-2019-11269. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-11022 | Oracle Application Testing Suite 13.3.0.1 Load Testing for Web Apps cross site scripting (EDB-49766 / Nessus ID 209233)
9 months 1 week ago
A vulnerability, which was classified as critical, was found in Oracle Application Testing Suite 13.3.0.1. Affected is an unknown function of the component Load Testing for Web Apps. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2020-11022. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-23342 | CMS 0.12.7 edit.php cross-site request forgery (EDB-49451)
9 months 1 week ago
A vulnerability classified as problematic was found in CMS 0.12.7. This vulnerability affects unknown code of the file anchor/views/users/edit.php. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2020-23342. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2019-11269 | Oracle Banking Payments 14.4.0 Payments Core redirect (EDB-47000)
9 months 1 week ago
A vulnerability has been found in Oracle Banking Payments 14.4.0 and classified as critical. This vulnerability affects unknown code of the component Payments Core. The manipulation leads to open redirect.
This vulnerability was named CVE-2019-11269. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Учёные проверили две главные теории сознания — и обе не сработали
9 months 1 week ago
Мозг показал, что сознание не в разуме, а в чувствах. И это не метафора.
Week in review: Critical SAP NetWeaver flaw exploited, RSAC 2025 Conference
9 months 1 week ago
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: RSAC 2025 Conference RSAC 2025 Conference took place at the Moscone Center in San Francisco. Check out our microsite for related news, photos, product releases, and more. Critical SAP NetWeaver flaw exploited by suspected initial access broker (CVE-2025-31324) CVE-2025-31324, a critical vulnerability in the SAP NetWeaver platform, is being actively exploited by attackers to upload malicious webshells to enable unauthorized … More →
The post Week in review: Critical SAP NetWeaver flaw exploited, RSAC 2025 Conference appeared first on Help Net Security.
Help Net Security
33 миллиона перуанцев в заложниках у Rhysida: почему правительство делает вид, что всё ОК
9 months 1 week ago
«Никакой атаки нет» — заявляют они, пока в даркнете тикает счётчик…
CVE-2025-4260 | zhangyanbo2007 youkefu up to 4.2.0 TemplateController.java impsave dataFile deserialization
9 months 1 week ago
A vulnerability was found in zhangyanbo2007 youkefu up to 4.2.0 and classified as problematic. Affected by this issue is the function impsave of the file m\web\handler\admin\system\TemplateController.java. The manipulation of the argument dataFile leads to deserialization.
This vulnerability is handled as CVE-2025-4260. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-4259 | newbee-mall 1.0 UploadController.java upload File unrestricted upload
9 months 1 week ago
A vulnerability has been found in newbee-mall 1.0 and classified as critical. Affected by this vulnerability is the function Upload of the file ltd/newbee/mall/controller/common/UploadController.java. The manipulation of the argument File leads to unrestricted upload.
This vulnerability is known as CVE-2025-4259. The attack can be launched remotely. Furthermore, there is an exploit available.
This product does not use versioning. This is why information about affected and unaffected releases are unavailable.
vuldb.com
Submit #562902: youkefu https://github.com/zhangyanbo2007/youkefu 1.0 反序列化 [Accepted]
9 months 1 week ago
Submit #562902 / VDB-307364
Serein123y
CVE-2025-4258 | zhangyanbo2007 youkefu up to 4.2.0 MediaController.java upload imgFile unrestricted upload
9 months 1 week ago
A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu up to 4.2.0. Affected is the function Upload of the file \youkefu-master\src\main\java\com\ukefu\webim\web\handler\resource\MediaController.java. The manipulation of the argument imgFile leads to unrestricted upload.
This vulnerability is traded as CVE-2025-4258. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com