Aggregator
预计损失高达28亿元,知名金融机构遭网络攻击泄露客户敏感数据
11 months 2 weeks ago
官方将对被骗汇款的客户进行赔偿
CVE-2025-4807 | SourceCodester Online Student Clearance System 1.0 exposure of information through directory listing
11 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in SourceCodester Online Student Clearance System 1.0. This affects an unknown part. The manipulation leads to exposure of information through directory listing.
This vulnerability is uniquely identified as CVE-2025-4807. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-4806 | SourceCodester/oretnom23 Stock Management System 1.0 view_bo ID sql injection
11 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in SourceCodester/oretnom23 Stock Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/?page=back_order/view_bo. The manipulation of the argument ID leads to sql injection.
This vulnerability is handled as CVE-2025-4806. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #572238: SourceCodester Online Student Clearance System v1.0 Directory traversal [Accepted]
11 months 2 weeks ago
Submit #572238 / VDB-309261
laifeng-boy
Submit #572219: SourceCodester/oretnom23 Stock Management System (SMS-PHP by oretnom23) 1.0 SQL Injection [Accepted]
11 months 2 weeks ago
Submit #572219 / VDB-309260
Th3W0lf
Submit #572172: phpgurukul Online Course Registration v3.1 SQL Injection [Duplicate]
11 months 2 weeks ago
Submit #572172 / VDB-309072
QKset
【漏洞通告】Ivanti EPMM 未授权远程代码执行(CVE-2025-4428)
11 months 2 weeks ago
2025年5月16日,深瞳漏洞实验室监测到一则Ivanti-Endpoint-Manager-Mobile组件存在代码执行漏洞的信息,漏洞编号:CVE-2025-4428,漏洞威胁等级:高危。
CVE-2025-2248 | WP-PManager Plugin up to 1.2 on WordPress cross-site request forgery
11 months 2 weeks ago
A vulnerability classified as problematic was found in WP-PManager Plugin up to 1.2 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2025-2248. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-2203 | FunnelKit Plugin up to 3.10.1 on WordPress sql injection
11 months 2 weeks ago
A vulnerability classified as critical has been found in FunnelKit Plugin up to 3.10.1 on WordPress. Affected is an unknown function. The manipulation leads to sql injection.
This vulnerability is traded as CVE-2025-2203. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-1288 | WOOEXIM Plugin up to 5.0.0 on WordPress cross site scripting
11 months 2 weeks ago
A vulnerability was found in WOOEXIM Plugin up to 5.0.0 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-1288. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-2247 | WP-PManager Plugin up to 1.2 on WordPress Setting cross-site request forgery
11 months 2 weeks ago
A vulnerability was found in WP-PManager Plugin up to 1.2 on WordPress. It has been declared as problematic. This vulnerability affects unknown code of the component Setting Handler. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2025-2247. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-1303 | Plugin Oficial Plugin up to 1.7.3 on WordPress cross site scripting
11 months 2 weeks ago
A vulnerability was found in Plugin Oficial Plugin up to 1.7.3 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-1303. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-1289 | Plugin Oficial Plugin up to 1.7.3 on WordPress Setting cross site scripting
11 months 2 weeks ago
A vulnerability was found in Plugin Oficial Plugin up to 1.7.3 on WordPress and classified as problematic. Affected by this issue is some unknown functionality of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-1289. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-1033 | Badgearoo Plugin up to 1.0.14 on WordPress Setting cross site scripting
11 months 2 weeks ago
A vulnerability has been found in Badgearoo Plugin up to 1.0.14 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-1033. The attack can be launched remotely. There is no exploit available.
vuldb.com
Submit #567696: 1000 Projects Bookstore Management System PHP MySQL Project v1.0 SQL Injection [Duplicate]
11 months 2 weeks ago
Submit #567696 / VDB-283418
attackxu
CVE-2024-8201 | Hitachi Ops Center Analyzer 10.9.0-00/10.9.0-01/10.9.2-00/11.0.0-04/11.0.1-00 RAID Agent Component missing origin validation in websockets (sec-2025-116 / EUVD-2024-54549)
11 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Hitachi Ops Center Analyzer 10.9.0-00/10.9.0-01/10.9.2-00/11.0.0-04/11.0.1-00. Affected is an unknown function of the component RAID Agent Component. The manipulation leads to missing origin validation in websockets.
This vulnerability is traded as CVE-2024-8201. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-3624 | Hitachi Ops Center Analyzer 10.9.0-00/10.9.0-01/10.9.2-00/11.0.0-04/11.0.1-00 Detail View authorization (sec-2025-116 / EUVD-2025-15416)
11 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Hitachi Ops Center Analyzer 10.9.0-00/10.9.0-01/10.9.2-00/11.0.0-04/11.0.1-00. This issue affects some unknown processing of the component Detail View. The manipulation leads to missing authorization.
The identification of this vulnerability is CVE-2025-3624. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-47928 | spotipy 4f5759dbfb4506c7b6280572a4db1aabc1ac778d integration_tests.yml pull_request_target wrong session (GHSA-h25v-8c87-rvm8)
11 months 2 weeks ago
A vulnerability classified as critical was found in spotipy 4f5759dbfb4506c7b6280572a4db1aabc1ac778d. This vulnerability affects the function pull_request_target of the file .github/workflows/integration_tests.yml. The manipulation leads to exposure of data element to wrong session.
This vulnerability was named CVE-2025-47928. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-1531 | Hitachi Ops Center Analyzer Viewpoint default credentials (sec-2025-116 / EUVD-2025-15425)
11 months 2 weeks ago
A vulnerability classified as critical has been found in Hitachi Ops Center Analyzer Viewpoint. This affects an unknown part. The manipulation leads to use of default credentials.
This vulnerability is uniquely identified as CVE-2025-1531. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com