Aggregator
【安全圈】2025年1月国内数据泄露事件汇总
1 year 3 months ago
【安全圈】Bybit遭遇黑客攻击:15亿美元被盗
1 year 3 months ago
CVE-2025-1578 | PHPGurukul Online Shopping Portal 2.1 /search-result.php product sql injection
1 year 3 months ago
A vulnerability, which was classified as critical, was found in PHPGurukul Online Shopping Portal 2.1. This affects an unknown part of the file /search-result.php. The manipulation of the argument product leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-1578. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #502997: PHPGurukul Online Shopping Portal Project V2.1 SQL Injection [Duplicate]
1 year 3 months ago
Submit #502997 / VDB-185601
panghuanjie
Submit #502876: code-projects blood-bank-system-in-php 0/1 Cross Site Scripting [Accepted]
1 year 3 months ago
Submit #502876 / VDB-296555
r2og
Submit #502508: PHPGurukul Shopping Portal V2.1 Unrestricted Upload [Duplicate]
1 year 3 months ago
Submit #502508 / VDB-278209
panghuanjie
CVE-2025-1577 | code-projects Blood Bank System 1.0 /prostatus.php message cross site scripting
1 year 3 months ago
A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank System 1.0. Affected by this issue is some unknown functionality of the file /prostatus.php. The manipulation of the argument message leads to cross site scripting.
This vulnerability is handled as CVE-2025-1577. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #502391: PHPGurukul Online Shopping Portal V2.1 SQL Injection [Accepted]
1 year 3 months ago
Submit #502391 / VDB-296553
panghuanjie
CVE-2025-1576 | code-projects Real Estate Property Management System 1.0 /ajax_state.php StateName sql injection
1 year 3 months ago
A vulnerability classified as critical was found in code-projects Real Estate Property Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax_state.php. The manipulation of the argument StateName as part of String leads to sql injection.
This vulnerability is known as CVE-2025-1576. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #502356: PHPGurukul Online Shopping Portal 2.1 Argument Injection [Duplicate]
1 year 3 months ago
Submit #502356 / VDB-278830
panghuanjie
Submit #502087: code-projects blood-bank-system-in-php 0/1 Cross Site Scripting [Accepted]
1 year 3 months ago
Submit #502087 / VDB-296552
heiheiworld
Submit #502071: code-projects Real Estate Property Management System php 1/0 SQL INJECTION [Accepted]
1 year 3 months ago
Submit #502071 / VDB-296551
fjl1113
CVE-2024-10893 | WP Booking Calendar Plugin up to 10.6.4 on WordPress Setting cross site scripting (fda-4145-810)
1 year 3 months ago
A vulnerability, which was classified as problematic, was found in WP Booking Calendar Plugin up to 10.6.4 on WordPress. This affects an unknown part of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-10893. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-49420 | Samsung GamingHub prior 6.1.04.6 Korea/7.1.03.7 Global Response improper validation of specified type of input
1 year 3 months ago
A vulnerability was found in Samsung GamingHub and classified as critical. This issue affects some unknown processing of the component Response Handler. The manipulation leads to improper validation of specified type of input.
The identification of this vulnerability is CVE-2024-49420. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-49411 | Samsung Devices ThemeCenter path traversal
1 year 3 months ago
A vulnerability was found in Samsung Devices. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component ThemeCenter. The manipulation leads to path traversal.
This vulnerability is known as CVE-2024-49411. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-11326 | Optin Cat Campaign Monitor Forms Plugin up to 2.5.7 on WordPress cross site scripting
1 year 3 months ago
A vulnerability has been found in Optin Cat Campaign Monitor Forms Plugin up to 2.5.7 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-11326. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-11200 | Goodlayers Core Plugin up to 2.0.7 on WordPress font-family cross site scripting
1 year 3 months ago
A vulnerability was found in Goodlayers Core Plugin up to 2.0.7 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument font-family leads to cross site scripting.
This vulnerability is handled as CVE-2024-11200. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-11325 | Optin Cat AWeber Forms Plugin up to 2.5.7 on WordPress cross site scripting
1 year 3 months ago
A vulnerability was found in Optin Cat AWeber Forms Plugin up to 2.5.7 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-11325. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-11782 | WP Mailster Plugin up to 1.8.17.0 on WordPress cross site scripting
1 year 3 months ago
A vulnerability was found in WP Mailster Plugin up to 1.8.17.0 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-11782. The attack can be initiated remotely. There is no exploit available.
vuldb.com