Aggregator
CVE-2024-12924 | Akınsoft QR Menü up to 1.05.11 redirect (EUVD-2024-54939)
CVE-2025-9802 | RemoteClinic 2.0 /staff/profile.php ID sql injection (EUVD-2025-26366)
Submit #641133: RemoteClinic V2.0 Boolean-Based Blind SQL Injection [Accepted]
CVE-2025-9801 | SimStudioAI sim up to ed9b9ad83f1a7c61f4392787fb51837d34eeb0af filePath path traversal (Issue 959 / EUVD-2025-26364)
CVE-2025-9800 | SimStudioAI sim up to ed9b9ad83f1a7c61f4392787fb51837d34eeb0af HTML File Parser route.ts import unrestricted upload (Issue 958 / EUVD-2025-26365)
Пульс атак — из Украины, цель — ваши VPN: невидимая сеть охотится в три смены
Submit #641130: simstudioai https://github.com/simstudioai/sim <=1.0.0 Arbitrary File Deletion [Accepted]
Submit #641129: simstudioai https://github.com/simstudioai/sim <=1.0.0 Dangerous type of file upload (CWE-434) [Accepted]
Crooks exploit Meta malvertising to target Android users with Brokewell
SUSE Fleet: Plain Text Storage of Vulnerability Exploit Helm Values
A high-severity vulnerability in SUSE’s Fleet, a GitOps management tool for Kubernetes clusters, has been disclosed by security researcher samjustus via GitHub Security Advisory GHSA-6h9x-9j5v-7w9h. The vulnerability, tracked as CVE-2024-52284, allows Helm chart values—often containing sensitive credentials—to be stored inside BundleDeployment resources in plain text, exposing them to any user with GET or LIST permissions. […]
The post SUSE Fleet: Plain Text Storage of Vulnerability Exploit Helm Values appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-9799 | Langfuse up to 3.88.0 Webhook promptRouter.ts promptChangeEventSourcing server-side request forgery (Issue 8522 / EUVD-2025-26361)
Google Web Designer Vulnerability Lets Hackers Take Over Client Systems
A critical client-side remote code execution (RCE) vulnerability in Google Web Designer exposed Windows users to full system compromise, according to a detailed write-up by security researcher Balint Magyar. Affecting versions prior to 16.4.0.0711 (released July 29, 2025), the flaw allowed attackers to inject malicious CSS into a configuration file and leverage an internal API […]
The post Google Web Designer Vulnerability Lets Hackers Take Over Client Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Submit #641128: langfuse https://github.com/langfuse/langfuse <=3.88.0 SSRF [Accepted]
Play
You must login to view this content
Play
You must login to view this content
Play
You must login to view this content
Play
You must login to view this content