Aggregator
.NET 安全攻防知识交流社区
2 months 1 week ago
再回答一个 .NET 反序列化问题,看看有没有你想要知道的?
2 months 1 week ago
Salt Typhoon: What Security Action Should Governments Take Now?
2 months 1 week ago
The FBI just announced that the Salt Typhoon cyber attacks against U.S. telecoms uncovered last year were much worse and more widespread than previously disclosed. What’s next?
The post Salt Typhoon: What Security Action Should Governments Take Now? appeared first on Security Boulevard.
Lohrmann on Cybersecurity
CVE-2025-9716 | O2OA up to 10.0-410 Personal Profile Page form name/alias/description cross site scripting (Issue 182 / EUVD-2025-26285)
2 months 1 week ago
A vulnerability has been found in O2OA up to 10.0-410 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /x_processplatform_assemble_designer/jaxrs/form of the component Personal Profile Page. This manipulation of the argument name/alias/description causes cross site scripting.
This vulnerability appears as CVE-2025-9716. The attack may be initiated remotely. In addition, an exploit is available.
The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
vuldb.com
CVE-2025-9717 | O2OA up to 10.0-410 Personal Profile Page unit cross site scripting (Issue 183 / EUVD-2025-26284)
2 months 1 week ago
A vulnerability was found in O2OA up to 10.0-410 and classified as problematic. Affected by this issue is some unknown functionality of the file /x_organization_assemble_control/jaxrs/unit/ of the component Personal Profile Page. Such manipulation of the argument name/shortName/distinguishedName/pinyin/pinyinInitial/levelName leads to cross site scripting.
This vulnerability is traded as CVE-2025-9717. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-9718 | O2OA up to 10.0-410 Personal Profile Page process name/alias cross site scripting (Issue 184 / EUVD-2025-26286)
2 months 1 week ago
A vulnerability was found in O2OA up to 10.0-410. It has been classified as problematic. This affects an unknown part of the file /x_processplatform_assemble_designer/jaxrs/process of the component Personal Profile Page. Performing manipulation of the argument name/alias results in cross site scripting.
This vulnerability is known as CVE-2025-9718. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
vuldb.com
CVE-2025-9719 | O2OA up to 10.0-410 Personal Profile Page script name/alias/description/applicationName cross site scripting (Issue 185)
2 months 1 week ago
A vulnerability was found in O2OA up to 10.0-410. It has been declared as problematic. This vulnerability affects unknown code of the file /x_processplatform_assemble_designer/jaxrs/script of the component Personal Profile Page. Executing manipulation of the argument name/alias/description/applicationName can lead to cross site scripting.
This vulnerability is handled as CVE-2025-9719. The attack can be executed remotely. Additionally, an exploit exists.
vuldb.com
CVE-2025-5083 | Marco Milesi Amministrazione Trasparente Plugin up to 9.0 on WordPress Setting print_r cross site scripting
2 months 1 week ago
A vulnerability has been found in Marco Milesi Amministrazione Trasparente Plugin up to 9.0 on WordPress and classified as problematic. This impacts the function print_r of the component Setting Handler. This manipulation causes cross site scripting.
This vulnerability is registered as CVE-2025-5083. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2025-9405 | Open5GS up to 2.7.5 src/amf/gmm-sm.c gmm_state_exception assertion (Issue 3947 / EUVD-2025-25719)
2 months 1 week ago
A vulnerability labeled as problematic has been found in Open5GS up to 2.7.5. The impacted element is the function gmm_state_exception of the file src/amf/gmm-sm.c. The manipulation results in reachable assertion.
This vulnerability is known as CVE-2025-9405. It is possible to launch the attack remotely. Furthermore, an exploit is available.
Applying a patch is advised to resolve this issue.
vuldb.com
CVE-2025-9755 | Khanakag-17 Library Management System up to 60ed174506094dcd166e34904a54288e5d10ff24 /index.php msg cross site scripting (EUVD-2025-26318)
2 months 1 week ago
A vulnerability classified as problematic has been found in Khanakag-17 Library Management System up to 60ed174506094dcd166e34904a54288e5d10ff24. This affects an unknown function of the file /index.php. The manipulation of the argument msg leads to cross site scripting.
This vulnerability is referenced as CVE-2025-9755. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided.
vuldb.com
CVE-2025-9754 | Campcodes Online Hospital Management System 1.0 Edit Profile Page /edit-profile.php Username cross site scripting
2 months 1 week ago
A vulnerability described as problematic has been identified in Campcodes Online Hospital Management System 1.0. The impacted element is an unknown function of the file /edit-profile.php of the component Edit Profile Page. Executing manipulation of the argument Username can lead to cross site scripting.
The identification of this vulnerability is CVE-2025-9754. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-9753 | Campcodes Online Hospital Management System 1.0 Patient Search patient-search.php Search by Name Mobile No cross site scripting (EUVD-2025-26316)
2 months 1 week ago
A vulnerability marked as problematic has been reported in Campcodes Online Hospital Management System 1.0. The affected element is an unknown function of the file /admin/patient-search.php of the component Patient Search Module. Performing manipulation of the argument Search by Name Mobile No results in cross site scripting.
This vulnerability was named CVE-2025-9753. The attack may be initiated remotely. In addition, an exploit is available.
vuldb.com
Submit #640660: GitHub Library Management System 1.0 Cross Site Scripting [Accepted]
2 months 1 week ago
Submit #640660 / VDB-322056
0xSebin
CVE-2025-9752 | D-Link DIR-852 1.00CN B09 SOAP Service soap.cgi soapcgi_main service os command injection
2 months 1 week ago
A vulnerability labeled as critical has been found in D-Link DIR-852 1.00CN B09. Impacted is the function soapcgi_main of the file soap.cgi of the component SOAP Service. Such manipulation of the argument service leads to os command injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is uniquely identified as CVE-2025-9752. The attack can be launched remotely. Moreover, an exploit is present.
vuldb.com
Submit #640616: Campcodes Hospital Management System (Last Updated: August 18, 2024) Cross Site Scripting [Accepted]
2 months 1 week ago
Submit #640616 / VDB-322055
Yashh2
Submit #640609: Campcodes Hospital Management System (Last Updated: August 18, 2024) Cross Site Scripting [Accepted]
2 months 1 week ago
Submit #640609 / VDB-322054
Yashh2
CVE-2025-9751 | Campcodes Online Learning Management System 1.0 /login.php Username sql injection
2 months 1 week ago
A vulnerability identified as critical has been detected in Campcodes Online Learning Management System 1.0. This issue affects some unknown processing of the file /login.php. This manipulation of the argument Username causes sql injection.
This vulnerability is handled as CVE-2025-9751. The attack can be initiated remotely. Additionally, an exploit exists.
vuldb.com
CVE-2025-9750 | Campcodes Online Learning Management System 1.0 /admin/login.php Username sql injection (EUVD-2025-26313)
2 months 1 week ago
A vulnerability categorized as critical has been discovered in Campcodes Online Learning Management System 1.0. This vulnerability affects unknown code of the file /admin/login.php. The manipulation of the argument Username results in sql injection.
This vulnerability is known as CVE-2025-9750. It is possible to launch the attack remotely. Furthermore, an exploit is available.
vuldb.com
Submit #640590: D-Link DIR-852 1.00CN B09 Command Injection [Accepted]
2 months 1 week ago
Submit #640590 / VDB-322053
iC0rner