Aggregator
CVE-2010-2133 | Mylittleforum My Little Forum 2.1.4 contact.php ID sql injection (EDB-11616 / XFDB-56618)
9 months ago
A vulnerability marked as critical has been reported in Mylittleforum My Little Forum 2.1.4. This affects an unknown function of the file contact.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is referenced as CVE-2010-2133. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
vuldb.com
CVE-2010-5096 | MyBB up to 1.1.8 search.php keywords sql injection (ID 1330 / EDB-35141)
9 months ago
A vulnerability was found in MyBB and classified as critical. This issue affects some unknown processing of the file search.php. Such manipulation of the argument keywords leads to sql injection.
This vulnerability is traded as CVE-2010-5096. The attack may be launched remotely. Furthermore, there is an exploit available.
There are still doubts about whether this vulnerability truly exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2010-4982 | Mykazaam Address / Contact Organizer var1 sql injection (EDB-14326 / XFDB-60269)
9 months ago
A vulnerability identified as critical has been detected in Mykazaam Address and Contact Organizer. The affected element is an unknown function. The manipulation of the argument var1 leads to sql injection.
This vulnerability is referenced as CVE-2010-4982. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
vuldb.com
CVE-2010-4984 | Mykazaam Notes Management System notes.php sql injection (EDB-14325 / XFDB-60254)
9 months ago
A vulnerability marked as critical has been reported in Mykazaam Notes Management System. This affects an unknown function of the file notes.php. This manipulation causes sql injection.
This vulnerability is tracked as CVE-2010-4984. The attack is possible to be carried out remotely. Moreover, an exploit is present.
vuldb.com
CVE-2010-4985 | Mykazaam Notes Management System notes.php cross site scripting (EDB-14325 / XFDB-60253)
9 months ago
A vulnerability described as problematic has been identified in Mykazaam Notes Management System. This impacts an unknown function of the file notes.php. Such manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2010-4985. The attack may be performed from remote. In addition, an exploit is available.
vuldb.com
CVE-2010-1499 | Musicboxv2 MusicBox 3.3 genre_artists.php ID sql injection (EDB-12303 / XFDB-57979)
9 months ago
A vulnerability labeled as critical has been found in Musicboxv2 MusicBox 3.3. This vulnerability affects unknown code of the file genre_artists.php. The manipulation of the argument ID results in sql injection.
This vulnerability is reported as CVE-2010-1499. The attack can be launched remotely. Moreover, an exploit is present.
vuldb.com
CVE-2025-59799 | Artifex Ghostscript up to 10.05.1 gdevpdfm.c pdfmark_coerce_dest size stack-based overflow (EUVD-2025-30395 / Nessus ID 265894)
9 months ago
A vulnerability, which was classified as critical, was found in Artifex Ghostscript up to 10.05.1. Affected by this issue is the function pdfmark_coerce_dest of the file devices/vector/gdevpdfm.c. The manipulation of the argument size results in stack-based buffer overflow.
This vulnerability is cataloged as CVE-2025-59799. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-59798 | Artifex Ghostscript up to 10.05.1 gdevpdtw.c pdf_write_cmap stack-based overflow (EUVD-2025-30394 / Nessus ID 265893)
9 months ago
A vulnerability has been found in Artifex Ghostscript up to 10.05.1 and classified as critical. This affects the function pdf_write_cmap of the file devices/vector/gdevpdtw.c. This manipulation causes stack-based buffer overflow.
This vulnerability is registered as CVE-2025-59798. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2025-59692 | PureVPN Client Application CLI 2.0.1/GUI 2.10.0 on Linux Network Traffic resource transfer (EUVD-2025-30226 / Nessus ID 265898)
9 months ago
A vulnerability classified as problematic has been found in PureVPN Client Application CLI 2.0.1/GUI 2.10.0 on Linux. This affects an unknown part of the component Network Traffic Handler. The manipulation leads to incorrect resource transfer.
This vulnerability is listed as CVE-2025-59692. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2022-50415 | Linux Kernel up to 6.1.3 parisc start_task null pointer dereference (Nessus ID 265900 / WID-SEC-2025-2092)
9 months ago
A vulnerability classified as critical was found in Linux Kernel up to 6.1.3. This affects the function start_task of the component parisc. Executing manipulation can lead to null pointer dereference.
This vulnerability appears as CVE-2022-50415. The attacker needs to be present on the local network. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
【情报】以色列情报机构摩萨德的局长大卫·巴内亚(David Barnea)
9 months ago
以色列三个情报机构:负责军事情报的“阿曼”(AMAN)、负责内部安全的“辛贝特”(Shin Bet)以及直接向以色列总理汇报的“摩萨德”(Mossad)。据估计,摩萨德约有7000名直接或间接的工作人员,使其成为世界上最大的情报机构之一。
EU probes SAP over anti-competitive ERP support practices
9 months ago
The European Comission is investigating potential anti-competitive practices in aftermarket services SAP provides for its on-premise ERP software. [...]
Bill Toulas
CVE-2025-11106 | code-projects Simple Scheduling System 1.0 addfaculty.php falname sql injection
9 months ago
A vulnerability classified as critical was found in code-projects Simple Scheduling System 1.0. This vulnerability affects unknown code of the file /schedulingsystem/addfaculty.php. Such manipulation of the argument falname leads to sql injection.
This vulnerability is documented as CVE-2025-11106. The attack can be executed remotely. Additionally, an exploit exists.
vuldb.com
研究发现过去 15 年睡眠问题日益严重
9 months ago
睡眠对身心健康至关重要,而年轻成年人的睡眠问题成为了一项重大的公共卫生挑战。根据发表在《Science Advances》期刊上的一项研究,丹麦研究人员调查了该国出生于 1980-2015 年的 220 万人口的数据,发现 15-45 岁人群自我报告有睡眠问题的比例从 2010 年的 34% 增至 2021 年的 49%,帮助睡眠的褪黑素使用量增加了 10 倍——开褪黑素处方的比例从每千人 2.43 增加到 20.9。
Ваш роутер стал работать хуже? Проверьте — миллионы устройств уже добывают криптовалюту для хакеров
9 months ago
Схема работает прямо сейчас — в миллионах квартир по всему миру.
CVE-2024-43192 | IBM Storage TS4500 Library 1.11.0.0/2.11.0.0 cross-site request forgery (EUVD-2024-55025 / CNNVD-202509-4272)
9 months ago
A vulnerability described as problematic has been identified in IBM Storage TS4500 Library 1.11.0.0/2.11.0.0. The affected element is an unknown function. Such manipulation leads to cross-site request forgery.
This vulnerability is documented as CVE-2024-43192. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-36239 | IBM Storage TS4500 Library 1.11.0.0/2.11.0.0 Web UI cross site scripting (EUVD-2025-31399 / CNNVD-202509-4271)
9 months ago
A vulnerability classified as problematic was found in IBM Storage TS4500 Library 1.11.0.0/2.11.0.0. This affects an unknown function of the component Web UI. Executing manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2025-36239. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-59939 | LabRedesCefetRJ WeGIA up to 3.4.x control.php id_produto sql injection (GHSA-jx9m-pgf8-v489 / EUVD-2025-31395)
9 months ago
A vulnerability classified as critical has been found in LabRedesCefetRJ WeGIA up to 3.4.x. The impacted element is an unknown function of the file control.php. Performing manipulation of the argument id_produto results in sql injection.
This vulnerability is reported as CVE-2025-59939. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-59932 | FlagForgeCTF flagForge up to 2.3.0 /api/resources improper authorization (GHSA-v8rh-25rf-gfqw / EUVD-2025-31401)
9 months ago
A vulnerability, which was classified as critical, has been found in FlagForgeCTF flagForge up to 2.3.0. This impacts an unknown function of the file /api/resources. The manipulation leads to improper authorization.
This vulnerability is traded as CVE-2025-59932. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com