Aggregator
Drawn to Danger: Windows Graphics Vulnerabilities Lead to Remote Code Execution and Memory Exposure
2 days 13 hours ago
Background Check Point Research (CPR) identified three security vulnerabilities in the Graphics Device Interface (GDI) in Windows. We promptly reported these issues to Microsoft, and they were addressed in the Patch Tuesday updates in May, July, and August 2025. These are the vulnerabilities: Vulnerability disclosures such as these highlight the need for proactive measures to mitigate potential risks. […]
The post Drawn to Danger: Windows Graphics Vulnerabilities Lead to Remote Code Execution and Memory Exposure appeared first on Check Point Research.
CVE-2025-12617 | itsourcecode Billing System 1.0 login_crud.php Password sql injection (EUVD-2025-37471)
2 days 13 hours ago
A vulnerability was found in itsourcecode Billing System 1.0. It has been declared as critical. This affects an unknown function of the file /admin/app/login_crud.php. Executing manipulation of the argument Password can lead to sql injection.
This vulnerability is registered as CVE-2025-12617. It is possible to launch the attack remotely. Furthermore, an exploit is available.
vuldb.com
От домофона до $256 тысяч в сумке. Москвичку обманули на 28 миллионов — через «кодировку ключей» и видеозвонок с «полицией»
2 days 13 hours ago
Пенсионерка поверила телефонным аферистам и отдала им все свои сбережения.
Submit #678829: Loan Management System 1.0.0 SQL Injection [Duplicate]
2 days 13 hours ago
Submit #678829 / VDB-322043
pegasus
CVE-2025-12616 | PHPGurukul News Portal 1.0 /onps/settings.py insertion of sensitive information into debugging code (EUVD-2025-37472)
2 days 13 hours ago
A vulnerability was found in PHPGurukul News Portal 1.0. It has been classified as problematic. The impacted element is an unknown function of the file /onps/settings.py. Performing manipulation results in insertion of sensitive information into debugging code.
This vulnerability is cataloged as CVE-2025-12616. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #678665: itsourcecode Company The billing system 1.0 SQL Injection [Accepted]
2 days 13 hours ago
Submit #678665 / VDB-330911
liule960117
CVE-2025-12615 | PHPGurukul News Portal 1.0 /onps/settings.py SECRET_KEY hard-coded key (EUVD-2025-37470)
2 days 13 hours ago
A vulnerability was found in PHPGurukul News Portal 1.0 and classified as problematic. The affected element is an unknown function of the file /onps/settings.py. Such manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key
.
This vulnerability is listed as CVE-2025-12615. The attack may be performed from remote. In addition, an exploit is available.
vuldb.com
Submit #678664: SourceCodester Company Gas Station Management System 1.0 SQL Injection [Duplicate]
2 days 13 hours ago
Submit #678664 / VDB-255375
liule960117
Submit #678649: PHPGurukul News Portal using Python Django and MySQL 1.0 Insertion of Sensitive Information Into Debugging Code [Accepted]
2 days 13 hours ago
Submit #678649 / VDB-330910
Nishant_Kumar
CVE-2025-12614 | SourceCodester Best House Rental Management System 1.0 /admin_class.php delete_payment ID sql injection (EUVD-2025-37469)
2 days 13 hours ago
A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as critical. Impacted is the function delete_payment of the file /admin_class.php. This manipulation of the argument ID causes sql injection.
This vulnerability is tracked as CVE-2025-12614. The attack is possible to be carried out remotely. Moreover, an exploit is present.
vuldb.com
Submit #678625: PHPGurukul News Portal using Python Django and MySQL 1.0 Use of Hard-coded Cryptographic Key [Accepted]
2 days 14 hours ago
Submit #678625 / VDB-330909
Nishant_Kumar
Submit #678184: sourcecodester Best house rental management system 1.0 SQL Injection [Accepted]
2 days 14 hours ago
Submit #678184 / VDB-330908
qi_nice
Zine#44 - 善意、远离手机、阅读、万圣节主题
2 days 14 hours ago
这篇文章主要介绍了作者整理订阅流的方法及其效果,并分享了多个领域的资源与思考。其中包括用户体验优化的文章、QWERTY键盘布局的历史分析、如何成为博学多才的方法、AI工具隐私问题探讨以及一些工具推荐等。此外还包含了一些摘录与多媒体内容。
Steam 用户中 Linux 比例超过 3%
2 days 14 hours ago
Valve 公布的 2025 年 10 月 Steam 硬件和软件调查显示,玩家运行的操作系统中 Linux 比例突破 3% 达到 3.05%(增加 0.41%),Windows 多年来首次跌至 95% 以内占 94.84%,OSX 占 2.11%。上一次 Linux 用户比例接近 3% 还是十年前,Linux 使用增长的趋势主要受到掌机 Steam Deck 的推动。在所有 Linux 操作系统中,Steam Deck 运行的 SteamOS 占 27%,AMD CPU 占 67.1%,英特尔占 32.89%。而在 Windows 平台,英特尔占 57.8%,AMD 占 42%。对于用户使用的语言,简体中文占 24.01%,英文占 37.96%。
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 69
2 days 14 hours ago
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques Uncovering Qilin attack methods exposed through multiple cases Mem3nt0 mori – The Hacking Team is back! Insider Threats Loom […]
Pierluigi Paganini
Security Affairs newsletter Round 548 by Pierluigi Paganini – INTERNATIONAL EDITION
2 days 14 hours ago
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. BadCandy Webshell threatens unpatched Cisco IOS XE devices, warns Australian government China-linked UNC6384 exploits Windows zero-day […]
Pierluigi Paganini
Brekelmans en Eichelsheim in Midden-Oosten voor defensietop
2 days 14 hours ago
“Veiligheid in Europa en het Midden-Oosten zijn nauw met elkaar verbonden.” Dat zei demissionair minister Ruben Brekelmans tijdens de IISS Manama Dialogue in Bahrein, de vooraanstaande internationale veiligheidsconferentie in het Midden-Oosten. De minister maakt momenteel samen met Commandant der Strijdkrachten (CDS) generaal Onno Eichelsheim een rondreis door het gebied. Ze bezoeken Bahrein, Qatar, Jordanië en Libanon. Het aanhalen van de banden met landen in het Midden-Oosten staat in deze reis centraal.
«Мы не такие уникальные, как думали». ИИ понял язык на уровне лингвистов — и поставил под сомнение границы человеческого мышления
2 days 15 hours ago
Речь была последним козырем человечества. Но умные машины научились проникать и туда.
CSPT漏洞浅析 - 飘渺红尘✨
2 days 15 hours ago
CSPT全称是Client-Side Path Traversal ,即客户端路径遍历。 概念说明 CSPT 全称 Client-Side Path Traversal(客户端路径遍历),是一种针对前端应用的漏洞,核心是攻击者通过篡改 URL 参数、请求参数等,让浏览器(客户端)错误地向非预期的服务
飘渺红尘✨