Aggregator
CVE-2010-0691 | Jtl-software JTL-Shop 2 druckansicht.php s sql injection (EDB-11445 / SA38588)
9 months 1 week ago
A vulnerability labeled as critical has been found in Jtl-software JTL-Shop 2. Impacted is an unknown function of the file druckansicht.php. The manipulation of the argument s results in sql injection.
This vulnerability is identified as CVE-2010-0691. The attack can be executed remotely. Additionally, an exploit exists.
vuldb.com
CVE-2010-4360 | Jurpo Jurpopage 0.2.0 index.php sql injection (EDB-15621 / BID-45076)
9 months 1 week ago
A vulnerability, which was classified as critical, has been found in Jurpo Jurpopage 0.2.0. This impacts an unknown function of the file index.php. Performing manipulation results in sql injection.
This vulnerability is identified as CVE-2010-4360. The attack can be initiated remotely. Additionally, an exploit exists.
vuldb.com
CVE-2010-0759 | Greatjoomla Scriptegrator plugin 1.4.1 Libraries jsloader.php files[] path traversal (EDB-11498 / Nessus ID 44674)
9 months 1 week ago
A vulnerability, which was classified as problematic, has been found in Greatjoomla Scriptegrator plugin 1.4.1. This vulnerability affects unknown code in the library plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php of the component Libraries. Performing manipulation of the argument files[] results in path traversal.
This vulnerability is identified as CVE-2010-0759. The attack can be initiated remotely. Additionally, an exploit exists.
vuldb.com
CVE-2010-0760 | Greatjoomla Scriptegrator plugin 1.4.1 Libraries jsloader.php files[] path traversal (EDB-11498 / SA38637)
9 months 1 week ago
A vulnerability, which was classified as problematic, was found in Greatjoomla Scriptegrator plugin 1.4.1. This issue affects some unknown processing in the library plugins/system/cdscriptegrator/libraries/jquery/js/ui/jsloader.php of the component Libraries. Executing manipulation of the argument files[] can lead to path traversal.
This vulnerability is tracked as CVE-2010-0760. The attack can be launched remotely. Moreover, an exploit is present.
vuldb.com
CVE-2010-1602 | Zimbllc Com Zimbcomment 0.8.1 index.php controller path traversal (EDB-12283 / Nessus ID 43636)
9 months 1 week ago
A vulnerability described as problematic has been identified in Zimbllc Com Zimbcomment 0.8.1. This impacts an unknown function of the file index.php. The manipulation of the argument controller results in path traversal.
This vulnerability is cataloged as CVE-2010-1602. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2010-1603 | Zimbllc Com Zimbcore 0.1 index.php controller path traversal (EDB-12284 / BID-39546)
9 months 1 week ago
A vulnerability classified as problematic has been found in Zimbllc Com Zimbcore 0.1. Affected is an unknown function of the file index.php. This manipulation of the argument controller causes path traversal.
This vulnerability is registered as CVE-2010-1603. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
vuldb.com
CVE-2010-2923 | Prasanna Com Youtube 1.5 index.php id_cate sql injection (EDB-14467 / XFDB-60624)
9 months 1 week ago
A vulnerability classified as critical has been found in Prasanna Com Youtube 1.5. This affects an unknown part of the file index.php. The manipulation of the argument id_cate leads to sql injection.
This vulnerability is documented as CVE-2010-2923. The attack can be initiated remotely. Additionally, an exploit exists.
vuldb.com
CVE-2010-5053 | Php-shop-system Com Xobbix 1.0.1 index.php prodid sql injection (EDB-12097 / BID-39259)
9 months 1 week ago
A vulnerability has been found in Php-shop-system Com Xobbix 1.0.1 and classified as critical. Affected by this issue is some unknown functionality of the file index.php. The manipulation of the argument prodid leads to sql injection.
This vulnerability is traded as CVE-2010-5053. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Говорили «невозможно взломать» — русский хакер получил награду за лучший взлом Linux
9 months 1 week ago
Случайность стала новым правилом, а привычные барьеры просто исчезли.
静界全功能版本
9 months 1 week ago
Aembit Named to Fast Company’s Seventh-Annual List of the 100 Best Workplaces for Innovators
9 months 1 week ago
Silver Spring, USA, 9th September 2025, CyberNewsWire
CyberNewswire
Chinese Cyber Espionage Campaign Impersonates US Congressman
9 months 1 week ago
A House select committee said Chinese actors impersonated Representative John Moolenaar to steal information that could be used to influence trade talks
Сначала — бан, потом — 19 трупов. Непал отменил блокировку соцсетей
9 months 1 week ago
Непальские граждане вышли на улицы за соцсети и победили.
[Webinar] Shadow AI Agents Multiply Fast — Learn How to Detect and Control Them
9 months 1 week ago
⚠️ One click is all it takes.
An engineer spins up an “experimental” AI Agent to test a workflow. A business unit connects to automate reporting. A cloud platform quietly enables a new agent behind the scenes.
Individually, they look harmless. But together, they form an invisible swarm of Shadow AI Agents—operating outside security’s line of sight, tied to identities you don’t even know exist.
The Hacker News
CVE-2025-1688 | Milestone Systems XProtect VMS up to 24.2 Installer missing encryption
9 months 1 week ago
A vulnerability classified as problematic was found in Milestone Systems XProtect VMS up to 24.2. This issue affects some unknown processing of the component Installer. Such manipulation leads to missing encryption of sensitive data.
This vulnerability is uniquely identified as CVE-2025-1688. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-24404 | Apache HertzBeat up to 1.6.x HTTP Sitemap XML Response Parser xml injection
9 months 1 week ago
A vulnerability classified as critical has been found in Apache HertzBeat up to 1.6.x. This affects an unknown function of the component HTTP Sitemap XML Response Parser. The manipulation leads to xml injection.
This vulnerability is traded as CVE-2025-24404. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-48208 | Apache Hertzbeat up to 1.7.1 JNDI ldap injection
9 months 1 week ago
A vulnerability classified as critical was found in Apache Hertzbeat up to 1.7.1. This impacts an unknown function of the component JNDI Handler. The manipulation results in ldap injection.
This vulnerability is known as CVE-2025-48208. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-10134 | Nonprofit Charity Theme up to 3.2.2 on WordPress alone_import_pack_restore_data authorization
9 months 1 week ago
A vulnerability was found in Nonprofit Charity Theme up to 3.2.2 on WordPress. It has been declared as critical. This impacts the function alone_import_pack_restore_data. The manipulation results in missing authorization.
This vulnerability is reported as CVE-2025-10134. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2025-9539 | AutomatorWP Plugin up to 5.3.6 on WordPress automatorwp_ajax_import_automation_from_url authorization
9 months 1 week ago
A vulnerability was found in AutomatorWP Plugin up to 5.3.6 on WordPress. It has been rated as critical. Affected is the function automatorwp_ajax_import_automation_from_url. This manipulation causes missing authorization.
This vulnerability appears as CVE-2025-9539. The attack may be initiated remotely. There is no available exploit.
vuldb.com