Aggregator
CVE-2025-6345 | SourceCodester My Food Recipe 1.0 Add Recipe Page /endpoint/add-recipe.php addRecipeModal Name cross site scripting
9 months 2 weeks ago
A vulnerability was found in SourceCodester My Food Recipe 1.0 and classified as problematic. Affected by this issue is the function addRecipeModal of the file /endpoint/add-recipe.php of the component Add Recipe Page. The manipulation of the argument Name leads to cross site scripting.
This vulnerability is handled as CVE-2025-6345. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6344 | code-projects Online Shoe Store 1.0 /contactus.php email sql injection
9 months 2 weeks ago
A vulnerability has been found in code-projects Online Shoe Store 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /contactus.php. The manipulation of the argument email leads to sql injection.
This vulnerability is known as CVE-2025-6344. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6343 | code-projects Online Shoe Store 1.0 /admin/admin_product.php pid sql injection
9 months 2 weeks ago
A vulnerability, which was classified as critical, was found in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /admin/admin_product.php. The manipulation of the argument pid leads to sql injection.
This vulnerability is traded as CVE-2025-6343. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6342 | code-projects Online Shoe Store 1.0 admin_football.php pid sql injection
9 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in code-projects Online Shoe Store 1.0. This issue affects some unknown processing of the file /admin/admin_football.php. The manipulation of the argument pid leads to sql injection.
The identification of this vulnerability is CVE-2025-6342. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
基础奖励再翻倍!奖励提升计划已更新至V8.0
9 months 2 weeks ago
福利加码,每份努力都超值得💥详情戳--
Submit #597093: SourceCodester My Food Recipe 1.0 Stored Cross Site Scripting [Accepted]
9 months 2 weeks ago
Submit #597093 / VDB-313340
RaulPACXXX
CVE-2025-6341 | code-projects School Fees Payment System 1.0 cross-site request forgery
9 months 2 weeks ago
A vulnerability classified as problematic was found in code-projects School Fees Payment System 1.0. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2025-6341. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6340 | code-projects School Fees Payment System 1.0 /branch.php Branch/Address/Detail cross site scripting
9 months 2 weeks ago
A vulnerability classified as problematic has been found in code-projects School Fees Payment System 1.0. This affects an unknown part of the file /branch.php. The manipulation of the argument Branch/Address/Detail leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-6340. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Sophisticated Phishing Attack Uses ASP Pages to Target Prominent Russia Critics – Google
9 months 2 weeks ago
Google Threat Intelligence Group (GTIG), in collaboration with external partners, has uncovered a sophisticated phishing campaign orchestrated by a Russia state-sponsored cyber threat actor, tracked as UNC6293. Active from at least April through early June 2025, this campaign specifically targeted prominent academics and critics of Russia. GTIG assesses with low confidence that UNC6293 is associated […]
The post Sophisticated Phishing Attack Uses ASP Pages to Target Prominent Russia Critics – Google appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Aman Mishra
Submit #597045: code-projects Online Shoe Store V1.0 SQL Injection [Accepted]
9 months 2 weeks ago
Submit #597045 / VDB-313339
Customer
Submit #597044: code-projects Online Shoe Store V1.0 SQL Injection [Accepted]
9 months 2 weeks ago
Submit #597044 / VDB-313338
Customer
Submit #597043: code-projects Online Shoe Store V1.0 SQL Injection [Accepted]
9 months 2 weeks ago
Submit #597043 / VDB-313337
Customer
Депутаты предложили СМС о том, что СМС не будет
9 months 2 weeks ago
Главе Минцифры предлагают писать людям, когда всё молчит.
Submit #597023: code-projects School Fees Payment System 1.0 Cross-Site Request Forgery [Accepted]
9 months 2 weeks ago
Submit #597023 / VDB-313336
DS_Leo
Submit #596998: code-projects School Fees Payment System 1.0 Cross Site Scripting [Accepted]
9 months 2 weeks ago
Submit #596998 / VDB-313335
DS_Leo
Submit #596997: PHPGurukul Tourism Management System V1.0 Unrestricted Upload [Duplicate]
9 months 2 weeks ago
Submit #596997 / VDB-260918
Customer
CVE-2025-6339 | ponaravindb Hospital Management System 1.0 /func3.php username1 sql injection
9 months 2 weeks ago
A vulnerability was found in ponaravindb Hospital Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /func3.php. The manipulation of the argument username1 leads to sql injection.
This vulnerability is handled as CVE-2025-6339. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6337 | TOTOLINK A3002R/A3002RU 3.0.0-B20230809.1615/4.0.0-B20230531.1404 HTTP POST Request /boafrm/formTmultiAP submit-url buffer overflow
9 months 2 weeks ago
A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615/4.0.0-B20230531.1404. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formTmultiAP of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow.
This vulnerability is known as CVE-2025-6337. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #596744: GitHub ponaravindb Hospital-Management-System v1.0 sql injection [Accepted]
9 months 2 weeks ago
Submit #596744 / VDB-313334
Xuqiang