Posts of last few hours
A vulnerability was found in moxi159753 Mogu Blog v2 up to 5.2. It has been rated as critical. The affected element is an unknown function of the file /file/pictures. This manipulation of the argument filedatas causes unrestricted upload.
This vulnerability appears as CVE-2025-13815. The attack may be initiated remotely. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
https://vuldb.com/vuln/333824
A vulnerability categorized as critical has been discovered in moxi159753 Mogu Blog v2 up to 5.2. The impacted element is the function FileOperation.unzip of the file /networkDisk/unzipFile of the component ZIP File Handler. Such manipulation of the argument fileUrl leads to path traversal.
This vulnerability is traded as CVE-2025-13816. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
https://vuldb.com/vuln/333825
A vulnerability was found in Yohann0617 oci-helper up to 3.2.4 and classified as critical. This issue affects the function addCfg of the file src/main/java/com/yohann/ocihelper/service/impl/OciServiceImpl.java of the component OCI Configuration Upload. Executing a manipulation of the argument File can lead to path traversal.
This vulnerability is registered as CVE-2025-13875. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
https://vuldb.com/vuln/334031
A vulnerability was found in nocobase up to 1.9.4/2.0.0-alpha.37. It has been declared as problematic. The affected element is an unknown function of the file nocobase\packages\core\auth\src\base\jwt-service.ts of the component JWT Service. The manipulation of the argument API_KEY results in use of hard-coded cryptographic key
.
This vulnerability is reported as CVE-2025-13877. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
https://vuldb.com/vuln/334033
A vulnerability labeled as problematic has been found in ObjectPlanet Opinio 7.26 rev12562. Affected is an unknown function of the component survey-import. Executing a manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2025-13873. The attack can be executed remotely. There is not any exploit available.
https://vuldb.com/vuln/334037
A vulnerability was found in Schneider Electric EcoStruxure Power Build Rapsody. It has been classified as critical. Affected is an unknown function of the component SSD File Parser. This manipulation causes use after free.
This vulnerability is registered as CVE-2025-13845. Remote exploitation of the attack is possible. No exploit is available.
To fix this issue, it is recommended to deploy a patch.
https://vuldb.com/vuln/341396
A vulnerability classified as very critical was found in Schneider Electric EcoStruxure Power Build Rapsody. This affects an unknown function of the component SSD File Parser. Executing a manipulation can lead to double free.
The identification of this vulnerability is CVE-2025-13844. The attack may be launched remotely. There is no exploit available.
It is advisable to implement a patch to correct this issue.
https://vuldb.com/vuln/341405
A vulnerability marked as problematic has been reported in ESET Management Agent up to 12.5.2104.0. This vulnerability affects unknown code. This manipulation causes time-of-check time-of-use.
This vulnerability is tracked as CVE-2025-13818. The attack is restricted to local execution. No exploit exists.
https://vuldb.com/vuln/344678
A vulnerability categorized as critical has been discovered in MCPHub up to 0.10.x. Affected by this vulnerability is an unknown functionality of the component Endpoint. Such manipulation leads to authorization bypass.
This vulnerability is uniquely identified as CVE-2025-13822. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/357303
A vulnerability categorized as critical has been discovered in enquirer up to 2.4.1. Affected is the function Enquirer.set of the component Public Package API. The manipulation of the argument question.name results in improperly controlled modification of object prototype attributes.
This vulnerability is reported as CVE-2026-15187. The attack can be launched remotely. Moreover, an exploit is present.
The project was informed of the problem early through an issue report.
https://vuldb.com/vuln/377113
A vulnerability labeled as critical has been found in aerostackdev aerostack-mcp up to 6315dfde7df0a15aaf743f88d91347115e09ba23. Affected by this issue is the function upload_media of the component mcp-whatsapp. Such manipulation of the argument media_url leads to server-side request forgery.
This vulnerability is traded as CVE-2026-15189. The attack may be launched remotely. There is no exploit available.
This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases.
The project was informed of the problem early through an issue report but has not responded yet.
https://vuldb.com/vuln/377115
Plex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities. [...]
https://www.bleepingcomputer.com/news/security/plex-warns-users-to-patch-security-vulnerabilities-immediately/
A vulnerability was found in Online Diagnostic Lab Management System 1.0. It has been classified as critical. The impacted element is an unknown function of the file /tests/view_test.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is traded as CVE-2022-43162. It is possible to initiate the attack remotely. There is no exploit available.
https://vuldb.com/vuln/213870
A vulnerability marked as problematic has been reported in timg 1.4.4. The affected element is the function timg::QueryBackgroundColor of the file /timg/src/term-query.cc. Performing a manipulation results in memory leak.
This vulnerability is cataloged as CVE-2022-43151. The attack must originate from the local network. There is no exploit available.
https://vuldb.com/vuln/212560
A vulnerability described as critical has been identified in tsMuxer 2.6.16. The impacted element is the function BitStreamWriter::flushBits in the library /tsMuxer/bitStream.h. Executing a manipulation can lead to heap-based buffer overflow.
This vulnerability is registered as CVE-2022-43152. The attack requires access to the local network. No exploit is available.
https://vuldb.com/vuln/212561
A vulnerability labeled as critical has been found in rtf2html 0.2.0. Impacted is an unknown function of the file /rtf2html/./rtf_tools.h. Such manipulation leads to heap-based buffer overflow.
This vulnerability is listed as CVE-2022-43148. The attack must be carried out from within the local network. There is no available exploit.
https://vuldb.com/vuln/212559
CVE-2022-43144 | SourceCodester Canteen Management System 1.0 cross site scripting (EUVD-2022-46190)
A vulnerability was found in SourceCodester Canteen Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2022-43144. The attack may be performed from remote. There is no available exploit.
https://vuldb.com/vuln/213269
全球最大暗物质探测器 LUX-ZEPLIN(LZ)实验团队于 9 月 1 日在日本山形县天童市举办的 TeV 粒子天体物理大会上宣布探测器记录到一次不同寻常的高能闪光,它可能是穿行于银河系的大质量暗物质粒子与原子核发生碰撞所产生的。如果这一观测结果能得到更多数据的支持,或许意味着人们终于发现了暗物质。这种不可见的物质被认为维系着星系,防止其分裂。它同时也将证实,暗物质由质量远大于质子的粒子构成,即弱相互作用大质量粒子(WIMP)。研究人员分析了 2023 年 3 月-2024 年 4 月共计 220 天的观测数据。他们重点研究高能粒子撞击氙核产生的罕见闪光,这种撞击会使后者高速反冲。这个“超额”事件是一次反冲信号,在探测器中沉积了 248 千电子伏特的能量。LZ 合作组估算,能造成这种反冲的暗物质粒子的质量至少相当于 200 吉电子伏特,可能在 1000 吉电子伏特左右(1 吉电子伏特约等于一个质子的质量)。 LZ 合作组已经有效排除了放射性本底的干扰。
https://www.solidot.org/story?sid=85276
A vulnerability labeled as problematic has been found in FreeRDP up to 3.28.x. The affected element is an unknown function of the component Drive Redirection. The manipulation results in path traversal.
This vulnerability was named CVE-2026-67295. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
https://vuldb.com/vuln/385249
Latest Blog Posts
- 1 week 6 days ago
- 2 months 2 weeks ago
- 2 months 2 weeks ago
- 2 months 2 weeks ago
- 2 months 2 weeks ago
- 7 months 1 week ago
- 1 year ago
- 1 year ago
- 1 year 1 month ago
- 1 year 5 months ago