A 55-year-old Chinese national has been sentenced to four years in prison and three years of supervised release for sabotaging his former employer's network with custom malware and deploying a kill switch that locked out employees when his account was disabled.
Davis Lu, 55, of Houston, Texas, was convicted of causing intentional damage to protected computers in March 2025. He was arrested and
A vulnerability was found in Apache OFBiz. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the component scrum Plugin. Performing manipulation results in code injection.
This vulnerability was named CVE-2025-54466. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability, which was classified as problematic, has been found in DogukanUrker flaskBlog up to 2.8.1. Affected by this issue is some unknown functionality of the file /createpost of the component POST Request Handler. This manipulation causes cross site scripting.
This vulnerability is tracked as CVE-2025-53631. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability was found in projectworlds Travel Management System 1.0. It has been declared as critical. Impacted is an unknown function of the file /updatepackage.php. Such manipulation of the argument s1 leads to sql injection.
This vulnerability is referenced as CVE-2025-9052. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability was found in projectworlds Travel Management System 1.0. It has been rated as critical. The affected element is an unknown function of the file /updatesubcategory.php. Performing manipulation of the argument t1/s1 results in sql injection.
This vulnerability is identified as CVE-2025-9053. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability, which was classified as very critical, was found in IBM Storage Virtualize 8.4/8.5/8.6/8.7. The impacted element is an unknown function of the component SSH Session Handler. The manipulation results in incorrect authorization.
This vulnerability was named CVE-2025-36120. The attack may be performed from a remote location. There is no available exploit.
You should upgrade the affected component.
A vulnerability has been found in IBM Concert Software up to 1.1.0 and classified as problematic. This affects an unknown function. This manipulation causes exposure of sensitive information due to incompatible policies.
The identification of this vulnerability is CVE-2024-49827. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
A vulnerability was found in IBM Concert Software up to 1.1.0. It has been classified as problematic. Affected is an unknown function of the component Trusted Domain Handler. Performing manipulation results in permissive cross-domain policy with untrusted domains.
This vulnerability is identified as CVE-2025-27909. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in IBM Concert Software up to 1.1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. Executing manipulation can lead to inefficient regular expression complexity.
This vulnerability is tracked as CVE-2025-33090. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability was found in IBM Concert Software up to 1.1.0. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to hard-coded credentials.
This vulnerability is listed as CVE-2025-33100. The attack must be carried out locally. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability categorized as problematic has been discovered in IBM Concert Software up to 1.1.0. This affects an unknown part. The manipulation results in improper clearing of heap memory before release.
This vulnerability is cataloged as CVE-2025-1759. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability was found in GoogleTag Manager up to 1.9.x on Drupal. It has been rated as problematic. The impacted element is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-8362. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability described as critical has been identified in AI SEO Link Advisor up to 1.0.5 on Drupal. Affected by this issue is some unknown functionality. Executing manipulation can lead to server-side request forgery.
This vulnerability is tracked as CVE-2025-8675. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability was found in FirebirdSQL Firebird up to 3.0.12/4.0.5/5.0.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component XDR Message Handler. The manipulation results in null pointer dereference.
This vulnerability was named CVE-2025-54989. The attack may be performed from a remote location. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in PHPGurukul Zoo Management System 2.1. Affected by this vulnerability is an unknown functionality of the file /admin/add-foreigner-ticket.php. Performing manipulation of the argument visitorname results in cross site scripting.
This vulnerability is reported as CVE-2025-9017. The attack is possible to be carried out remotely. Moreover, an exploit is present.