Aggregator
杰克・多尔西投资 1000 万美元助力非营利组织,推动去中心化社交技术发展
2 months ago
安全客
CVE-2025-50586 | StudentManage 1.0 cross-site request forgery (EUVD-2025-21902)
2 months ago
A vulnerability has been found in StudentManage 1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2025-50586. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-45157 | Splashin 2.0 on iOS Location Data permission (EUVD-2025-21904)
2 months ago
A vulnerability, which was classified as critical, was found in Splashin 2.0 on iOS. This affects an unknown part of the component Location Data Handler. The manipulation leads to permission issues.
This vulnerability is uniquely identified as CVE-2025-45157. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2025-49747 | Microsoft Azure Machine Learning authorization (EUVD-2025-21901)
2 months ago
A vulnerability, which was classified as very critical, has been found in Microsoft Azure Machine Learning. Affected by this issue is some unknown functionality. The manipulation leads to missing authorization.
This vulnerability is handled as CVE-2025-49747. The attack may be launched remotely. There is no exploit available.
This product is a managed service. It is not possible for users to maintain vulnerability countermeasures themselves.
vuldb.com
CVE-2025-49746 | Microsoft Azure Machine Learning improper authorization (EUVD-2025-21900)
2 months ago
A vulnerability classified as critical was found in Microsoft Azure Machine Learning. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper authorization.
This vulnerability is known as CVE-2025-49746. The attack can be launched remotely. There is no exploit available.
This product is available as a managed service. Users are not able to maintain vulnerability countermeasures themselves.
vuldb.com
CVE-2025-47995 | Microsoft Azure Machine Learning weak authentication (EUVD-2025-21914)
2 months ago
A vulnerability classified as problematic has been found in Microsoft Azure Machine Learning. Affected is an unknown function. The manipulation leads to weak authentication.
This vulnerability is traded as CVE-2025-47995. It is possible to launch the attack remotely. There is no exploit available.
This product is a managed service. This means that users are not able to maintain vulnerability countermeasures themselves.
vuldb.com
Submit #616770: codeprojects Food Ordering Review System V1.0 SQL Injection [Accepted]
2 months ago
Submit #616770 / VDB-316918
n0name
CVE-2025-47158 | Microsoft Azure DevOps authentication bypass by assumed-immutable data (EUVD-2025-21915)
2 months ago
A vulnerability was found in Microsoft Azure DevOps. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to authentication bypass by assumed-immutable data.
The identification of this vulnerability is CVE-2025-47158. The attack may be initiated remotely. There is no exploit available.
This product is a managed service. It is not possible for users to maintain vulnerability countermeasures themselves.
vuldb.com
CVE-2025-45156 | Splashin 2.0 on iOS Location Update access control (EUVD-2025-21905)
2 months ago
A vulnerability was found in Splashin 2.0 on iOS. It has been declared as critical. This vulnerability affects unknown code of the component Location Update Handler. The manipulation leads to improper access controls.
This vulnerability was named CVE-2025-45156. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
PoisonSeed Tricking Users Into Bypassing FIDO Keys With QR Codes
2 months ago
PoisonSeed group tricks users into bypassing FIDO Keys by misusing QR code logins, highlighting new social engineering risk to secure MFA.
Waqas
CVE-2025-52162 | Agorum Core Open 11.9.2/11.10.1 RSSReader Endpoint xml external entity reference (EUVD-2025-21899)
2 months ago
A vulnerability was found in Agorum Core Open 11.9.2/11.10.1. It has been classified as problematic. This affects an unknown part of the component RSSReader Endpoint. The manipulation leads to xml external entity reference.
This vulnerability is uniquely identified as CVE-2025-52162. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2025-7783 | form-data up to 2.5.3/3.0.2/4.0.2 HTTP Parameter lib/form_data.Js random values
2 months ago
A vulnerability was found in form-data up to 2.5.3/3.0.2/4.0.2 and classified as problematic. Affected by this issue is some unknown functionality in the library lib/form_data.Js of the component HTTP Parameter Handler. The manipulation leads to insufficiently random values.
This vulnerability is handled as CVE-2025-7783. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-53762 | Microsoft Purview permissive list of allowed inputs (EUVD-2025-21916)
2 months ago
A vulnerability has been found in Microsoft Purview and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to permissive list of allowed inputs.
This vulnerability is known as CVE-2025-53762. The attack can be launched remotely. There is no exploit available.
This product is available as a managed service. Users are not able to maintain vulnerability countermeasures themselves.
vuldb.com
CVE-2025-27210
2 months ago
Currently trending CVE - Hype Score: 1
Пропустили патч? Получите .NET-шпиона прямо в почтовом сервере
2 months ago
GhostContainer оживил CVE-2020-0688 — и вшился в Exchange навсегда.
Live Webinar | Bot or Not Isn’t Good Enough: Rethinking Bot Protection for the Age of AI Agents
2 months ago
AI, Cloud & Compliance: Mastering Data Security for Financial Services in a Hyper-Regulated Era
2 months ago
Crypto ATM Crackdown: British Cops Bust Suspected Operators
2 months ago
As Crypto ATMs Facilitate Scams and Money Laundering, More Governments Take Aim
Attackers Target Legacy Code in TeleMessage's Signal Clone
2 months ago
Multiple US Government Agencies Have Used the Now-Patched Message Archiving App
Attackers are actively attempting to exploit a vulnerability that exists in older versions of the Signal message app clone TeleMessage TM SGNL, built by Smarsh to keep copies of all communications, including the ability to comply with federal record-keeping requirements.
Attackers are actively attempting to exploit a vulnerability that exists in older versions of the Signal message app clone TeleMessage TM SGNL, built by Smarsh to keep copies of all communications, including the ability to comply with federal record-keeping requirements.