Aggregator
NAVO en defensie-industrie samen sterk tegen oorlogsdreiging (video)
2 months 2 weeks ago
NAVO-landen en de defensie-industrie hebben elkaar gevonden, zo blijkt. Het NATO Summit Defence Industry Forum (NSDIF) leverde veel nieuwe afspraken en initiatieven op. Hiermee wordt de productiecapaciteit van wapens, munitie en militaire technologieën versneld uitgebreid en versterkt.
CVE-2021-4457 | ZoomSounds Plugin up to 6.04 on WordPress unrestricted upload (EUVD-2021-34682)
2 months 2 weeks ago
A vulnerability classified as critical has been found in ZoomSounds Plugin up to 6.04 on WordPress. Affected is an unknown function. The manipulation leads to unrestricted upload.
This vulnerability is traded as CVE-2021-4457. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-27685 | PHPGurukul Student Record System 3.20 cshortname/cfullname/cdate sql injection
2 months 2 weeks ago
A vulnerability was found in PHPGurukul Student Record System 3.20. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument cshortname/cfullname/cdate leads to sql injection.
The identification of this vulnerability is CVE-2024-27685. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-6669 | gooaclok819 sublinkX up to 1.8 middlewares/jwt.go hard-coded key (Issue 69 / EUVD-2025-19165)
2 months 2 weeks ago
A vulnerability was found in gooaclok819 sublinkX up to 1.8. It has been declared as problematic. This vulnerability affects unknown code of the file middlewares/jwt.go. The manipulation with the input sublink leads to use of hard-coded cryptographic key
.
This vulnerability was named CVE-2025-6669. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
NSA and CISA Urge Adoption of Memory Safe Languages for Safety
2 months 2 weeks ago
NSA and CISA are urging developers to adopt memory safe languages (MSLs) to combat vulnerabilities in software
CVE-2025-6668 | code-projects Inventory Management System 1.0 fetchSelectedBrand.php brandId sql injection (EUVD-2025-19140)
2 months 2 weeks ago
A vulnerability was found in code-projects Inventory Management System 1.0. It has been classified as critical. This affects an unknown part of the file /php_action/fetchSelectedBrand.php. The manipulation of the argument brandId leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-6668. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
FONPER Falls Victim to INC RANSOM Ransomware
2 months 2 weeks ago
FONPER Falls Victim to INC RANSOM Ransomware
Dark Web Informer - Cyber Threat Intelligence
Твоя наивность — чей-то бизнес
2 months 2 weeks ago
Почему кибераферы на концертах стали нормой.
CVE-2025-6667 | code-projects Car Rental System 1.0 /admin/add_cars.php image unrestricted upload (EUVD-2025-19141)
2 months 2 weeks ago
A vulnerability was found in code-projects Car Rental System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/add_cars.php. The manipulation of the argument image leads to unrestricted upload.
This vulnerability is handled as CVE-2025-6667. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
运送近百辆电动汽车的货船起火沉没
2 months 2 weeks ago
6 月 23日 下午,一艘载有 3000 多辆包括纯电动汽车(EV)在内的汽车运输船在从中国驶往墨西哥的途中,于美国阿拉斯加州海域沉没。该船于 6 月 3 日在海上发生火灾,22名船员成功获救。沉没船只是总部位于英国伦敦的 Zodiac Maritime 公司运营的“Morning Midas号”(利比里亚船籍),这是一艘全长约 180 米的大中型船。该船 5 月从中国出发,原定于 6 月 15 日抵达墨西哥的拉萨罗·卡德纳斯港。该船共装载了 3048 辆汽车,其中 70 辆为纯电动汽车,681 辆为混合动力车。该船在航行至阿拉斯加州阿达克岛以南约 480 公里的海域时发生火灾,甲板冒出浓烟。全体船员乘坐救生艇逃生,并被航行至附近的商船救起。目前尚不清楚起火点是否来自电动汽车。
Citrix Releases Emergency Patches for Actively Exploited CVE-2025-6543 in NetScaler ADC
2 months 2 weeks ago
Citrix has released security updates to address a critical flaw affecting NetScaler ADC that it said has been exploited in the wild.
The vulnerability, tracked as CVE-2025-6543, carries a CVSS score of 9.2 out of a maximum of 10.0.
It has been described as a case of memory overflow that could result in unintended control flow and denial-of-service. However, successful exploitation requires the
The Hacker News
Submit #602340: code-projects Inventory Management System V1.0 SQL injection [Accepted]
2 months 2 weeks ago
Submit #602340 / VDB-313881
a9133065377
CVE-2025-6665 | code-projects Inventory Management System 1.0 editBrand.php editBrandStatus sql injection (EUVD-2025-19138)
2 months 2 weeks ago
A vulnerability has been found in code-projects Inventory Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /php_action/editBrand.php. The manipulation of the argument editBrandStatus leads to sql injection.
This vulnerability is known as CVE-2025-6665. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6664 | CodeAstro Patient Record Management System 1.0 cross-site request forgery (EUVD-2025-19139)
2 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in CodeAstro Patient Record Management System 1.0. Affected is an unknown function. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2025-6664. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #602325: code-projects Car Rental System V1.0 Unrestricted Upload [Accepted]
2 months 2 weeks ago
Submit #602325 / VDB-313880
zzb1
微软发布编辑器 MS-DOS Editor 的 Rust 版本
2 months 2 weeks ago
微软开源了其经典编辑器 MS-DOS Editor 的 Rust 语言版本,源代码托管在 GitHub,支持 Windows、macOS 和 Linux。MS-DOS Editor 或简称为 Editor,最初是随 MS-DOS 5.0 发布的,至今有逾三十年历史。微软再次复活 MS-DOS Editor 是为了解决 64 位 Windows 操作系统缺乏默认的命令行界面文本编辑器问题,32 位 Windows 内置了 MS-DOS editor,但 64 位系统没有。新版本仅为 250KB,引入了现代特性如 Unicode 支持,正则表达式以及处理 GB 大小文件的能力。旧版本受限于内存只能处理小于 300KB 的文件。
CVE-2025-5275 | Charitable Plugin up to 1.8.6.1/1.8.6.2 on WordPress Privacy Setting cross site scripting
2 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Charitable Plugin up to 1.8.6.1/1.8.6.2 on WordPress. This issue affects some unknown processing of the component Privacy Setting Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-5275. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-5559 | TimeZoneCalculator Plugin up to 3.37 on WordPress Shortcode timezonecalculator_output cross site scripting
2 months 2 weeks ago
A vulnerability classified as problematic has been found in TimeZoneCalculator Plugin up to 3.37 on WordPress. This affects the function timezonecalculator_output of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-5559. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-6546 | Drive Folder Embedder Plugin up to 1.1.0 on WordPress tablecssclass cross site scripting
2 months 2 weeks ago
A vulnerability classified as problematic was found in Drive Folder Embedder Plugin up to 1.1.0 on WordPress. This vulnerability affects unknown code. The manipulation of the argument tablecssclass leads to cross site scripting.
This vulnerability was named CVE-2025-6546. The attack can be initiated remotely. There is no exploit available.
vuldb.com