A vulnerability classified as critical has been found in GreenCMS up to 2.3.0603. This affects an unknown part of the file /index.php?m=admin&c=media&a=fileconnect. The manipulation of the argument upload[] leads to unrestricted upload. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is uniquely identified as CVE-2025-9415. The attack is possible to be carried out remotely. Moreover, an exploit is present.
A vulnerability described as problematic has been identified in MINOVA TTA 11.17.0 on Windows. Affected by this issue is some unknown functionality of the component Debug Port 1604. Executing manipulation can lead to information disclosure.
This vulnerability is handled as CVE-2025-7426. The attack can be executed remotely. There is not any exploit available.
The application of restrictive firewalling is recommended.
A vulnerability marked as critical has been reported in kalcaddle kodbox 1.61. Affected by this vulnerability is an unknown functionality of the file /?explorer/upload/serverDownload of the component Download from Link Handler. Performing manipulation of the argument url results in server-side request forgery.
This vulnerability is known as CVE-2025-9414. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
作者:知道创宇404实验室
日期:2025年8月25日
最近在研究 AiPy 应用的过程中,注意到已有研究利用大型语言模型(LLM)结合 IDA Pro MCP 实现软件破解[1]。因此,本研究尝试探索将 AiPy 与 IDA Pro 相结合,以评估其在软件分析与破解任务中的可行性与效果。
AiPy 结合IDA Pro
首先,需要解决的问题是如何通过 AiPy 调用 IDA。第一种方法是...
Подробно объясняем, как функция Duress PIN в GrapheneOS стирает все данные при введении альтернативного кода, чем она полезна обычным пользователям, каким рискам помогает противостоять и почему стоковый Android пока далёк от подобных мер.
A vulnerability categorized as problematic has been discovered in MIT Kerberos. This affects an unknown part of the component Key Distribution Center. Executing manipulation can lead to heap-based buffer overflow.
This vulnerability appears as CVE-2003-0082. The attack may be performed from a remote location. There is no available exploit.
It is advisable to upgrade the affected component.
A vulnerability labeled as problematic has been found in Moxa Utility for DRP-A100 and Utility for DRP-C100 on Windows. Affected is an unknown function of the file SerialInterfaceService.exe of the component Serial Interface Service. Such manipulation leads to unquoted search path.
This vulnerability is traded as CVE-2025-5191. An attack has to be approached locally. There is no exploit available.
The affected component should be upgraded.
A vulnerability identified as critical has been detected in lostvip-com ruoyi-go up to 2.1. This impacts the function SelectListByPage of the file modules/system/system_router.go. This manipulation of the argument orderByColumn/isAsc causes sql injection.
This vulnerability appears as CVE-2025-9413. The attack may be initiated remotely. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability categorized as critical has been discovered in lostvip-com ruoyi-go up to 2.1. This affects the function SelectListByPage of the file modules/system/dao/DictDataDao.go. The manipulation of the argument orderByColumn/isAsc results in sql injection.
This vulnerability is reported as CVE-2025-9412. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in lostvip-com ruoyi-go up to 2.1. It has been rated as critical. The impacted element is the function SelectPageList of the file modules/system/service/LoginInforService.go. The manipulation of the argument isAsc leads to sql injection.
This vulnerability is documented as CVE-2025-9411. The attack can be initiated remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in lostvip-com ruoyi-go up to 2.1. It has been declared as critical. The affected element is the function SelectListByPage of the file modules/system/dao/GenTableDao.go. Executing manipulation of the argument isAsc/orderByColumn can lead to sql injection.
This vulnerability is registered as CVE-2025-9410. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.