Aggregator
CVE-2025-1797 | Hunan Zhonghe Baiyi Information Technology Baiyiyun Asset Management and Operations System up to 20250217 anyUserBoundHouse.php huid sql injection
1 year 3 months ago
A vulnerability, which was classified as critical, has been found in Hunan Zhonghe Baiyi Information Technology Baiyiyun Asset Management and Operations System up to 20250217. Affected by this issue is some unknown functionality of the file /wuser/anyUserBoundHouse.php. The manipulation of the argument huid leads to sql injection.
This vulnerability is handled as CVE-2025-1797. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-1817 | Mini-Tmall up to 20250211 Admin Name /admin cross site scripting
1 year 3 months ago
A vulnerability classified as problematic was found in Mini-Tmall up to 20250211. This vulnerability affects unknown code of the file /admin of the component Admin Name Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-1817. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-1815 | pbrong hrms up to 1.0.1 \resource\resource.go HrmsDB user_cookie improper authorization
1 year 3 months ago
A vulnerability, which was classified as critical, was found in pbrong hrms up to 1.0.1. This affects the function HrmsDB of the file \resource\resource.go. The manipulation of the argument user_cookie leads to improper authorization.
This vulnerability is uniquely identified as CVE-2025-1815. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-1810 | Pixsoft Vivaz 6.0.11 Login Endpoint sistema cross site scripting
1 year 3 months ago
A vulnerability was found in Pixsoft Vivaz 6.0.11. It has been classified as problematic. Affected is an unknown function of the file /servlet?act=login&submit=1&evento=0&pixrnd=0125021817031859360231 of the component Login Endpoint. The manipulation of the argument sistema leads to cross site scripting.
This vulnerability is traded as CVE-2025-1810. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-1811 | AT Software Solutions ATSVD up to 3.4.1 Login Endpoint /login.aspx txtUsuario sql injection
1 year 3 months ago
A vulnerability was found in AT Software Solutions ATSVD up to 3.4.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /login.aspx of the component Login Endpoint. The manipulation of the argument txtUsuario leads to sql injection.
This vulnerability is known as CVE-2025-1811. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-1813 | zj1983 zz up to 2024-08 cross-site request forgery
1 year 3 months ago
A vulnerability classified as problematic was found in zj1983 zz up to 2024-08. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2025-1813. The attack can be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-1806 | Eastnets PaymentSafe 2.5.26.0 URL /Default.aspx improper authorization
1 year 3 months ago
A vulnerability, which was classified as problematic, has been found in Eastnets PaymentSafe 2.5.26.0. Affected by this issue is some unknown functionality of the file /Default.aspx of the component URL Handler. The manipulation leads to improper authorization.
This vulnerability is handled as CVE-2025-1806. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-1808 | Pixsoft E-Saphira 1.7.24 Login Endpoint servlet?act=login&tipo=1 txtUsuario sql injection
1 year 3 months ago
A vulnerability has been found in Pixsoft E-Saphira 1.7.24 and classified as critical. This vulnerability affects unknown code of the file /servlet?act=login&tipo=1 of the component Login Endpoint. The manipulation of the argument txtUsuario leads to sql injection.
This vulnerability was named CVE-2025-1808. The attack can be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-1809 | Pixsoft Sol up to 7.6.6c Login Endpoint txtUsuario sql injection
1 year 3 months ago
A vulnerability was found in Pixsoft Sol up to 7.6.6c and classified as critical. This issue affects some unknown processing of the file /pix_projetos/servlet?act=login&submit=1&evento=0&pixrnd=0125021816444195731041 of the component Login Endpoint. The manipulation of the argument txtUsuario leads to sql injection.
The identification of this vulnerability is CVE-2025-1809. The attack may be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-1799 | Zorlan SkyCaiji 2.9 Tool.php previewAction data server-side request forgery
1 year 3 months ago
A vulnerability, which was classified as critical, was found in Zorlan SkyCaiji 2.9. This affects the function previewAction of the file vendor/skycaiji/app/admin/controller/Tool.php. The manipulation of the argument data leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2025-1799. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-1800 | D-Link DAR-7000 3.2 HTTP POST Request sxh_vpnlic.php get_ip_addr_details ethname command injection
1 year 3 months ago
A vulnerability has been found in D-Link DAR-7000 3.2 and classified as critical. This vulnerability affects the function get_ip_addr_details of the file /view/vpn/sxh_vpn/sxh_vpnlic.php of the component HTTP POST Request Handler. The manipulation of the argument ethname leads to command injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability was named CVE-2025-1800. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Over 4,000 ISP IPs Targeted in Brute-Force Attacks to Deploy Info Stealers and Cryptominers
1 year 3 months ago
Internet service providers (ISPs) in China and the West Coast of the United States have become the target of a mass exploitation campaign that deploys information stealers and cryptocurrency miners on compromised hosts.
The findings come from the Splunk Threat Research Team, which said the activity also led to the delivery of various binaries that facilitate data exfiltration as well as offer
The Hacker News
DPRK IT Fraud Network Uses GitHub to Target Global Companies
1 year 3 months ago
Nisos
DPRK IT Fraud Network Uses GitHub to Target Global Companies
Nisos is tracking a network of likely North Korean (DPRK)-affiliated IT workers posing as Vietnamese, Japanese, and Singaporean nationals with the goal of obtaining employment in remote engineering...
The post DPRK IT Fraud Network Uses GitHub to Target Global Companies appeared first on Nisos by Nisos
The post DPRK IT Fraud Network Uses GitHub to Target Global Companies appeared first on Security Boulevard.
Nisos
CVE-2025-1925 | Open5GS up to 2.7.2 AMF src/amf/nsmf-handler.c amf_nsmf_pdusession_handle_update_sm_context denial of service
1 year 3 months ago
A vulnerability classified as problematic was found in Open5GS up to 2.7.2. Affected by this vulnerability is the function amf_nsmf_pdusession_handle_update_sm_context of the file src/amf/nsmf-handler.c of the component AMF. The manipulation leads to denial of service.
This vulnerability is known as CVE-2025-1925. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
云原生攻防靶场Metarget 重磅升级:全新功能与深度优化!
1 year 3 months ago
云原生攻防靶场Metarget 重磅升级:全新功能与深度优化!
1 year 3 months ago
云原生攻防靶场Metarget 重磅升级:全新功能与深度优化!
1 year 3 months ago
云原生攻防靶场Metarget 重磅升级:全新功能与深度优化!
1 year 3 months ago
FreeBuf早报 | 美国停止针对俄罗斯的网络进攻;严重的Android漏洞正被利用
1 year 3 months ago
据知情人士透露,美国国防部长皮特·赫格塞思已下令要求美国网络司令部停止针对俄罗斯的进攻行动。