A vulnerability classified as problematic has been found in code-projects Online Bike Rental 1.0. Affected is an unknown function of the file /vehical-details.php of the component HTTP GET Request Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-0339. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
A vulnerability was found in Silabs Simplicity SDK. It has been rated as critical. This issue affects some unknown processing of the component 802.15.4 Packet Handler. The manipulation leads to buffer overflow.
The identification of this vulnerability is CVE-2024-6350. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Minidlna up to 1.3.3. It has been declared as critical. This vulnerability affects unknown code of the file minidlna.conf. The manipulation leads to os command injection.
This vulnerability was named CVE-2024-51442. The attack can only be initiated within the local network. There is no exploit available.
Over 4,000 abandoned but still active web backdoors were hijacked and their communication infrastructure sinkholed after researchers registered expired domains used for commanding them. [...]
Medusind, a leading billing provider for healthcare organizations, is notifying hundreds of thousands of individuals of a data breach that exposed their personal and health information more than a year ago, in December 2023. [...]
A vulnerability was found in Codezips Project Management System 1.0. It has been classified as critical. This affects an unknown part of the file /pages/forms/teacher.php. The manipulation of the argument name leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-0336. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability was found in code-projects Online Bike Rental System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the component Change Image Handler. The manipulation leads to unrestricted upload.
This vulnerability is handled as CVE-2025-0335. The attack may be launched remotely. Furthermore, there is an exploit available.
Other endpoints might be affected as well.
A vulnerability has been found in leiyuxi cy-fast 1.0 and classified as critical. Affected by this vulnerability is the function listData of the file /sys/user/listData. The manipulation of the argument order leads to sql injection.
This vulnerability is known as CVE-2025-0334. The attack can be launched remotely. Furthermore, there is an exploit available.