Aggregator
麦当劳AI招聘助手暴露了约6400万条应聘者个人数据
2 months 1 week ago
AI放大数据泄露风险!
大疆无人机军用固件厂商被黑客攻击,俄军无人机集体瘫痪
2 months 1 week ago
当前环境出现异常,需完成验证后才能继续访问。
麦当劳AI招聘助手暴露了约6400万条应聘者个人数据
2 months 1 week ago
当前环境异常需完成验证后方可继续访问。
CISA Issues 13 New Advisories on Industrial Control System Vulnerabilities and Exploits
2 months 1 week ago
The Cybersecurity and Infrastructure Security Agency (CISA) released thirteen new Industrial Control Systems (ICS) advisories, spotlighting a range of security vulnerabilities and potential exploits affecting critical infrastructure components. These advisories are a vital resource for organizations relying on ICS technologies, offering detailed technical insights into current threats and actionable mitigations to safeguard operations. With industries […]
The post CISA Issues 13 New Advisories on Industrial Control System Vulnerabilities and Exploits appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Aman Mishra
Pre-Auth SQL Injection to RCE - Fortinet FortiWeb Fabric Connector (CVE-2025-25257) - watchTowr Labs
2 months 1 week ago
/r/netsec 是一个由社区管理的技术信息安全内容聚合平台,旨在为安全从业者、学生、研究人员和黑客提供有价值的信息资源。
Pre-Auth SQL Injection to RCE - Fortinet FortiWeb Fabric Connector (CVE-2025-25257)
2 months 1 week ago
Fortinet的FortiWeb Fabric Connector存在SQL注入漏洞(CVE-2025-25257),允许未经身份验证的攻击者通过构造HTTP请求执行任意SQL代码。该漏洞影响多个版本的FortiWeb,并可通过Authorization头中的Bearer令牌利用。攻击者可借此获取敏感数据或进一步控制服务器。修复建议包括升级到指定版本以防止 exploitation.
CVE-2025-7434 | Tenda FH451 up to 1.0.0.9 POST Request /goform/addressNat fromAddressNat page stack-based overflow (EUVD-2025-21101)
2 months 1 week ago
A vulnerability was found in Tenda FH451 up to 1.0.0.9 and classified as critical. Affected by this issue is the function fromAddressNat of the file /goform/addressNat of the component POST Request Handler. The manipulation of the argument page leads to stack-based buffer overflow.
This vulnerability is handled as CVE-2025-7434. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-7435 | LiveHelperChat lhc-php-resque Extension up to ee1270b35625f552425e32a6a3061cd54b5085c4 List list queue name cross site scripting (EUVD-2025-21100)
2 months 1 week ago
A vulnerability was found in LiveHelperChat lhc-php-resque Extension up to ee1270b35625f552425e32a6a3061cd54b5085c4. It has been classified as problematic. This affects an unknown part of the file /site_admin/lhcphpresque/list/ of the component List Handler. The manipulation of the argument queue name leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-7435. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-7436 | Campcodes Online Recruitment Management System 1.0 ajax.php?action=delete_vacancy ID sql injection (EUVD-2025-21102)
2 months 1 week ago
A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/ajax.php?action=delete_vacancy. The manipulation of the argument ID leads to sql injection.
This vulnerability was named CVE-2025-7436. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-7401 | Premium Age Verification Restriction Plugin up to 3.0.2 on WordPress remote_tunnel.php path traversal (EUVD-2025-21108)
2 months 1 week ago
A vulnerability was found in Premium Age Verification Restriction Plugin up to 3.0.2 on WordPress. It has been rated as critical. This issue affects some unknown processing of the file remote_tunnel.php. The manipulation leads to path traversal.
The identification of this vulnerability is CVE-2025-7401. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-5392 | GB Forms DB Plugin up to 1.0.2 on WordPress gbfdb_talk_to_front code injection
2 months 1 week ago
A vulnerability, which was classified as critical, was found in GB Forms DB Plugin up to 1.0.2 on WordPress. This affects the function gbfdb_talk_to_front. The manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2025-5392. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-6716 | Contest Gallery Plugin up to 26.0.8 on WordPress cross site scripting
2 months 1 week ago
A vulnerability has been found in Contest Gallery Plugin up to 26.0.8 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-6716. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-6068 | FooGallery Plugin up to 2.4.31 on WordPress HTML Attribute HTML injection
2 months 1 week ago
A vulnerability was found in FooGallery Plugin up to 2.4.31 on WordPress and classified as problematic. This issue affects some unknown processing of the component HTML Attribute Handler. The manipulation leads to HTML injection.
The identification of this vulnerability is CVE-2025-6068. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-7442 | WPGYM Plugin up to 67.7.x on WordPress sql injection
2 months 1 week ago
A vulnerability was found in WPGYM Plugin up to 67.7.x on WordPress. It has been rated as critical. This issue affects the function MJ_gmgt_delete_class_limit_for_member/MJ_gmgt_get_yearly_income_expense/MJ_gmgt_get_monthly_income_expense/MJ_gmgt_add_class_limit/MJ_gmgt_view_meeting_detail/MJ_gmgt_create_meeting. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2025-7442. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-6745 | WoodMart Plugin up to 8.2.5 on WordPress Password Protect woodmart_get_posts_by_query improper authentication
2 months 1 week ago
A vulnerability classified as critical has been found in WoodMart Plugin up to 8.2.5 on WordPress. Affected is the function woodmart_get_posts_by_query of the component Password Protect Handler. The manipulation leads to improper authentication.
This vulnerability is traded as CVE-2025-6745. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-5530 | WPC Smart Compare for WooCommerce Plugin up to 6.4.6 on WordPress Shortcode shortcode_btn cross site scripting
2 months 1 week ago
A vulnerability classified as problematic was found in WPC Smart Compare for WooCommerce Plugin up to 6.4.6 on WordPress. Affected by this vulnerability is the function shortcode_btn of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-5530. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-4593 | aviplugins WP Register Profile With Shortcode Plugin up to 3.6.2 on WordPress information disclosure
2 months 1 week ago
A vulnerability, which was classified as problematic, has been found in aviplugins WP Register Profile With Shortcode Plugin up to 3.6.2 on WordPress. Affected by this issue is some unknown functionality of the component Shortcode Handler. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2025-4593. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-6838 | Broken Link Notifier Plugin up to 1.3.0 on WordPress csv injection
2 months 1 week ago
A vulnerability, which was classified as critical, was found in Broken Link Notifier Plugin up to 1.3.0 on WordPress. This affects an unknown part. The manipulation leads to csv injection.
This vulnerability is uniquely identified as CVE-2025-6838. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-6851 | Broken Link Notifier Plugin up to 1.3.0 on WordPress ajax_blinks server-side request forgery
2 months 1 week ago
A vulnerability has been found in Broken Link Notifier Plugin up to 1.3.0 on WordPress and classified as critical. This vulnerability affects the function ajax_blinks. The manipulation leads to server-side request forgery.
This vulnerability was named CVE-2025-6851. The attack can be initiated remotely. There is no exploit available.
vuldb.com