Aggregator
告别终端安全盲区!MVS终端漏洞检测系统安卓版正式开放试用
3 months 2 weeks ago
安卓系统漏洞检测已正式上线试用!
巡星漏洞扫描平台
3 months 2 weeks ago
红队快速漏洞扫描平台
巡星漏洞扫描平台
3 months 2 weeks ago
当前环境出现异常,需完成验证后才能继续访问,并有“去验证”的操作选项。
CVE-2025-11989 | GitLab Enterprise Edition up to 18.3.4/18.4.2/18.5.0 Description authorization (Patch 1426)
3 months 2 weeks ago
A vulnerability classified as problematic has been found in GitLab Enterprise Edition up to 18.3.4/18.4.2/18.5.0. This issue affects some unknown processing of the component Description Handler. The manipulation leads to missing authorization.
This vulnerability is listed as CVE-2025-11989. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-6601 | GitLab Enterprise Edition up to 18.4.2/18.5.0 logic error (Patch 551267)
3 months 2 weeks ago
A vulnerability described as problematic has been identified in GitLab Enterprise Edition up to 18.4.2/18.5.0. This vulnerability affects unknown code. Executing manipulation can lead to business logic errors.
This vulnerability is tracked as CVE-2025-6601. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-11974 | GitLab Community Edition/Enterprise Edition up to 18.3.4/18.4.2/18.5.0 API Endpoint allocation of resources (Patch 571761)
3 months 2 weeks ago
A vulnerability marked as problematic has been reported in GitLab Community Edition and Enterprise Edition up to 18.3.4/18.4.2/18.5.0. This affects an unknown part of the component API Endpoint. Performing manipulation results in allocation of resources.
This vulnerability is identified as CVE-2025-11974. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-10497 | GitLab Community Edition/Enterprise Edition up to 18.3.4/18.4.2/18.5.0 allocation of resources (Patch 570336)
3 months 2 weeks ago
A vulnerability labeled as problematic has been found in GitLab Community Edition and Enterprise Edition up to 18.3.4/18.4.2/18.5.0. Affected by this issue is some unknown functionality. Such manipulation leads to allocation of resources.
This vulnerability is referenced as CVE-2025-10497. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2025-11447 | GitLab Community Edition/Enterprise Edition up to 18.3.4/18.4.2/18.5.0 JSON allocation of resources (Patch 574858)
3 months 2 weeks ago
A vulnerability identified as problematic has been detected in GitLab Community Edition and Enterprise Edition up to 18.3.4/18.4.2/18.5.0. Affected by this vulnerability is an unknown functionality of the component JSON Handler. This manipulation causes allocation of resources.
The identification of this vulnerability is CVE-2025-11447. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2025-11971 | GitLab Enterprise Edition up to 18.3.4/18.4.2/18.5.0 Pipeline Execution authorization (Patch 566587)
3 months 2 weeks ago
A vulnerability categorized as problematic has been discovered in GitLab Enterprise Edition up to 18.3.4/18.4.2/18.5.0. Affected is an unknown function of the component Pipeline Execution Handler. The manipulation results in incorrect authorization.
This vulnerability was named CVE-2025-11971. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-12287 | Bdtask Wholesale Inventory Control and Inventory Management System edit_profile sql injection
3 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Bdtask Wholesale Inventory Control and Inventory Management System up to 20251013. This impacts an unknown function of the file /Admin_dashboard/edit_profile. Such manipulation of the argument first_name/last_name leads to sql injection.
This vulnerability is traded as CVE-2025-12287. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-12288 | Bdtask Pharmacy Management System up to 9.4 User Profile /user/edit_user/ authorization
3 months 2 weeks ago
A vulnerability has been found in Bdtask Pharmacy Management System up to 9.4 and classified as problematic. Affected is an unknown function of the file /user/edit_user/ of the component User Profile Handler. Performing manipulation results in authorization bypass.
This vulnerability is known as CVE-2025-12288. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
派早报:苹果调查橙色 iPhone 17 Pro 变色问题
3 months 2 weeks ago
苹果调查橙色 iPhone 17 Pro 变色问题;互联网平台签署自律公约推动互联互通;微软将《光环》登陆 PlayStation 平台;外卖平台被市场监管总局调查;OpenAI 收购「快捷指令」前开发团队新公司;日本教师使用恐怖游戏 P.T. 教英语;苹果计划调整 iPhone 发布策略等。
CVE-2010-2256 | Payperviewvideosoftware Pay Per Minute Video Chat Script 2.0 memberviewdetails.php model cross site scripting (EDB-10983 / SA38086)
3 months 2 weeks ago
A vulnerability labeled as problematic has been found in Payperviewvideosoftware Pay Per Minute Video Chat Script 2.0. This vulnerability affects unknown code of the file admin/memberviewdetails.php. Executing manipulation of the argument model can lead to cross site scripting.
This vulnerability appears as CVE-2010-2256. The attack may be performed from remote. In addition, an exploit is available.
vuldb.com
CVE-2010-2257 | Payperviewvideosoftware Pay Per Minute Video Chat Script 2.0 index_ie.php page sql injection (EDB-10983 / OSVDB-61469)
3 months 2 weeks ago
A vulnerability marked as critical has been reported in Payperviewvideosoftware Pay Per Minute Video Chat Script 2.0. This issue affects some unknown processing of the file index_ie.php. The manipulation of the argument page leads to sql injection.
This vulnerability is traded as CVE-2010-2257. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2010-1855 | Phpscripte24 Pay Per Watch / Bid Auktions System auktion.php id_auk sql injection (EDB-11816 / XFDB-57055)
3 months 2 weeks ago
A vulnerability was found in Phpscripte24 Pay Per Watch and Bid Auktions System and classified as critical. This impacts an unknown function of the file auktion.php. The manipulation of the argument id_auk results in sql injection.
This vulnerability is identified as CVE-2010-1855. The attack can be executed remotely. Additionally, an exploit exists.
vuldb.com
CVE-2010-4278 | Artica Pandora FMS up to 2.1.0 networkmap.php layout os command injection (EDB-15640 / SBV-28859)
3 months 2 weeks ago
A vulnerability marked as critical has been reported in Artica Pandora FMS up to 2.1.0. Affected by this vulnerability is an unknown functionality of the file operation/agentes/networkmap.php. Performing manipulation of the argument layout results in os command injection.
This vulnerability is known as CVE-2010-4278. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2010-4846 | Mhproducts Pay Pal Shop Digital view_item.php ItemID sql injection (EDB-15772 / XFDB-64204)
3 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Mhproducts Pay Pal Shop Digital. This vulnerability affects unknown code of the file view_item.php. Executing manipulation of the argument ItemID can lead to sql injection.
This vulnerability is tracked as CVE-2010-4846. The attack can be launched remotely. Moreover, an exploit is present.
vuldb.com
CVE-2010-4281 | Artica Pandora FMS up to 2.1.0 JAXP ajax.php safe_url_extraclean page code injection (EDB-15643 / XFDB-63599)
3 months 2 weeks ago
A vulnerability classified as critical was found in Artica Pandora FMS up to 2.1.0. This vulnerability affects the function safe_url_extraclean of the file ajax.php of the component JAXP. The manipulation of the argument page results in code injection.
This vulnerability was named CVE-2010-4281. The attack may be performed from remote. In addition, an exploit is available.
Upgrading the affected component is advised.
vuldb.com
马斯克 xAI 上新款「虚拟女友」;传小米 17 Air 明年上;996 成美国创业者美德 | 极客早知道
3 months 2 weeks ago
Intel 积极瘦身:融资 200 亿美元还债 43 亿美元 优化 4 万员工;Windows 10 停止支持:反带动苹果 Mac 销量大增;苹果悄然在 iOS 26.1 中引入新功能:第三方 App 可以后台备份照片了!