Aggregator
CVE-2025-5729 | code-projects Health Center Patient Record Management System 1.0 /birthing_record.php itr_no sql injection
3 months ago
A vulnerability, which was classified as critical, was found in code-projects Health Center Patient Record Management System 1.0. Affected is an unknown function of the file /birthing_record.php. The manipulation of the argument itr_no leads to sql injection.
This vulnerability is traded as CVE-2025-5729. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #590590: code-projects Health Center Patient Record Management System 1.0 SQL Injection [Accepted]
3 months ago
Submit #590590 / VDB-311250
FierceCat
阿联酋中央银行要求金融机构放弃短信和 OTP 身份验证
3 months ago
安全客
CVE-2011-10007 | RCLAMP File::Find::Rule up to 0.34 on Perl grep os command injection (EUVD-2011-5236)
3 months ago
A vulnerability, which was classified as critical, has been found in RCLAMP File::Find::Rule up to 0.34 on Perl. This issue affects the function grep. The manipulation leads to os command injection.
The identification of this vulnerability is CVE-2011-10007. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
TA397 Hackers Exploits Scheduled Tasks to Deploy Malware on Targeted Systems
3 months ago
A recent in-depth analysis by Proofpoint Threat Research has shed light on the sophisticated operations of TA397, also known as Bitter, a suspected state-backed threat actor highly likely aligned with Indian intelligence interests. Identified as an espionage-focused group, TA397 has been actively targeting entities across Europe and Asia, particularly those with connections to China, Pakistan, […]
The post TA397 Hackers Exploits Scheduled Tasks to Deploy Malware on Targeted Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Aman Mishra
CVE-2025-5728 | SourceCodester Open Source Clinic Management System 1.0 /manage_website.php website_image unrestricted upload
3 months ago
A vulnerability classified as critical was found in SourceCodester Open Source Clinic Management System 1.0. This vulnerability affects unknown code of the file /manage_website.php. The manipulation of the argument website_image leads to unrestricted upload.
This vulnerability was named CVE-2025-5728. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
独家披露:起底台“资通电军”APT组织技术底牌及网络攻击阴谋
3 months ago
安全客
CVE-2025-5727 | SourceCodester Student Result Management System 1.0 Announcement Page announcement Title cross site scripting
3 months ago
A vulnerability classified as problematic has been found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file /script/academic/announcement of the component Announcement Page. The manipulation of the argument Title leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-5727. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-5726 | SourceCodester Student Result Management System 1.0 Division System Page division-system cross site scripting
3 months ago
A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /script/academic/division-system of the component Division System Page. The manipulation of the argument Division leads to cross site scripting.
This vulnerability is handled as CVE-2025-5726. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-5725 | SourceCodester Student Result Management System 1.0 Grading System Page grading-system Remark cross site scripting
3 months ago
A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /script/academic/grading-system of the component Grading System Page. The manipulation of the argument Remark leads to cross site scripting.
This vulnerability is known as CVE-2025-5725. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-5724 | SourceCodester Student Result Management System 1.0 Subjects Page subjects Subject cross site scripting
3 months ago
A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /script/academic/subjects of the component Subjects Page. The manipulation of the argument Subject leads to cross site scripting.
This vulnerability is traded as CVE-2025-5724. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-5723 | SourceCodester Student Result Management System 1.0 Classes Page /script/academic/classes Class Name cross site scripting
3 months ago
A vulnerability was found in SourceCodester Student Result Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /script/academic/classes of the component Classes Page. The manipulation of the argument Class Name leads to cross site scripting.
The identification of this vulnerability is CVE-2025-5723. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-5722 | SourceCodester Student Result Management System 1.0 Add Academic Term /script/academic/terms cross site scripting
3 months ago
A vulnerability has been found in SourceCodester Student Result Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /script/academic/terms of the component Add Academic Term. The manipulation of the argument Academic Term leads to cross site scripting.
This vulnerability was named CVE-2025-5722. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-5721 | SourceCodester Student Result Management System 1.0 Profile Setting Page update_profile cross site scripting
3 months ago
A vulnerability, which was classified as problematic, was found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file /script/academic/core/update_profile of the component Profile Setting Page. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-5721. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #590578: Sourcecodester Open Source Clinic Management System 1.0 File Upload vulnerability [Accepted]
3 months ago
Submit #590578 / VDB-311248
mysq
Submit #590569: SourceCodester Student Result Management System 1.0 Cross Site Scripting [Accepted]
3 months ago
Submit #590569 / VDB-311241
erictee2802
CVE-2024-30087 | Microsoft Windows up to Server 2022 23H2 Win32k input validation (EUVD-2024-28024)
3 months ago
A vulnerability, which was classified as critical, was found in Microsoft Windows. Affected is an unknown function of the component Win32k. The manipulation leads to improper input validation.
This vulnerability is traded as CVE-2024-30087. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-5648 | Radare2 5.9.9 radiff2 /libr/cons/pal.c r_cons_pal_init -T memory corruption (EUVD-2025-16977)
3 months ago
A vulnerability was found in Radare2 5.9.9. It has been classified as problematic. Affected is the function r_cons_pal_init in the library /libr/cons/pal.c of the component radiff2. The manipulation of the argument -T leads to memory corruption.
This vulnerability is traded as CVE-2025-5648. An attack has to be approached locally. Furthermore, there is an exploit available.
The real existence of this vulnerability is still doubted at the moment.
It is recommended to apply a patch to fix this issue.
The documentation explains that the parameter -T is experimental and "crashy". Further analysis has shown "the race is not a real problem unless you use asan". A new warning has been added.
vuldb.com
CVE-2025-4568 | Trol InterMedia 2ClickPortal up to 7.14.2 changes__reference_id sql injection (EUVD-2025-16979)
3 months ago
A vulnerability, which was classified as critical, has been found in Trol InterMedia 2ClickPortal up to 7.14.2. Affected by this issue is some unknown functionality. The manipulation of the argument changes__reference_id leads to sql injection.
This vulnerability is handled as CVE-2025-4568. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com