A Chinese national was arrested in Milan, Italy, last week for allegedly being linked to the state-sponsored Silk Typhoon hacking group, which responsible for cyberattacks against American organizations and government agencies. [...]
A vulnerability, which was classified as problematic, has been found in IBM Engineering Requirements Management DOORS 9.7.2.9. Affected by this issue is some unknown functionality. The manipulation leads to weak password recovery.
This vulnerability is handled as CVE-2024-43190. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in SourceCodester Best Salon Management System 1.0. Affected by this issue is some unknown functionality of the file /panel/search-appointment.php. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-7142. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability has been found in CodeAstro Patient Record Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument uname leads to sql injection.
This vulnerability is known as CVE-2025-7147. The attack can be launched remotely. Furthermore, there is an exploit available.
A vulnerability was found in CodeAstro Simple Hospital Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /patient.html of the component POST Parameter Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-7148. The attack may be launched remotely. Furthermore, there is an exploit available.
Multiple parameters might be affected.
A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/candidates_delete.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-7149. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.