Aggregator
CVE-2025-3042 | Project Worlds Online Time Table Generator 1.0 updateprofile.php pic unrestricted upload
CVE-2025-3041 | Project Worlds Online Time Table Generator 1.0 /admin/updatestudent.php pic unrestricted upload
CVE-2025-3040 | Project Worlds Online Time Table Generator 1.0 /admin/add_student.php pic unrestricted upload
Submit #524982: SourceCodester The apartment visitor management system 1.0 SQL Injection [Duplicate]
Unsolved Challenge: Why API Access Control Vulnerabilities Remain a Major Security Risk
Despite advancements in API security, access control vulnerabilities, such as broken object-level authentication (BOLA) and broken function-level authentication (BFLA), remain almost impossible to detect. This blog will explore why these vulnerabilities are so difficult to detect, the limitations of current security tools, and the implications for businesses relying on API-driven applications. It will also discuss [...]
The post Unsolved Challenge: Why API Access Control Vulnerabilities Remain a Major Security Risk appeared first on Wallarm.
The post Unsolved Challenge: Why API Access Control Vulnerabilities Remain a Major Security Risk appeared first on Security Boulevard.
Submit #524949: GuoMinJim PersonManage v1.0 Improper Access Controls [Accepted]
CVE-2025-2586 | Red Hat OpenShift Lightspeed Service API resource consumption
Submit #524936: projectworlds Online Time Table Generator 1.0 Unrestricted Upload [Accepted]
Submit #524935: projectworlds Online Time Table Generator 1.0 Unrestricted Upload [Accepted]
Submit #524934: projectworlds Online Time Table Generator 1.0 Unrestricted Upload [Accepted]
CVE-2000-0737 | Microsoft Windows 2000 Service Control Manager privileges management (MS00-053 / EDB-20133)
CVE-2024-34341 | basecamp trix up to 2.1.0 cross site scripting (Duplicate CVE-2024-43368 / GHSA-qjqp-xr96-cj99)
CVE-2024-34342 | wojtekmaj react-pdf up to 7.7.2/8.0.1 PDF.js cross site scripting (GHSA-wgrm-67xf-hhpq)
CVE-2024-4600 | Socomec Net vision 7.20 set_param.cgi cross-site request forgery
CVE-2024-33859 | Logpoint up to 7.3.x Web UI Interesting Field cross site scripting
CVE-2024-33748 | MvnRepository MS Basic up to 2.1.18.3 Search cross site scripting
CVE-2024-4463 | Squelch Tabs and Accordions Shortcodes Plugin up to 0.4.7 on WordPress cross-site request forgery
ClickFake Interview – Lazarus Hackers Exploit Windows and macOS Users Fake Job Campaign
The Lazarus Group, a North Korean state-sponsored hacking collective, has launched a new campaign dubbed ClickFake Interview, targeting job seekers in the cryptocurrency industry. This malicious operation uses fake job interview websites to deploy a Go-based backdoor, known as GolangGhost, on both Windows and macOS systems. The campaign represents an evolution of the previously documented […]
The post ClickFake Interview – Lazarus Hackers Exploit Windows and macOS Users Fake Job Campaign appeared first on Cyber Security News.