A vulnerability was found in yarnpkg Yarn up to 1.22.22. It has been classified as problematic. Affected is the function explodeHostedGitFragment of the file src/resolvers/exotics/hosted-git-resolver.js. The manipulation leads to inefficient regular expression complexity.
This vulnerability is traded as CVE-2025-8262. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in Vaelsys 4.1.0 and classified as critical. This issue affects some unknown processing of the file /grid/vgrid_server.php of the component User Creation Handler. The manipulation leads to improper authorization.
The identification of this vulnerability is CVE-2025-8261. The attack may be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability has been found in Vaelsys 4.1.0 and classified as problematic. This vulnerability affects unknown code of the file /grid/vgrid_server.php of the component MD4 Hash Handler. The manipulation of the argument xajaxargs leads to use of weak hash.
This vulnerability was named CVE-2025-8260. The attack can be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as critical, was found in Vaelsys 4.1.0. This affects the function execute_DataObjectProc of the file /grid/vgrid_server.php. The manipulation of the argument xajaxargs leads to os command injection.
This vulnerability is uniquely identified as CVE-2025-8259. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as problematic, has been found in Cool Mo Maigcal Number App up to 1.0.3 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.sdmagic.number. The manipulation leads to improper export of android application components.
This vulnerability is handled as CVE-2025-8258. An attack has to be approached locally. Furthermore, there is an exploit available.
《科学》期刊撤下了受争议的砷基生命论文。2010 年《科学》期刊发表了 F. Wolfe-Simon 等人的论文《A bacterium that can grow by using arsenic instead of phosphorus》,声称在加州湖泊中发现了一种砷基细菌 GFAJ-1,它利用砷而不是磷生长。论文发表之后引发了很多争议,2012 年《科学》发表了两篇未能复制这一发现的论文。《科学》期刊主编 Holden Thorp 在声明中称,他们没有在 2012 年撤回论文是因为当时的政策主要针对存在科学不端行为,而这篇论文的作者没有故意欺骗或犯有不端行为。《科学》后来扩大了撤稿的政策:如果一篇论文报告的实验结果不支持其核心结论,撤下是合适的。
A vulnerability classified as problematic was found in Lobby Universe Lobby App up to 2.8.0 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.maverick.lobby. The manipulation leads to improper export of android application components.
This vulnerability is known as CVE-2025-8257. The attack needs to be approached locally. Furthermore, there is an exploit available.
A vulnerability classified as critical has been found in code-projects Online Ordering System 1.0. Affected is an unknown function of the file /admin/product.php. The manipulation of the argument image leads to unrestricted upload.
This vulnerability is traded as CVE-2025-8256. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
A vulnerability was found in code-projects Exam Form Submission 1.0. It has been rated as critical. This issue affects some unknown processing of the file /register.php. The manipulation of the argument image leads to unrestricted upload.
The identification of this vulnerability is CVE-2025-8255. The attack may be initiated remotely. Furthermore, there is an exploit available.
A vulnerability was found in Campcodes Courier Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /view_parcel.php. The manipulation of the argument ID leads to sql injection.
This vulnerability was named CVE-2025-8254. The attack can be initiated remotely. Furthermore, there is an exploit available.