Aggregator
CVE-2025-5726 | SourceCodester Student Result Management System 1.0 Division System Page division-system cross site scripting
CVE-2025-5725 | SourceCodester Student Result Management System 1.0 Grading System Page grading-system Remark cross site scripting
CVE-2025-5724 | SourceCodester Student Result Management System 1.0 Subjects Page subjects Subject cross site scripting
CVE-2025-5723 | SourceCodester Student Result Management System 1.0 Classes Page /script/academic/classes Class Name cross site scripting
CVE-2025-5722 | SourceCodester Student Result Management System 1.0 Add Academic Term /script/academic/terms cross site scripting
CVE-2025-5721 | SourceCodester Student Result Management System 1.0 Profile Setting Page update_profile cross site scripting
Submit #590578: Sourcecodester Open Source Clinic Management System 1.0 File Upload vulnerability [Accepted]
Submit #590569: SourceCodester Student Result Management System 1.0 Cross Site Scripting [Accepted]
CVE-2024-30087 | Microsoft Windows up to Server 2022 23H2 Win32k input validation (EUVD-2024-28024)
CVE-2025-5648 | Radare2 5.9.9 radiff2 /libr/cons/pal.c r_cons_pal_init -T memory corruption (EUVD-2025-16977)
CVE-2025-4568 | Trol InterMedia 2ClickPortal up to 7.14.2 changes__reference_id sql injection (EUVD-2025-16979)
CVE-2025-5701 | HyperComments Plugin up to 1.2.2 on WordPress hc_request_handler improper authorization (EUVD-2025-16984)
CVE-2025-5341 | Forminator Plugin up to 1.44.1 on WordPress id/data-size cross site scripting (EUVD-2025-16983)
ClickFix Email Scam Alert: Fake Booking.com Emails Deliver Malware
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2025-5419 Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
#Infosec2025: Seven Steps to Building a Mature Vulnerability Management Program
CISA Releases Seven Industrial Control Systems Advisories
CISA released seven Industrial Control Systems (ICS) advisories on June 5, 2025. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.
- ICSA-25-155-01 CyberData 011209 SIP Emergency Intercom
- ICSA-25-155-02 Hitachi Energy Relion 670, 650 series and SAM600-IO Product
- ICSA-21-049-02 Mitsubishi Electric FA Engineering Software Products (Update H)
- ICSA-25-133-02 Hitachi Energy Relion 670/650/SAM600-IO Series (Update A)
- ICSA-23-068-05 Hitachi Energy Relion 670, 650 and SAM600-IO Series (Update A)
- ICSA-21-336-05 Hitachi Energy Relion 670/650/SAM600-IO (Update A)
- ICSA-23-089-01 Hitachi Energy IEC 61850 MMS-Server (Update A)
CISA encourages users and administrators to review newly released ICS advisories for technical details and mitigations.
VMware NSX XSS Vulnerability Exposes Systems to Malicious Code Injection
Broadcom has issued a high-severity security advisory (VMSA-2025-0012) for VMware NSX, addressing three newly discovered stored Cross-Site Scripting (XSS) vulnerabilities: CVE-2025-22243, CVE-2025-22244, and CVE-2025-22245. These vulnerabilities impact the NSX Manager UI, gateway firewall, and router port components, exposing organizations to potential code injection attacks if left unpatched. The vulnerabilities, all stemming from improper input validation, […]
The post VMware NSX XSS Vulnerability Exposes Systems to Malicious Code Injection appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.