Aggregator
CVE-2025-3821 | SourceCodester Web-based Pharmacy Product Management System 1.0 add-admin.php txtpassword/txtfullname/txtemail cross site scripting
Submit #555918: Sourcecodester Web-based Pharmacy Product Management System v1.0 Cross Site Scripting [Accepted]
Submit #555906: sourcecodester Online Eyewear Shop Website v1.0 SQL Injection [Duplicate]
CVE-2025-3800 | WCMS 11 AnonymousController.php mobile_phone sql injection
Critical Erlang/OTP SSH RCE bug now has public exploits, patch now
CVE-2025-3557 | ScriptAndTools eCommerce-website-in-PHP 3.0 cross-site request forgery
CVE-2024-21896 | Node.js up to 20.11.0/21.6.1 Experimental Permission Model path traversal (Nessus ID 216256)
CVE-2024-25626 | Yocto Project poky up to 3.1.30/4.0.15/4.3.1 HTTP os command injection (GHSA-75xw-78mm-72r4)
CVE-2024-25982 | Moodle prior 4.3.3/4.1.9 Language Pack cross-site request forgery (FEDORA-2024-d2f180202f)
CVE-2024-21984 | NetApp StorageGRID up to 11.7 cross site scripting (ntap-20240216-0013)
CVE-2024-21496 | greenpau caddy-security javascript URL cross site scripting (Issue 267)
CVE-2023-5190 | Liferay Portal/DXP External URL redirect
CVE-2024-25640 | dfir-iris iris-web up to 2.3.x cross site scripting (GHSA-2xq6-qc74-w5vp)
Wordpress Newsletters 后台SQL注入漏洞(CVE-2025-30921)
New Limitations Placed on DOGE’s Access to Private Social Security Information
A federal judge has issued a preliminary injunction that significantly limits the Department of Government Efficiency’s (DOGE) access to sensitive Social Security Administration (SSA) data. The ruling, handed down yesterday, found that the government had provided DOGE with access to this private information without a sufficient legal basis. The court order requires DOGE to immediately […]
The post New Limitations Placed on DOGE’s Access to Private Social Security Information appeared first on Cyber Security News.
Chinese Hackers Exploit Ivanti Connect Secure Flaw to Gain Unauthorized Access
In a sophisticated cyber-espionage operation, a group known as UNC5221, suspected to have China-nexus, has exploited a critical vulnerability in Ivanti Connect Secure VPN appliances. The exploit, identified as CVE-2025-22457, represents a stack-based buffer overflow affecting multiple Ivanti products, including Policy Secure and Zero Trust Access gateways. A Critical Flaw Initially Underestimated CVE-2025-22457 was initially […]
The post Chinese Hackers Exploit Ivanti Connect Secure Flaw to Gain Unauthorized Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.