Aggregator
英特尔Arc显卡暂获安全,但前路迷雾重重
4 months 3 weeks ago
安全客
目标密集环境:为何微软365已成最大风险隐患
4 months 3 weeks ago
安全客
ShinyHunters 声称通过 Drift 攻击窃取 15 亿条 Salesforce 记录
4 months 3 weeks ago
安全客
30 万节点 AISURU 僵尸网络发动创纪录的 11.5 Tbps DDoS 攻击
4 months 3 weeks ago
安全客
CISA 警告两种恶意软件正利用 Ivanti EPMM CVE-2025-4427 和 CVE-2025-4428
4 months 3 weeks ago
安全客
AI驱动防御升级,360终端安全智能体亮相国家网络安全宣传周
4 months 3 weeks ago
安全客
CVE-2025-10741 | Selleo Mentingo up to 2025.08.27 Profile Picture userAvatar unrestricted upload (EUVD-2025-30365)
4 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Selleo Mentingo up to 2025.08.27. The affected element is an unknown function of the component Profile Picture Handler. The manipulation of the argument userAvatar leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2025-10741. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
Submit #645385: Selleo Labs Sp. z o.o. Mentingo learn-v2025.08.27 Unrestricted Upload [Accepted]
4 months 3 weeks ago
Submit #645385 / VDB-325068
KhanMarshal
CVE-2025-48703 | centos-webpanel CentOS Web Panel up to 0.9.8.864 t_total os command injection
4 months 3 weeks ago
A vulnerability classified as critical was found in centos-webpanel CentOS Web Panel up to 0.9.8.864. Impacted is an unknown function. Executing manipulation of the argument t_total can lead to os command injection.
This vulnerability is handled as CVE-2025-48703. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-9949 | Internal Links Manager Plugin up to 3.0.1 on WordPress process_bulk_action cross-site request forgery (EUVD-2025-30309)
4 months 3 weeks ago
A vulnerability classified as problematic has been found in Internal Links Manager Plugin up to 3.0.1 on WordPress. This issue affects the function process_bulk_action. Performing manipulation results in cross-site request forgery.
This vulnerability is known as CVE-2025-9949. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2025-10181 | Draft List Plugin up to 2.6 on WordPress Shortcode drafts cross site scripting (EUVD-2025-30313)
4 months 3 weeks ago
A vulnerability described as problematic has been identified in Draft List Plugin up to 2.6 on WordPress. This vulnerability affects the function drafts of the component Shortcode Handler. Such manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-10181. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-10305 | Secure Passkeys Plugin up to 1.2.1 on WordPress delete_passkey authorization (EUVD-2025-30311)
4 months 3 weeks ago
A vulnerability marked as critical has been reported in Secure Passkeys Plugin up to 1.2.1 on WordPress. This affects the function delete_passkey. This manipulation causes missing authorization.
This vulnerability appears as CVE-2025-10305. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2025-10489 | SureForms Plugin up to 1.12.0 on WordPress register_post_types authorization (EUVD-2025-30312)
4 months 3 weeks ago
A vulnerability labeled as critical has been found in SureForms Plugin up to 1.12.0 on WordPress. Affected by this issue is the function register_post_types. The manipulation results in missing authorization.
This vulnerability is reported as CVE-2025-10489. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2025-10002 | flowdee ClickWhale Plugin up to 2.5.0 on WordPress export_csv sql injection (EUVD-2025-30310)
4 months 3 weeks ago
A vulnerability identified as critical has been detected in flowdee ClickWhale Plugin up to 2.5.0 on WordPress. Affected by this vulnerability is the function export_csv. The manipulation leads to sql injection.
This vulnerability is documented as CVE-2025-10002. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2025-10652 | Robcore Netatmo Plugin up to 1.7 on WordPress Shortcode robcore-netatmo sql injection (EUVD-2025-30322)
4 months 3 weeks ago
A vulnerability categorized as critical has been discovered in Robcore Netatmo Plugin up to 1.7 on WordPress. Affected is the function robcore-netatmo of the component Shortcode Handler. Executing manipulation can lead to sql injection.
This vulnerability is registered as CVE-2025-10652. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2025-36248 | IBM Copy Services Manager 6.3.13 Web UI cross site scripting
4 months 3 weeks ago
A vulnerability was found in IBM Copy Services Manager 6.3.13. It has been rated as problematic. This impacts an unknown function of the component Web UI. Performing manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2025-36248. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
Submit #645195: LafeLabs trashmagicmedia main xss [Duplicate]
4 months 3 weeks ago
Submit #645195 / VDB-286034
dev03301
Венера осталась без «Акацуки»: легендарная японская миссия подошла к концу
4 months 3 weeks ago
Пустая орбита словно держит паузу перед новым ответом.
Тайвань планирует «зонтик ПВО» для блокировки китайских авиаударов
4 months 3 weeks ago
Десятки пусковых установок и радары объединят в единую сеть для перехватов за пределами видимости.