Aggregator
CVE-2025-2034 | PHPGurukul Pre-School Enrollment System 1.0 edit-class.php?cid=1 classname/capacity/classtiming sql injection
4 months ago
A vulnerability has been found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit-class.php?cid=1. The manipulation of the argument classname/capacity/classtiming leads to sql injection.
This vulnerability is known as CVE-2025-2034. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-2616 | yangyouwang 杨有旺 crud 简约后台管理系统 1.0.0 Role Management Page cross site scripting (IBSPOX)
4 months ago
A vulnerability classified as problematic has been found in yangyouwang 杨有旺 crud 简约后台管理系统 1.0.0. Affected is an unknown function of the component Role Management Page. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-2616. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
雅虎将 TechCrunch 出售给 Regent
4 months ago
雅虎周五宣布将旗下的科技新闻网站 TechCrunch 出售给媒体投资公司 Regent。雅虎的业务重心是聚合新闻,不再是自己生产新闻。相比下 Regent 正转向投资新闻制作,本周早些时候收购了旗下包括 PCWorld、Macworld 和 TechAdvisor 等科技新闻网站的 Foundry。最新交易的收购金额没有披露,也不需要监管部门审查,意味着价格可能在 1 亿美元以内,超过 1 亿美元的交易才需要审查。TechCrunch 是硅谷最具影响力的科技新闻网站之一,成立于 2005 年,它在 2010 年被 AOL 收购,Verizon 在 2015 年收购 AOL 后拥有了 TechCrunch,2021 年 Verizon 以 50 亿美元将雅虎和 AOL 出售给私募股权公司 Apollo Global Management,新公司使用雅虎的名字。
反弹SHELL&不回显外带&正反向连接&防火墙出入站&文件下载
4 months ago
反弹shell,是渗透测试中拿权限的主要手段之一,本篇文章介绍了linux与windows的操作系统中基本的反弹shell场景。
不会有人2025了还不会反弹shell吧?让你的反弹shell从0到1!
4 months ago
本篇文章将从最简单的搭建开始讲起,直到你学会如何在一台无代码环境上的服务器执行反弹Shell命令,从而上线服务器。
CVE-2025-2577 | Bitspecter Suite Plugin up to 1.0.0 on WordPress SVG File Upload cross site scripting
4 months ago
A vulnerability, which was classified as problematic, was found in Bitspecter Suite Plugin up to 1.0.0 on WordPress. Affected is an unknown function of the component SVG File Upload Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-2577. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-1970 | webtoffee Export and Import Users and Customers Plugin up to 2.6.2 on WordPress validate_file server-side request forgery
4 months ago
A vulnerability, which was classified as critical, has been found in webtoffee Export and Import Users and Customers Plugin up to 2.6.2 on WordPress. This issue affects the function validate_file. The manipulation leads to server-side request forgery.
The identification of this vulnerability is CVE-2025-1970. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-1973 | webtoffee Export and Import Users and Customers Plugin up to 2.6.2 on WordPress download_file path traversal
4 months ago
A vulnerability classified as problematic was found in webtoffee Export and Import Users and Customers Plugin up to 2.6.2 on WordPress. This vulnerability affects the function download_file. The manipulation leads to path traversal.
This vulnerability was named CVE-2025-1973. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-1972 | webtoffee Export and Import Users and Customers Plugin up to 2.6.2 on WordPress admin_log_page file inclusion
4 months ago
A vulnerability classified as problematic has been found in webtoffee Export and Import Users and Customers Plugin up to 2.6.2 on WordPress. This affects the function admin_log_page. The manipulation leads to file inclusion.
This vulnerability is uniquely identified as CVE-2025-1972. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-2331 | GiveWP Plugin up to 3.22.1 on WordPress permissionsCheck information disclosure
4 months ago
A vulnerability was found in GiveWP Plugin up to 3.22.1 on WordPress. It has been rated as problematic. Affected by this issue is the function permissionsCheck. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2025-2331. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-1971 | webtoffee Export and Import Users and Customers Plugin up to 2.6.2 on WordPress form_data deserialization
4 months ago
A vulnerability was found in webtoffee Export and Import Users and Customers Plugin up to 2.6.2 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument form_data leads to deserialization.
This vulnerability is known as CVE-2025-1971. The attack can be launched remotely. There is no exploit available.
vuldb.com
成本不到五毛钱,这款 AI 设计工具想要「训服」家居电商审美
4 months ago
AI 正在改变家居电商行业的内容生产模式。
CVE-2021-45785 | TruDesk Help Desk Ticketing Solution 1.1.11 /api/v1/admin/restart cross-site request forgery
4 months ago
A vulnerability has been found in TruDesk Help Desk Ticketing Solution 1.1.11 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /api/v1/admin/restart. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2021-45785. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-37680 | Hangzhou Meisoft Information Technology FineSoft up to 8.0 controllable cross site scripting
4 months ago
A vulnerability was found in Hangzhou Meisoft Information Technology FineSoft up to 8.0 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument controllable leads to cross site scripting.
This vulnerability is handled as CVE-2024-37680. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-37732 | Anchor CMS 0.12.7 PDF File cross site scripting
4 months ago
A vulnerability was found in Anchor CMS 0.12.7. It has been declared as problematic. This vulnerability affects unknown code of the component PDF File Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-37732. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-6290 | Google Chrome up to 126.0.6478.114 Dawn use after free (ID 342428)
4 months ago
A vulnerability classified as critical has been found in Google Chrome. Affected is an unknown function of the component Dawn. The manipulation leads to use after free.
This vulnerability is traded as CVE-2024-6290. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6291 | Google Chrome up to 126.0.6478.114 Swiftshader use after free (ID 409429 / Nessus ID 231952)
4 months ago
A vulnerability classified as critical was found in Google Chrome. Affected by this vulnerability is an unknown functionality of the component Swiftshader. The manipulation leads to use after free.
This vulnerability is known as CVE-2024-6291. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6293 | Google Chrome up to 126.0.6478.114 Dawn use after free (ID 345993)
4 months ago
A vulnerability, which was classified as critical, was found in Google Chrome. This affects an unknown part of the component Dawn. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2024-6293. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6292 | Google Chrome up to 126.0.6478.114 Dawn use after free (ID 342545 / Nessus ID 231926)
4 months ago
A vulnerability, which was classified as critical, has been found in Google Chrome. Affected by this issue is some unknown functionality of the component Dawn. The manipulation leads to use after free.
This vulnerability is handled as CVE-2024-6292. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com