Aggregator
CVE-2025-4899 | Campcodes Sales and Inventory System 1.0 transaction_update.php ID sql injection (EUVD-2025-15646)
CVE-2025-4898 | SourceCodester Student Result Management System 1.0 Logo File update_system.php unlink old_logo path traversal (EUVD-2025-15643)
CVE-2025-4897 | Tenda A15 15.13.07.09/15.13.07.13 HTTP POST Request /goform/multimodalAdd buffer overflow (EUVD-2025-15644)
CVE-2025-4896 | Tenda AC10 16.03.10.13 UserCongratulationsExec getuid buffer overflow
Submit #578041: campcodes Sales and Inventory System V1.0 SQL Injection [Accepted]
Submit #578040: Campcodes Sales and Inventory 1.0 SQL Injection [Accepted]
CVE-2025-30072 | Tiiwee X1 Alarm System TWX1HAKV2 authentication replay
Submit #578036: SRMS Student Result Management System 1.0 Path Traversal [Accepted]
CVE-2025-26086 | RSI Queue Management System 3.0 TaskID sql injection
Submit #578035: Tenda A15 V15.13.07.13 Buffer Overflow [Accepted]
Submit #578034: Tenda AC10V4.0 V16.03.10.13 Buffer Overflow [Accepted]
Critical WordPress Plugin Vulnerability Exposes 10K+ Sites to Cyber Attack
A severe privilege escalation vulnerability has been discovered in the popular WordPress plugin Eventin, putting more than 10,000 websites at risk of complete compromise. The vulnerability, now tracked as CVE-2025-47539, allows unauthenticated attackers to create administrator accounts without any user interaction, giving them full control over affected websites. Security researchers are urging site owners to […]
The post Critical WordPress Plugin Vulnerability Exposes 10K+ Sites to Cyber Attack appeared first on Cyber Security News.
CVE-2024-23922 | Sony XAV-AX5500 data authenticity (EDB-52143)
G.O.S.S.I.P 阅读推荐 2025-05-17 本地网络立入禁止
Sophisticated NPM Attack Exploits Google Calendar C2 For Sophisticated Communication
A new advanced supply chain attack targeting the Node Package Manager (NPM) ecosystem has emerged, leveraging Google Calendar as a covert command and control (C2) channel. Cybersecurity experts discovered the malware embedded in seemingly legitimate JavaScript libraries that, once installed, establish a stealthy communication pathway with attackers through common Google services. The malware has potentially […]
The post Sophisticated NPM Attack Exploits Google Calendar C2 For Sophisticated Communication appeared first on Cyber Security News.