Aggregator
COVID был только началом? Модель Гарварда уже знает, что дальше
7 months 1 week ago
Гарвард создал «предсказателя» пандемий.
Brother security advisory (AV25-392)
7 months 1 week ago
Canadian Centre for Cyber Security
China-linked group Houken hit French organizations using zero-days
7 months 1 week ago
China-linked group Houken hit French govt, telecom, media, finance and transport sectors using Ivanti CSA zero-days, says France’s ANSSI. France’s cyber agency ANSSI revealed that a Chinese hacking group used Ivanti CSA zero-days to target government, telecom, media, finance, and transport sectors. The campaign, active since September 2024, is linked to the Houken intrusion set, […]
Pierluigi Paganini
CVE-2013-2739 | minidlna memory corruption (EDB-38667 / OSVDB-95440)
7 months 1 week ago
A vulnerability has been found in minidlna and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2013-2739. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6920 | ai-inference-server API Inference Endpoint /invocations improper authentication
7 months 1 week ago
A vulnerability, which was classified as critical, was found in ai-inference-server. Affected is an unknown function of the file /invocations of the component API Inference Endpoint. The manipulation leads to improper authentication.
This vulnerability is traded as CVE-2025-6920. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2025-34056 | AVTECH IP Camera/DVR/NVR System Command PwdGrp.cgi pwd/grp os command injection (Exploit 40500 / EUVD-2025-19642)
7 months 1 week ago
A vulnerability classified as critical has been found in AVTECH IP Camera, DVR and NVR. This affects an unknown part of the file PwdGrp.cgi of the component System Command Handler. The manipulation of the argument pwd/grp leads to os command injection.
This vulnerability is uniquely identified as CVE-2025-34056. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-34050 | AVTECH IP Camera/DVR/NVR Web Interface cross-site request forgery (Exploit 40500 / EUVD-2025-19647)
7 months 1 week ago
A vulnerability, which was classified as problematic, was found in AVTECH IP Camera, DVR and NVR. This affects an unknown part of the component Web Interface. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2025-34050. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-34055 | AVTECH IP Camera/DVR/NVR up to T717-T717-T717-T717 adcommand.cgi strCmd os command injection (Exploit 40500 / EUVD-2025-19643)
7 months 1 week ago
A vulnerability was found in AVTECH IP Camera, DVR and NVR. It has been rated as critical. Affected by this issue is some unknown functionality of the file adcommand.cgi. The manipulation of the argument strCmd leads to os command injection.
This vulnerability is handled as CVE-2025-34055. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6956 | Campcodes Employee Management System 1.0 /changepassemp.php ID sql injection (EUVD-2025-19615)
7 months 1 week ago
A vulnerability was found in Campcodes Employee Management System 1.0. It has been classified as critical. This affects an unknown part of the file /changepassemp.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-6956. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6953 | TOTOLINK A3002RU 3.0.0-B20230809.1615 HTTP POST Request formParentControl submit-url buffer overflow (EUVD-2025-19619)
7 months 1 week ago
A vulnerability, which was classified as critical, was found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affected is an unknown function of the file /boafrm/formParentControl of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow.
This vulnerability is traded as CVE-2025-6953. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6954 | Campcodes Employee Management System 1.0 /applyleave.php ID sql injection (EUVD-2025-19620)
7 months 1 week ago
A vulnerability has been found in Campcodes Employee Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /applyleave.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is known as CVE-2025-6954. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-34058 | Hikvision Streaming Media Management Server 2.3.5 /systemLog/downFile.php fileName weak password (CNVD-2021-14544 / EUVD-2025-19639)
7 months 1 week ago
A vulnerability was found in Hikvision Streaming Media Management Server 2.3.5. It has been classified as critical. Affected is an unknown function of the file /systemLog/downFile.php. The manipulation of the argument fileName leads to weak password requirements.
This vulnerability is traded as CVE-2025-34058. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-34051 | AVTECH DVR up to V189-V189-V189-V189 Search.cgi?action=cgi_query queryb64str server-side request forgery (Exploit 40500 / EUVD-2025-19631)
7 months 1 week ago
A vulnerability classified as critical has been found in AVTECH DVR. Affected is an unknown function of the file /cgi-bin/nobody/Search.cgi?action=cgi_query. The manipulation of the argument queryb64str leads to server-side request forgery.
This vulnerability is traded as CVE-2025-34051. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-6955 | Campcodes Employee Management System 1.0 /process/aprocess.php mailuid sql injection (EUVD-2025-19616)
7 months 1 week ago
A vulnerability was found in Campcodes Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /process/aprocess.php. The manipulation of the argument mailuid leads to sql injection.
This vulnerability is handled as CVE-2025-6955. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-34053 | AVTECH IP Camera/DVR/NVR up to S984-S984-S984-S984 strstr authentication spoofing (Exploit 40500 / EUVD-2025-19645)
7 months 1 week ago
A vulnerability classified as critical was found in AVTECH IP Camera, DVR and NVR. Affected by this vulnerability is the function strstr. The manipulation leads to authentication bypass by spoofing.
This vulnerability is known as CVE-2025-34053. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-34054 | AVTECH DVR up to 1023-1014-1017-1002-FFFF Search.cgi?action=cgi_query queryb64str os command injection (Exploit 40500 / EUVD-2025-19644)
7 months 1 week ago
A vulnerability has been found in AVTECH DVR and classified as critical. Affected by this vulnerability is an unknown functionality of the file Search.cgi?action=cgi_query. The manipulation of the argument queryb64str leads to os command injection.
This vulnerability is known as CVE-2025-34054. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-4584 | IRM Newsroom Plugin up to 1.2.17 on WordPress Shortcode irmeventlist cross site scripting (EUVD-2025-18239)
7 months 1 week ago
A vulnerability classified as problematic has been found in IRM Newsroom Plugin up to 1.2.17 on WordPress. This affects the function irmeventlist of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-4584. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-4585 | IRM Newsroom Plugin up to 1.2.17 on WordPress Shortcode irmflat cross site scripting (EUVD-2025-18241)
7 months 1 week ago
A vulnerability, which was classified as problematic, has been found in IRM Newsroom Plugin up to 1.2.17 on WordPress. This issue affects the function irmflat of the component Shortcode Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-4585. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-4586 | IRM Newsroom Plugin up to 1.2.17 on WordPress Shortcode irmcalendarview cross site scripting (EUVD-2025-18233)
7 months 1 week ago
A vulnerability, which was classified as problematic, was found in IRM Newsroom Plugin up to 1.2.17 on WordPress. Affected is the function irmcalendarview of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-4586. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com