Aggregator
CVE-2025-6422 | Campcodes Online Recruitment Management System 1.0 About Content Page ajax.php?action=save_settings img unrestricted upload (EUVD-2025-18826)
CVE-2006-1959 | ActualScripts ActualAnalyzer 2.72/7.63/8.23 direct.php rf memory corruption (EDB-1767 / Nessus ID 21244)
CVE-2024-55058 | PHPGurukul Online Birth Certificate System 1.0 view-application-detail.php viewid resource injection (EUVD-2024-52729)
CVE-2024-55057 | PHPGurukul Online Birth Certificate System 1.0 weak password (EUVD-2024-52728)
CVE-2024-55056 | PHPGurukul Online Birth Certificate System 1.0 certificate-form.php full name cross site scripting (EUVD-2024-52727)
CVE-2024-55000 | Sourcecodester House Rental Management System 1.0 manage_categories.php cross site scripting (EUVD-2024-52725)
CVE-2024-54999 | MonicaHQ 4.1.2 General Information Module last_name injection (EUVD-2024-52724)
CVE-2024-54998 | MonicaHQ 4.1.2 /people/h Reason injection (EUVD-2024-52723)
Mattermost Vulnerabilities Let Attackers Execute Remote Code Via Path Traversal
Mattermost, a widely-used open-source collaboration platform, has recently disclosed critical vulnerabilities in its software that could allow attackers to execute remote code through path traversal exploits. As detailed on the official Mattermost Security Updates page, these flaws have been identified through rigorous security reviews and penetration testing conducted by global security research communities, deploying organizations, […]
The post Mattermost Vulnerabilities Let Attackers Execute Remote Code Via Path Traversal appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2019-11358 | jQuery up to 3.3.x Property extend Pollution cross site scripting (EDB-52141 / Nessus ID 208606)
CVE-2024-54997 | MonicaHQ 4.1.1 /journal/entries/ID/edit text improper authentication (EUVD-2024-52722)
CVE-2024-54994 | MonicaHQ 4.1.2 Add a new relationship first_name/last_name injection (EUVD-2024-52720)
CVE-2024-54996 | MonicaHQ 4.1.2 create title/description code injection (EUVD-2024-52721)
CVE-2024-54982 | Quectel BC25 BC25PAR01A06 NAS Message improper authentication (EUVD-2024-52717)
CVE-2024-54983 | Quectel BC95-CNV V100R001C00SPC051 NAS Message improper authentication (EUVD-2024-52718)
CVE-2024-54984 | Quectel BG96 BG96MAR02A08M1G NAS Message improper authentication (EUVD-2024-52719)
CVE-2024-54954 | OneBlog 2.3.6 Template Management Page injection (EUVD-2024-52716)
CVE-2013-4798 | HP LoadRunner up to 11.51 memory corruption (EDB-28083 / ID 121400)
Threat Actor Allegedly Selling FortiGate API Exploit Tool Targeting FortiOS
A threat actor has reportedly put up for sale a sophisticated FortiGate API exploit tool on a dark web marketplace, igniting significant concern within the cybersecurity community. The tool, which is being marketed for a price of $12,000 and comes with escrow services to facilitate transactions, is claimed to target Fortinet’s FortiOS systems by exploiting […]
The post Threat Actor Allegedly Selling FortiGate API Exploit Tool Targeting FortiOS appeared first on Cyber Security News.