Aggregator
CVE-2010-1726 | Alibabaclone EC21 Clone 3.0 offers_buy.php ID sql injection (EDB-12459 / XFDB-58266)
11 months 1 week ago
A vulnerability was found in Alibabaclone EC21 Clone 3.0. It has been declared as critical. This vulnerability affects unknown code of the file offers_buy.php. The manipulation of the argument ID leads to sql injection.
This vulnerability was named CVE-2010-1726. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2014-9096 | Pligg CMS up to 2.0.1 recover.php sql injection (ID 127615 / EDB-34168)
11 months 1 week ago
A vulnerability has been found in Pligg CMS up to 2.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file recover.php. The manipulation leads to sql injection.
This vulnerability is known as CVE-2014-9096. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-30929 | jeffpiazza DerbyNet 9.0 playlist.php back cross site scripting
11 months 1 week ago
A vulnerability, which was classified as problematic, was found in jeffpiazza DerbyNet 9.0. Affected is an unknown function of the file playlist.php. The manipulation of the argument back leads to cross site scripting.
This vulnerability is traded as CVE-2024-30929. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-3245 | wpdevteam EmbedPress Plugin up to 3.9.14 on WordPress cross site scripting (ID 3064544)
11 months 1 week ago
A vulnerability has been found in wpdevteam EmbedPress Plugin up to 3.9.14 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-3245. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-23592 | Lenovo Synaptics Fingerprint Readers security check
11 months 1 week ago
A vulnerability classified as critical has been found in Lenovo Synaptics Fingerprint Readers. This affects an unknown part. The manipulation leads to security check for standard.
This vulnerability is uniquely identified as CVE-2024-23592. It is possible to launch the attack on the physical device. There is no exploit available.
vuldb.com
CVE-2024-2444 | Inline Related Posts Plugin up to 3.4.x on WordPress Setting cross site scripting
11 months 1 week ago
A vulnerability has been found in Inline Related Posts Plugin up to 3.4.x on WordPress and classified as problematic. This vulnerability affects unknown code of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-2444. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-0662 | FancyBox Plugin 3.0.2/3.3.3 on WordPress cross site scripting
11 months 1 week ago
A vulnerability was found in FancyBox Plugin 3.0.2/3.3.3 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-0662. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-2458 | Powerkit Plugin up to 2.9.1 on WordPress Shortcode cross site scripting
11 months 1 week ago
A vulnerability classified as problematic has been found in Powerkit Plugin up to 2.9.1 on WordPress. Affected is an unknown function of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-2458. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
Cyberattacks on water and power utilities threaten public safety
11 months 1 week ago
62% of utility operators were targeted by cyberattacks in the past year, and of those, 80% were attacked multiple times, according to Semperis. 54% suffered permanent corruption or destruction of data and systems. (Source: Semperis) Utilities face rising cyber threats Recent high-profile cyberattacks by nation-state groups on water and electricity utilities underscore the vulnerability of critical infrastructure. A public utility in Littleton, MA, was recently compromised by a group linked to Volt Typhoon, the Chinese … More →
The post Cyberattacks on water and power utilities threaten public safety appeared first on Help Net Security.
Help Net Security
CVE-2004-2456 | MiniBB up to 1.7c index.php User sql injection (EDB-635 / Nessus ID 15763)
11 months 1 week ago
A vulnerability was found in MiniBB up to 1.7c. It has been classified as critical. This affects an unknown part of the file index.php. The manipulation of the argument User leads to sql injection.
This vulnerability is uniquely identified as CVE-2004-2456. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-27529 | Trend Micro Cleaner One Pro denial of service
11 months 1 week ago
A vulnerability classified as problematic was found in Trend Micro Cleaner One Pro. Affected by this vulnerability is an unknown functionality. The manipulation leads to denial of service.
This vulnerability is known as CVE-2025-27529. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2025-2760 | GIMP XWD File Parser integer overflow
11 months 1 week ago
A vulnerability classified as critical has been found in GIMP. Affected is an unknown function of the component XWD File Parser. The manipulation leads to integer overflow.
This vulnerability is traded as CVE-2025-2760. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-2761 | GIMP FLI File Parser out-of-bounds write
11 months 1 week ago
A vulnerability was found in GIMP. It has been rated as critical. This issue affects some unknown processing of the component FLI File Parser. The manipulation leads to out-of-bounds write.
The identification of this vulnerability is CVE-2025-2761. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-3416 | rust-openssl Md::fetch/Cipher::fetch use after free
11 months 1 week ago
A vulnerability was found in rust-openssl. It has been declared as critical. This vulnerability affects the function Md::fetch/Cipher::fetch. The manipulation leads to use after free.
This vulnerability was named CVE-2025-3416. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-31344 | giflib up to 5.2.2 DumpScreen2RGB buffer overflow
11 months 1 week ago
A vulnerability was found in giflib up to 5.2.2. It has been classified as critical. This affects the function DumpScreen2RGB. The manipulation leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2025-31344. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2025-2808 | Motors Plugin up to 1.4.63 on WordPress Phone Number cross site scripting
11 months 1 week ago
A vulnerability was found in Motors Plugin up to 1.4.63 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument Phone Number leads to cross site scripting.
This vulnerability is handled as CVE-2025-2808. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-3064 | WPFront User Role Editor Plugin up to 4.2.1 on WordPress whitelist_options cross-site request forgery
11 months 1 week ago
A vulnerability has been found in WPFront User Role Editor Plugin up to 4.2.1 on WordPress and classified as problematic. Affected by this vulnerability is the function whitelist_options. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2025-3064. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-3432 | AAWP Obfuscator Plugin up to 1.0 on WordPress data-aawp-web cross site scripting
11 months 1 week ago
A vulnerability, which was classified as problematic, was found in AAWP Obfuscator Plugin up to 1.0 on WordPress. Affected is an unknown function. The manipulation of the argument data-aawp-web leads to cross site scripting.
This vulnerability is traded as CVE-2025-3432. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-2876 | Melapress Security Plugin/Security Premium Plugin 2.1.0 on WordPress monitor_admin_actions authorization
11 months 1 week ago
A vulnerability, which was classified as critical, has been found in Melapress Security Plugin and Security Premium Plugin 2.1.0 on WordPress. This issue affects the function monitor_admin_actions. The manipulation leads to missing authorization.
The identification of this vulnerability is CVE-2025-2876. The attack may be initiated remotely. There is no exploit available.
vuldb.com