Aggregator
CVE-2025-7476 | code-projects Simple Car Rental System 1.0 /admin/approve.php ID sql injection
1 week ago
A vulnerability classified as critical was found in code-projects Simple Car Rental System 1.0. This vulnerability affects unknown code of the file /admin/approve.php. The manipulation of the argument ID leads to sql injection.
This vulnerability was named CVE-2025-7476. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
ClickFix: The Emerging Technique Threat Actors Use to Dominate Targeted Organizations
1 week ago
Threat actors have increasingly adopted ClickFix, a sophisticated social engineering technique that deceives users into executing malicious commands under the guise of resolving common computer issues like performance lags or pop-up errors. This method, often delivered via compromised websites, malvertising, YouTube tutorials, or fake tech support forums, relies on clipboard hijacking also known as pastejacking […]
The post ClickFix: The Emerging Technique Threat Actors Use to Dominate Targeted Organizations appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Aman Mishra
WorldLeaks
1 week ago
You must login to view this content
cohenido
CVE-2004-0714 | Cisco IOS up to 12.3 SNMP Service denial of service (VU#162451 / Nessus ID 48974)
1 week ago
A vulnerability was found in Cisco IOS up to 12.3 and classified as critical. Affected by this issue is some unknown functionality of the component SNMP Service. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2004-0714. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2004-0715 | BEA WebLogic 7.0/8.1 Group Creation administrative Local Privilege Escalation (VU#470470 / ID 86650)
1 week ago
A vulnerability classified as problematic has been found in BEA WebLogic 7.0/8.1. Affected is an unknown function of the file administrative of the component Group Creation Handler. The manipulation leads to Local Privilege Escalation.
This vulnerability is traded as CVE-2004-0715. Local access is required to approach this attack. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2004-0715 | BEA WebLogic Deleted Group privileges management (VU#470470 / ID 86650)
1 week ago
A vulnerability has been found in BEA WebLogic and classified as critical. This vulnerability affects unknown code of the component Deleted Group Handler. The manipulation leads to improper privilege management.
This vulnerability was named CVE-2004-0715. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2004-0725 | Moodle up to 1.3.2 help.php File cross site scripting (EDB-24279 / Nessus ID 13843)
1 week ago
A vulnerability was found in Moodle up to 1.3.2. It has been classified as problematic. Affected is an unknown function of the file help.php. The manipulation of the argument File leads to basic cross site scripting.
This vulnerability is traded as CVE-2004-0725. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2004-0728 | Microsoft Systems Management Server 2.50.2726.0 Remote Control Client Service denial of service (EDB-366 / ID 90138)
1 week ago
A vulnerability was found in Microsoft Systems Management Server 2.50.2726.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Remote Control Client Service. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2004-0728. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to apply restrictive firewalling.
vuldb.com
CVE-2004-0730 | phpBB 2.0.8/2.0.8a cat_title/faq[0][0] cross site scripting (Nessus ID 13840 / ID 12092)
1 week ago
A vulnerability classified as problematic was found in phpBB 2.0.8/2.0.8a. This vulnerability affects unknown code. The manipulation of the argument cat_title/faq[0][0] leads to basic cross site scripting.
This vulnerability was named CVE-2004-0730. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2006-1699 | Aweb Banner Generator up to 3.0 index.php banner cross site scripting (EDB-27582 / XFDB-25782)
1 week ago
A vulnerability has been found in Aweb Banner Generator up to 3.0 and classified as problematic. This vulnerability affects unknown code of the file index.php. The manipulation of the argument banner leads to basic cross site scripting.
This vulnerability was named CVE-2006-1699. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2013-1509 | Oracle WebCenter Sites 7.6.2/11.1.1.6.0/11.1.1.6.1 (EDB-24964 / XFDB-83458)
1 week ago
A vulnerability was found in Oracle WebCenter Sites 7.6.2/11.1.1.6.0/11.1.1.6.1. It has been classified as problematic. Affected is an unknown function of the component WebCenter Sites. The manipulation leads to an unknown weakness.
This vulnerability is traded as CVE-2013-1509. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
系外彗星 3I/ATLAS 可能比太阳系还古老
1 week ago
天文学家本月早些时候宣布可能发现了已知第三个星际天体、第二个星际彗星 3I/ATLAS(第一个是 Oumuamua,第二个是星际彗星 2I/Borisov)。天文学家现在报告 3I/ATLAS 可能比太阳系还要古老 30 亿年,很可能是人类目前见过最古老的彗星。与之前发现的星际天体 1I/ ʻOumuamua 和 2I/Borisov 不同,3I/ATLAS 似乎不是沿着平坦的银河平面移动,而是以一条更陡峭的路径穿越银河,科学家推测它可能来自银河系的「厚盘」—那是一个分布着许多年老恒星的区域,位置在我们熟悉的银河盘面上下。研究推估,这颗彗星若是从厚盘区域的某颗古老恒星系统中诞生,那么它应该富含水冰成分。随着它逐渐靠近太阳,阳光将会加热并激发彗星表面产生活动,释放出气体与尘埃,进而形成明亮的彗发和彗尾。根据初步观测,3I/ATLAS 已经显现出活跃的征兆,甚至可能比之前那两颗星际天体的活跃程度更高。如果这些特征获得确认,将有助于我们推估未来还能从望远镜观测到类似星际天体的数量。
CVE-2023-0655 | SonicWALL Email Security Email Address information exposure (SNWLID-2023-0002 / EUVD-2023-12689)
1 week ago
A vulnerability, which was classified as problematic, has been found in SonicWALL Email Security. This issue affects some unknown processing of the component Email Address Handler. The manipulation leads to information exposure through error message.
The identification of this vulnerability is CVE-2023-0655. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2023-0670 | Ulearn a5a7ca20de859051ea0470542844980a66dfc05d permission (EUVD-2023-12701)
1 week ago
A vulnerability, which was classified as critical, was found in Ulearn a5a7ca20de859051ea0470542844980a66dfc05d. This affects an unknown part. The manipulation leads to permission issues.
This vulnerability is uniquely identified as CVE-2023-0670. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2023-1875 | thorsten phpmyfaq up to 3.1.11 cross site scripting (EUVD-2023-1269)
1 week ago
A vulnerability classified as problematic was found in thorsten phpmyfaq up to 3.1.11. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2023-1875. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-25278 | Drupal up to 9.3.18/9.4.2 Form API access control (EUVD-2023-1267)
1 week ago
A vulnerability, which was classified as critical, has been found in Drupal up to 9.3.18/9.4.2. Affected by this issue is some unknown functionality of the component Form API. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2022-25278. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-0664 | QEMU on Windows Guest Agent Service unnecessary privileges (EUVD-2023-12697 / Nessus ID 209569)
1 week ago
A vulnerability, which was classified as critical, has been found in QEMU on Windows. Affected by this issue is some unknown functionality of the component Guest Agent Service. The manipulation leads to execution with unnecessary privileges.
This vulnerability is handled as CVE-2023-0664. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-0643 | squidex up to 7.3.x additional special element (EUVD-2023-12677)
1 week ago
A vulnerability was found in squidex up to 7.3.x. It has been classified as problematic. This affects an unknown part. The manipulation leads to improper handling of additional special element.
This vulnerability is uniquely identified as CVE-2023-0643. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-0642 | squidex up to 7.3.x cross-site request forgery (EUVD-2023-12676)
1 week ago
A vulnerability was found in squidex up to 7.3.x. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2023-0642. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com