Aggregator
CVE-2025-10831 | Campcodes Computer Sales and Inventory System 1.0 /pages/pro_edit1.php prodcode sql injection
CVE-2025-10832 | SourceCodester Pet Grooming Management Software 1.0 fetch_product_details.php barcode sql injection
CVE-2025-10833 | 1000projects Bookstore Management System 1.0 /login.php unm sql injection (EUVD-2025-30435)
CVE-2025-10834 | itsourcecode Open Source Job Portal 1.0 login.php user_email sql injection (EUVD-2025-30418)
CVE-2025-10835 | SourceCodester Pet Grooming Management Software 1.0 /admin/view_payorder.php ID sql injection
CVE-2025-10836 | SourceCodester Pet Grooming Management Software 1.0 /admin/print1.php ID sql injection
CVE-2025-10837 | code-projects Simple Food Ordering System 1.0 /ordersimple/order.php ID cross site scripting
CVE-2025-10838 | Tenda AC21 16.03.08.16 /goform/WifiExtraSet sub_45BB10 wpapsk_crypto buffer overflow
CVE-2025-10839 | SourceCodester Pet Grooming Management Software 1.0 /admin/inv-print.php ID sql injection
CVE-2025-10840 | SourceCodester Pet Grooming Management Software 1.0 /admin/print-payment.php sql111 sql injection
CVE-2025-10380 | Advanced Views Plugin up to 3.7.19 on WordPress special elements used in a template engine
CVE-2025-8902 | Widget Options Extended Plugin up to 5.2.1 on WordPress do_sidebar cross site scripting
Hackers Exploits IMDS Service to Gain Initial Access to a Cloud Environment
Threat actors were manipulating the Instance Metadata Service (IMDS), a core component designed to securely furnish compute instances with temporary credentials to infiltrate and navigate cloud infrastructures. By compelling unsuspecting applications to query IMDS endpoints, attackers harvest short-lived tokens, enabling credential theft, lateral movement, and privilege escalation within victim environments. Exploit IMDS Service Wiz reports […]
The post Hackers Exploits IMDS Service to Gain Initial Access to a Cloud Environment appeared first on Cyber Security News.
CVE-2025-10851 | Campcodes Gym Management System 1.0 /ajax.php?action=login Username sql injection (EUVD-2025-30878)
CVE-2025-10857 | Campcodes Point of Sale System POS 1.0 /login.php Username sql injection (EUVD-2025-30876)
CVE-2025-10147 | Eric Teubert Podlove Podcast Publisher Plugin up to 4.2.6 on WordPress move_as_original_file unrestricted upload (EUVD-2025-30877)
CVE-2025-9798 | Netcad Netigma prior 6.3.5 V8 cross site scripting (EUVD-2025-30875)
受 Salesforce 供应链攻击影响,全球汽车巨头 Stellantis 数据遭泄露
New npm Malware Steals Browser Passwords via Steganographic QR Code
A novel npm package named fezbox has been uncovered by the Socket Threat Research Team as a sophisticated malware delivery mechanism that exfiltrates username and password credentials from browser cookies via an embedded QR code. Published under the npm alias janedu (registration email janedu0216@gmail[.]com), the package masquerades as a harmless JavaScript/TypeScript utility library while quietly […]
The post New npm Malware Steals Browser Passwords via Steganographic QR Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.