Aggregator
CVE-2026-32117 | ekacnet grafanacubism-panel up to 0.1.2 cubism.js assign cross site scripting (GHSA-q6fh-6m3m-5948)
1 month 1 week ago
A vulnerability categorized as problematic has been discovered in ekacnet grafanacubism-panel up to 0.1.2. This affects the function assign of the file cubism.js. Executing a manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2026-32117. The attack may be performed from remote. There is no available exploit.
It is best practice to apply a patch to resolve this issue.
vuldb.com
CVE-2019-25482 | Jettweb Hazir Rent A Car Sitesi Scripti 2.0 POST Request arac_kategori_id sql injection (Exploit 46624)
1 month 1 week ago
A vulnerability was found in Jettweb Hazir Rent A Car Sitesi Scripti 2.0. It has been rated as critical. Affected is an unknown function of the component POST Request Handler. Performing a manipulation of the argument arac_kategori_id results in sql injection.
This vulnerability is cataloged as CVE-2019-25482. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2019-25488 | Jettweb Rent A Car Scripti 4.0 GET Parameter admin/index.php tur/id/ozellikdil sql injection (Exploit 46614)
1 month 1 week ago
A vulnerability categorized as critical has been discovered in Jettweb Rent A Car Scripti 4.0. Affected by this vulnerability is an unknown functionality of the file admin/index.php of the component GET Parameter Handler. Executing a manipulation of the argument tur/id/ozellikdil can lead to sql injection.
This vulnerability is registered as CVE-2019-25488. It is possible to launch the attack remotely. Furthermore, an exploit is available.
vuldb.com
CVE-2019-25508 | Jettweb Hazir Ilan Sitesi Scripti 2.0 katgetir.php kat sql injection (Exploit 46606)
1 month 1 week ago
A vulnerability identified as critical has been detected in Jettweb Hazir Ilan Sitesi Scripti 2.0. Affected by this issue is some unknown functionality of the file katgetir.php. The manipulation of the argument kat leads to sql injection.
This vulnerability is documented as CVE-2019-25508. The attack can be initiated remotely. Additionally, an exploit exists.
vuldb.com
CVE-2019-25510 | Jettweb Hazir Haber Sitesi Scripti 2.0 Administrative Interface admingiris.php username/password sql injection (Exploit 46598)
1 month 1 week ago
A vulnerability, which was classified as critical, has been found in Jettweb Hazir Haber Sitesi Scripti 2.0. This issue affects some unknown processing of the file admingiris.php of the component Administrative Interface. Performing a manipulation of the argument username/password results in sql injection.
This vulnerability was named CVE-2019-25510. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2019-25515 | Jettweb Hazir Haber Sitesi Scripti 3.0 login.php username/password sql injection (Exploit 46599)
1 month 1 week ago
A vulnerability has been found in Jettweb Hazir Haber Sitesi Scripti 3.0 and classified as critical. The affected element is an unknown function of the file login.php. The manipulation of the argument username/password leads to sql injection.
This vulnerability is referenced as CVE-2019-25515. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
vuldb.com
CVE-2019-25514 | Jettweb Hazir Haber Sitesi Scripti 3.0 kelime sql injection (Exploit 46599)
1 month 1 week ago
A vulnerability marked as critical has been reported in Jettweb Hazir Haber Sitesi Scripti 3.0. This vulnerability affects unknown code. This manipulation of the argument kelime causes sql injection.
This vulnerability appears as CVE-2019-25514. The attack may be initiated remotely. In addition, an exploit is available.
vuldb.com
CVE-2019-25517 | Jettweb Hazir Haber Sitesi Scripti 1.0 haberarsiv.php cid sql injection (Exploit 46597)
1 month 1 week ago
A vulnerability described as critical has been identified in Jettweb Hazir Haber Sitesi Scripti 1.0. This issue affects some unknown processing of the file haberarsiv.php. Such manipulation of the argument cid leads to sql injection.
This vulnerability is traded as CVE-2019-25517. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2019-25511 | Jettweb Hazir Haber Sitesi Scripti 3.0 fonksiyonlar.php videoid sql injection (Exploit 46599)
1 month 1 week ago
A vulnerability classified as critical has been found in Jettweb Hazir Haber Sitesi Scripti 3.0. Impacted is an unknown function of the file fonksiyonlar.php. Performing a manipulation of the argument videoid results in sql injection.
This vulnerability is known as CVE-2019-25511. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
vuldb.com
CVE-2019-25516 | Jettweb Hazir Haber Sitesi Scripti 1.0 gallery_id sql injection (Exploit 46597)
1 month 1 week ago
A vulnerability has been found in Jettweb Hazir Haber Sitesi Scripti 1.0 and classified as critical. This impacts an unknown function. This manipulation of the argument gallery_id causes sql injection.
The identification of this vulnerability is CVE-2019-25516. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2019-25513 | Jettweb Hazir Haber Sitesi Scripti 3.0 datagetir.php q sql injection (Exploit 46599)
1 month 1 week ago
A vulnerability was found in Jettweb Hazir Haber Sitesi Scripti 3.0. It has been declared as critical. Affected by this issue is some unknown functionality of the file datagetir.php. Executing a manipulation of the argument q can lead to sql injection.
This vulnerability is tracked as CVE-2019-25513. The attack can be launched remotely. Moreover, an exploit is present.
vuldb.com
Вэл Килмер возвращается с того света: нейросети доиграют роль актера в драме, которую он не успел закончить при жизни
1 month 1 week ago
Даже смерть больше не повод для увольнения?
Ransomware Affiliate Exposes Details of 'The Gentlemen' Operation
1 month 1 week ago
Hastalamuerte leaks The Gentlemen RaaS ops: FortiGate exploits, BYOVD evasion, Qilin split tactics
通过攻陷合法网站传播的新型iOS漏洞利用工具包DarkSword
1 month 1 week ago
SecWiki News 2026-03-19 Review
1 month 1 week ago
今日暂未更新资讯~
更多最新文章,请访问SecWiki
更多最新文章,请访问SecWiki
SLH
1 month 1 week ago
You must login to view this content
cohenido
FBI, CISA warn on Microsoft Intune risks after Iran-linked cyberattack on Stryker
1 month 1 week ago
The attackers behind a recent attack on Stryker did not use malware, instead breaking into a legitimate Microsoft device management system called Intune and wiping the company’s data that way.
CVE-2026-29793 | Feathersjs up to 5.0.41 getObjectId data query logic injection (GHSA-p9xr-7p9p-gpqx)
1 month 1 week ago
A vulnerability categorized as critical has been discovered in Feathersjs up to 5.0.41. The impacted element is the function getObjectId. The manipulation results in improper neutralization of special elements in data query logic.
This vulnerability was named CVE-2026-29793. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-29792 | Feathersjs up to 5.0.41 OAuth Service improper authentication (GHSA-wg9x-qfgw-pxhj)
1 month 1 week ago
A vulnerability described as critical has been identified in Feathersjs up to 5.0.41. The affected element is an unknown function of the component OAuth Service. Such manipulation leads to improper authentication.
This vulnerability is referenced as CVE-2026-29792. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com