Aggregator
CVE-2026-7196 | CodeAstro Online Classroom 1.0 /guestdetails deleteid sql injection
1 month 3 weeks ago
A vulnerability described as critical has been identified in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /guestdetails. Such manipulation of the argument deleteid leads to sql injection.
This vulnerability is listed as CVE-2026-7196. The attack may be performed from remote. In addition, an exploit is available.
vuldb.com
Submit #801111: sourcecodester Pharmacy Sales and Inventory System V1.0 cross site scripting [Accepted]
1 month 3 weeks ago
Submit #801111 / VDB-359801
zhuque
Submit #801109: sourcecodester Pharmacy Sales and Inventory System V1.0 SQL injection [Accepted]
1 month 3 weeks ago
Submit #801109 / VDB-359800
zhuque
Medtronic confirms breach after hackers claim 9 million records theft
1 month 3 weeks ago
Medical device giant Medtronic disclosed last week that hackers breached its network and accessed data in "certain corporate IT systems." [...]
Bill Toulas
Submit #801030: codeastro Online Classroom V1.0 SQL Injection [Accepted]
1 month 3 weeks ago
Submit #801030 / VDB-359799
hackint
CVE-2026-7194 | SourceCodester Pharmacy Sales and Inventory System 1.0 ajax.php?action=save_product ID sql injection
1 month 3 weeks ago
A vulnerability marked as critical has been reported in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts an unknown function of the file /ajax.php?action=save_product. This manipulation of the argument ID causes sql injection.
This vulnerability is tracked as CVE-2026-7194. The attack is possible to be carried out remotely. Moreover, an exploit is present.
vuldb.com
Русский язык, Шрек и учебники — всё это теперь "угроза". Anthropic так усилила фильтры, что ИИ отказывается работать
1 month 3 weeks ago
Opus 4.7 теперь блокирует учебники, PDF с игрушками и русский язык.
Submit #800977: sourcecodester Pharmacy Sales and Inventory System V1.0 SQL injection [Accepted]
1 month 3 weeks ago
Submit #800977 / VDB-359798
cm7ai
CVE-2026-6265 | Cerberus FTP Server up to 2025.4.2/2026.0 on Windows insecure preserved inherited permissions
1 month 3 weeks ago
A vulnerability labeled as problematic has been found in Cerberus FTP Server up to 2025.4.2/2026.0 on Windows. This affects an unknown function. The manipulation results in insecure preserved inherited permissions.
This vulnerability is identified as CVE-2026-6265. The attack is only possible with local access. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2025-15626 | Ribblr Crotchet and Knitting 2.5 on iOS authorization
1 month 3 weeks ago
A vulnerability identified as problematic has been detected in Ribblr Crotchet and Knitting 2.5 on iOS. The impacted element is an unknown function. The manipulation leads to authorization bypass.
This vulnerability is referenced as CVE-2025-15626. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2026-25710 | KDE Plasma plasma-login-manager privilege dropping
1 month 3 weeks ago
A vulnerability categorized as critical has been discovered in KDE Plasma. The affected element is an unknown function of the component plasma-login-manager. Executing a manipulation can lead to privilege dropping / lowering errors.
The identification of this vulnerability is CVE-2026-25710. The attack can only be executed locally. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software
1 month 3 weeks ago
A Chinese national posed as a U.S. researcher, tricking NASA staff in a phishing campaign to steal sensitive data tied to defense software and exports. A Chinese national ran a spear-phishing campaign by posing as a U.S. researcher and tricked NASA employees into sharing sensitive information. The NASA Office of Inspector General (OIG) and federal […]
Pierluigi Paganini
LINKEDIN BROWSERGATE
1 month 3 weeks ago
BrowserGate claims LinkedIn secretly fingerprints users via extensions and device data, sending encrypted results to third parties for tracking. BrowserGate is an investigation conducted by Fairlinked (https://browsergate.eu/), an association of commercial LinkedIn users, which documents what it describes as one of the largest data breach and corporate espionage scandals in digital history. The central thesis: […]
Pierluigi Paganini
Widely Used Browser Extensions Selling User Data
1 month 3 weeks ago
Dozens of browser extensions openly sell user data via privacy policy disclosures
⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More
1 month 3 weeks ago
Everything is dumb again. This week feels broken in a very familiar way. Old tricks are back. New tools are doing shady crap. Supply chains got hit. Fake help desks worked. Weird research showed how easy some attacks still are.
Most of it feels like stuff we should have fixed years ago. Bad extensions. Stolen creds. Remote tools are getting abused. Malware hides in places people trust. Same
The Hacker News
Hackers impersonate Microsoft Teams help desk to breach corporate networks
1 month 3 weeks ago
Hackers are impersonating Microsoft Teams help desk workers to trick victims into installing data-stealing malware, researchers found.
上周关注度较高的产品安全漏洞(20260420-20260426)
1 month 3 weeks ago
上周关注度较高的产品安全漏洞(20260420-20260426)
CNVD漏洞周报2026年第16期
1 month 3 weeks ago
国家信息安全漏洞共享平台(以下简称CNVD)本周共收集、整理信息安全漏洞527个,其中高危漏洞241个、中危漏洞238个、低危漏洞48个。
Хватит всё запрещать. Путин напомнил законодателям, что в стране нужно развивать, а не только ограничивать
1 month 3 weeks ago
Глава государства предостерег депутатов от излишних барьеров, тормозящих развитие страны