Aggregator
CVE-2008-7120 | Mrcgiguy Hot Links SQL-PHP up to 3 news.php newsphp sql injection (EDB-32355 / BID-31118)
8 months 1 week ago
A vulnerability was found in Mrcgiguy Hot Links SQL-PHP up to 3. It has been classified as critical. This affects an unknown part of the file news.php. The manipulation of the argument newsphp leads to sql injection.
This vulnerability is uniquely identified as CVE-2008-7120. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Sponsor my laptop!
8 months 1 week ago
作者因旧笔记本电脑性能问题决定购买新13英寸Framework笔记本(约2500美元),资金由curl基金和个人众筹提供。若众筹超1000美元可升级配置。捐赠者可获得笔记本贴标机会。主要用于旅行和会议。
Over 600 Laravel Apps Exposed to Remote Code Execution Due to Leaked APP_KEYs on GitHub
8 months 1 week ago
Cybersecurity researchers have discovered a serious security issue that allows leaked Laravel APP_KEYs to be weaponized to gain remote code execution capabilities on hundreds of applications.
"Laravel's APP_KEY, essential for encrypting sensitive data, is often leaked publicly (e.g., on GitHub)," GitGuardian said. "If attackers get access to this key, they can exploit a deserialization flaw to
The Hacker News
Microsoft сократила 15 тысяч сотрудников. Нет, вы что, ИИ тут ни при чем
8 months 1 week ago
Люди слишком дорого думают? Как сэкономить полмиллиарда на колл-центрах.
CVE-2025-49666 | Microsoft Windows Server Setup/Boot Event Collection heap-based overflow (EUVD-2025-20578)
8 months 1 week ago
A vulnerability classified as critical was found in Microsoft Windows Server 2016/Server 2019/Server 2022/Server 2022 23H2/Server 2025. This vulnerability affects unknown code of the component Server Setup/Boot Event Collection. The manipulation leads to heap-based buffer overflow.
This vulnerability was named CVE-2025-49666. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Квантовый хаос не испугался вакуума, не остановился на холоде… но сдался перед светом
8 months 1 week ago
Лазер сделал то, на что не решались установки за миллионы.
CVE-2025-49673 | Microsoft Windows Server 2008 R2 SP1 up to Server 2022 23H2 Routing/Remote Access Service heap-based overflow (EUVD-2025-20574)
8 months 1 week ago
A vulnerability was found in Microsoft Windows. It has been rated as critical. This issue affects some unknown processing of the component Routing/Remote Access Service. The manipulation leads to heap-based buffer overflow.
The identification of this vulnerability is CVE-2025-49673. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-49695 | Microsoft Office use after free (EUVD-2025-20563 / Nessus ID 241553)
8 months 1 week ago
A vulnerability, which was classified as critical, has been found in Microsoft Office. Affected by this issue is some unknown functionality. The manipulation leads to use after free.
This vulnerability is handled as CVE-2025-49695. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-49696 | Microsoft Office out-of-bounds (EUVD-2025-20562 / Nessus ID 241553)
8 months 1 week ago
A vulnerability, which was classified as critical, was found in Microsoft Office. This affects an unknown part. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2025-49696. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-7543 | PHPGurukul User Registration & Login and User Management System /admin/manage-users.php sql injection (EUVD-2025-21270)
8 months 1 week ago
A vulnerability was found in PHPGurukul User Registration & Login and User Management System 3.3. It has been classified as critical. This affects an unknown part of the file /admin/manage-users.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-7543. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-7542 | PHPGurukul User Registration & Login and User Management System /admin/user-profile.php sql injection (EUVD-2025-21271)
8 months 1 week ago
A vulnerability was found in PHPGurukul User Registration & Login and User Management System 3.3 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/user-profile.php. The manipulation of the argument uid leads to sql injection.
This vulnerability is handled as CVE-2025-7542. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #613920: PHPGurukul User Registration & Login and User Management System With Admin Panel 3.3 SQL Injection [Accepted]
8 months 1 week ago
Submit #613920 / VDB-316239
4m3rr0r
Submit #613919: PHPGurukul User Registration & Login and User Management System With Admin Panel 3.3 SQL Injection [Accepted]
8 months 1 week ago
Submit #613919 / VDB-316238
4m3rr0r
CVE-2025-7541 | code-projects Online Appointment Booking System 1.0 /get_town.php countryid sql injection (EUVD-2025-21272)
8 months 1 week ago
A vulnerability has been found in code-projects Online Appointment Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /get_town.php. The manipulation of the argument countryid leads to sql injection.
This vulnerability is known as CVE-2025-7541. The attack can be launched remotely. Furthermore, there is an exploit available.
Other parameters might be affected as well.
vuldb.com
CVE-2025-7540 | code-projects Online Appointment Booking System 1.0 /getclinic.php townid sql injection (EUVD-2025-21268)
8 months 1 week ago
A vulnerability, which was classified as critical, was found in code-projects Online Appointment Booking System 1.0. Affected is an unknown function of the file /getclinic.php. The manipulation of the argument townid leads to sql injection.
This vulnerability is traded as CVE-2025-7540. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
Other parameters might be affected as well.
vuldb.com
CVE-2025-7539 | code-projects Online Appointment Booking System 1.0 /getdoctordaybooking.php cid sql injection (EUVD-2025-21269)
8 months 1 week ago
A vulnerability, which was classified as critical, has been found in code-projects Online Appointment Booking System 1.0. This issue affects some unknown processing of the file /getdoctordaybooking.php. The manipulation of the argument cid leads to sql injection.
The identification of this vulnerability is CVE-2025-7539. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #613918: PHPGurukul User Registration & Login and User Management System With Admin Panel 3.3 SQL Injection [Duplicate]
8 months 1 week ago
Submit #613918 / VDB-298801
4m3rr0r
Submit #613912: PHPGurukul User Registration & Login and User Management System With Admin Panel 3.3 SQL Injection [Duplicate]
8 months 1 week ago
Submit #613912 / VDB-280374
4m3rr0r
Submit #613911: PHPGurukul User Registration & Login and User Management System With Admin Panel 3.3 SQL Injection [Duplicate]
8 months 1 week ago
Submit #613911 / VDB-286191
4m3rr0r