Aggregator
Sarcoma
8 months 3 weeks ago
cohenido
东京法庭下令解散统一教会
8 months 3 weeks ago
关于日本文部科学省申请下令解散“世界和平统一家庭联合会”(原“统一教会”)一事,东京地方法院 25 日依据《宗教法人法》发出了解散命令。法院指出,捐款令至少超过 1500 人蒙受了约 204 亿日元的损失,“造成了规模空前的巨额损失”,且这样的损失最近仍在持续,教团也未采取充分的应对措施,法院认为除剥夺法人资格外没有有效的处置手段。这是继奥姆真理教等之后第三例以该法规定的“违反法令”为由作出的解散命令决定,也是首个以非法募集捐款等《民法》的不法行为为根据的案例。前首相安倍晋三遭枪击身亡案引发关注,捐款造成损失等再度成为社会问题,教团与政界的密切关系也充分暴露,法院此次对教团做出了严厉的司法判断。教团会长田中富广称,“这是对信教自由的侵害。无论如何都无法接受”,表示拟立即提出申诉。今后若东京高等法院支持该决定,解散命令就将生效。教团方面仍可向最高法院提出申诉。
Authentication bypass CVE-2025-22230 impacts VMware Windows Tools
8 months 3 weeks ago
Broadcom addressed a high-severity authentication bypass vulnerability, tracked as CVE-2025-22230, in VMware Tools for Windows. Broadcom released security updates to address a high-severity authentication bypass vulnerability, tracked as CVE-2025-22230 (CVSS score 9.8), impacting VMware Tools for Windows. VMware Tools for Windows is a suite of utilities that enhances the performance and usability of virtual machines […]
Pierluigi Paganini
CVE-2023-52972 | Huawei YutuFZ-5651S1 3.31.2.0 SenaryAudio access control (huawei-sa-20250325-01-pc)
8 months 3 weeks ago
A vulnerability was found in Huawei YutuFZ-5651S1 3.31.2.0. It has been rated as critical. This issue affects some unknown processing of the component SenaryAudio. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2023-52972. An attack has to be approached locally. There is no exploit available.
vuldb.com
Public-Private Ops Net Big Wins Against African Cybercrime
8 months 3 weeks ago
Three cybersecurity firms worked with Interpol and authorities in Nigeria, South Africa, Rwanda, and four other African nations to arrest more than 300 cybercriminals.
Robert Lemos, Contributing Writer
CVE-2012-2227 | PluXml 5.1.5 default_lang path traversal (EDB-18828 / XFDB-75330)
8 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in PluXml 5.1.5. Affected by this issue is some unknown functionality. The manipulation of the argument default_lang leads to path traversal.
This vulnerability is handled as CVE-2012-2227. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-49082 | Linux Kernel up to 5.15.33/5.16.19/5.17.2 _scsih_expander_node_remove Local use after free
8 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 5.15.33/5.16.19/5.17.2 and classified as critical. This issue affects the function _scsih_expander_node_remove. The manipulation of the argument Local leads to use after free.
The identification of this vulnerability is CVE-2022-49082. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-2232 | PureThemes Realteo Plugin up to 1.2.8 on WordPress do_register_user privileges management
8 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in PureThemes Realteo Plugin up to 1.2.8 on WordPress. Affected by this issue is the function do_register_user. The manipulation leads to improper privilege management.
This vulnerability is handled as CVE-2025-2232. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-29782 | LabRedesCefetRJ WeGIA up to 3.2.16 adicionar_tipo_docs_atendido.php tipo cross site scripting (GHSA-5x5w-5c99-vr8h)
8 months 3 weeks ago
A vulnerability was found in LabRedesCefetRJ WeGIA up to 3.2.16. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file adicionar_tipo_docs_atendido.php. The manipulation of the argument tipo leads to cross site scripting.
This vulnerability is known as CVE-2025-29782. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-2325 | boopathi0001 WP Test Email Plugin up to 1.1.8 on WordPress cross site scripting
8 months 3 weeks ago
A vulnerability was found in boopathi0001 WP Test Email Plugin up to 1.1.8 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-2325. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-2025 | GiveWP Plugin up to 3.22.0 on WordPress give_reports_earnings authorization
8 months 3 weeks ago
A vulnerability has been found in GiveWP Plugin up to 3.22.0 on WordPress and classified as problematic. Affected by this vulnerability is the function give_reports_earnings. The manipulation leads to missing authorization.
This vulnerability is known as CVE-2025-2025. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-1530 | tripetto Form Builder Plugin for Contact Forms, Surveys and Quizzes cross-site request forgery
8 months 3 weeks ago
A vulnerability was found in tripetto Form Builder Plugin for Contact Forms, Surveys and Quizzes up to 8.0.9 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2025-1530. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-2383 | PHPGurukul Doctor Appointment Management System 1.0 /doctor/search.php searchdata sql injection
8 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in PHPGurukul Doctor Appointment Management System 1.0. Affected by this issue is some unknown functionality of the file /doctor/search.php. The manipulation of the argument searchdata leads to sql injection.
This vulnerability is handled as CVE-2025-2383. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-2384 | code-projects Real Estate Property Management System 1.0 Parameter /InsertCustomer.php sql injection
8 months 3 weeks ago
A vulnerability, which was classified as critical, was found in code-projects Real Estate Property Management System 1.0. This affects an unknown part of the file /InsertCustomer.php of the component Parameter Handler. The manipulation of the argument txtName/txtAddress/cmbCity/txtEmail/cmbGender/txtBirthDate/txtUserName2/txtPassword2 leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-2384. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-2386 | PHPGurukul Local Services Search Engine Management System 1.0 /serviceman-search.php location sql injection
8 months 3 weeks ago
A vulnerability was found in PHPGurukul Local Services Search Engine Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /serviceman-search.php. The manipulation of the argument location leads to sql injection.
The identification of this vulnerability is CVE-2025-2386. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-2783: хакеры пробили Chrome через ошибку в Windows
8 months 3 weeks ago
«Форумный тролль»: Лаборатории Касперского нашла опасный эксплойт.
CVE-2024-35653 | Visual Composer Website Builder Plugin up to 45.8.0 on WordPress cross site scripting
8 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Visual Composer Website Builder Plugin up to 45.8.0 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-35653. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-35649 | Pdfcrowd Save as PDF Plugin up to 3.2.3 on WordPress cross site scripting
8 months 3 weeks ago
A vulnerability has been found in Pdfcrowd Save as PDF Plugin up to 3.2.3 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-35649. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-0756 | Insert or Embed Articulate Content into WordPress Plugin cross site scripting
8 months 3 weeks ago
A vulnerability was found in Insert or Embed Articulate Content into WordPress Plugin up to 4.3000000023 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting.
This vulnerability is handled as CVE-2024-0756. The attack may be launched remotely. There is no exploit available.
vuldb.com