Aggregator
China-linked group Houken hit French organizations using zero-days
9 months 3 weeks ago
China-linked group Houken hit French govt, telecom, media, finance and transport sectors using Ivanti CSA zero-days, says France’s ANSSI. France’s cyber agency ANSSI revealed that a Chinese hacking group used Ivanti CSA zero-days to target government, telecom, media, finance, and transport sectors. The campaign, active since September 2024, is linked to the Houken intrusion set, […]
Pierluigi Paganini
CVE-2013-2739 | minidlna memory corruption (EDB-38667 / OSVDB-95440)
9 months 3 weeks ago
A vulnerability has been found in minidlna and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2013-2739. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6920 | ai-inference-server API Inference Endpoint /invocations improper authentication
9 months 3 weeks ago
A vulnerability, which was classified as critical, was found in ai-inference-server. Affected is an unknown function of the file /invocations of the component API Inference Endpoint. The manipulation leads to improper authentication.
This vulnerability is traded as CVE-2025-6920. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2025-34056 | AVTECH IP Camera/DVR/NVR System Command PwdGrp.cgi pwd/grp os command injection (Exploit 40500 / EUVD-2025-19642)
9 months 3 weeks ago
A vulnerability classified as critical has been found in AVTECH IP Camera, DVR and NVR. This affects an unknown part of the file PwdGrp.cgi of the component System Command Handler. The manipulation of the argument pwd/grp leads to os command injection.
This vulnerability is uniquely identified as CVE-2025-34056. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-34050 | AVTECH IP Camera/DVR/NVR Web Interface cross-site request forgery (Exploit 40500 / EUVD-2025-19647)
9 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in AVTECH IP Camera, DVR and NVR. This affects an unknown part of the component Web Interface. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2025-34050. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-34055 | AVTECH IP Camera/DVR/NVR up to T717-T717-T717-T717 adcommand.cgi strCmd os command injection (Exploit 40500 / EUVD-2025-19643)
9 months 3 weeks ago
A vulnerability was found in AVTECH IP Camera, DVR and NVR. It has been rated as critical. Affected by this issue is some unknown functionality of the file adcommand.cgi. The manipulation of the argument strCmd leads to os command injection.
This vulnerability is handled as CVE-2025-34055. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6956 | Campcodes Employee Management System 1.0 /changepassemp.php ID sql injection (EUVD-2025-19615)
9 months 3 weeks ago
A vulnerability was found in Campcodes Employee Management System 1.0. It has been classified as critical. This affects an unknown part of the file /changepassemp.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-6956. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6953 | TOTOLINK A3002RU 3.0.0-B20230809.1615 HTTP POST Request formParentControl submit-url buffer overflow (EUVD-2025-19619)
9 months 3 weeks ago
A vulnerability, which was classified as critical, was found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affected is an unknown function of the file /boafrm/formParentControl of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow.
This vulnerability is traded as CVE-2025-6953. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6954 | Campcodes Employee Management System 1.0 /applyleave.php ID sql injection (EUVD-2025-19620)
9 months 3 weeks ago
A vulnerability has been found in Campcodes Employee Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /applyleave.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is known as CVE-2025-6954. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-34058 | Hikvision Streaming Media Management Server 2.3.5 /systemLog/downFile.php fileName weak password (CNVD-2021-14544 / EUVD-2025-19639)
9 months 3 weeks ago
A vulnerability was found in Hikvision Streaming Media Management Server 2.3.5. It has been classified as critical. Affected is an unknown function of the file /systemLog/downFile.php. The manipulation of the argument fileName leads to weak password requirements.
This vulnerability is traded as CVE-2025-34058. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-34051 | AVTECH DVR up to V189-V189-V189-V189 Search.cgi?action=cgi_query queryb64str server-side request forgery (Exploit 40500 / EUVD-2025-19631)
9 months 3 weeks ago
A vulnerability classified as critical has been found in AVTECH DVR. Affected is an unknown function of the file /cgi-bin/nobody/Search.cgi?action=cgi_query. The manipulation of the argument queryb64str leads to server-side request forgery.
This vulnerability is traded as CVE-2025-34051. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-6955 | Campcodes Employee Management System 1.0 /process/aprocess.php mailuid sql injection (EUVD-2025-19616)
9 months 3 weeks ago
A vulnerability was found in Campcodes Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /process/aprocess.php. The manipulation of the argument mailuid leads to sql injection.
This vulnerability is handled as CVE-2025-6955. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-34053 | AVTECH IP Camera/DVR/NVR up to S984-S984-S984-S984 strstr authentication spoofing (Exploit 40500 / EUVD-2025-19645)
9 months 3 weeks ago
A vulnerability classified as critical was found in AVTECH IP Camera, DVR and NVR. Affected by this vulnerability is the function strstr. The manipulation leads to authentication bypass by spoofing.
This vulnerability is known as CVE-2025-34053. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-34054 | AVTECH DVR up to 1023-1014-1017-1002-FFFF Search.cgi?action=cgi_query queryb64str os command injection (Exploit 40500 / EUVD-2025-19644)
9 months 3 weeks ago
A vulnerability has been found in AVTECH DVR and classified as critical. Affected by this vulnerability is an unknown functionality of the file Search.cgi?action=cgi_query. The manipulation of the argument queryb64str leads to os command injection.
This vulnerability is known as CVE-2025-34054. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-4584 | IRM Newsroom Plugin up to 1.2.17 on WordPress Shortcode irmeventlist cross site scripting (EUVD-2025-18239)
9 months 3 weeks ago
A vulnerability classified as problematic has been found in IRM Newsroom Plugin up to 1.2.17 on WordPress. This affects the function irmeventlist of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-4584. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-4585 | IRM Newsroom Plugin up to 1.2.17 on WordPress Shortcode irmflat cross site scripting (EUVD-2025-18241)
9 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in IRM Newsroom Plugin up to 1.2.17 on WordPress. This issue affects the function irmflat of the component Shortcode Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-4585. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-4586 | IRM Newsroom Plugin up to 1.2.17 on WordPress Shortcode irmcalendarview cross site scripting (EUVD-2025-18233)
9 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in IRM Newsroom Plugin up to 1.2.17 on WordPress. Affected is the function irmcalendarview of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-4586. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-3702 | Melapress File Monitor Plugin up to 2.1.x on WordPress authorization (EUVD-2025-19863)
9 months 3 weeks ago
A vulnerability was found in Melapress File Monitor Plugin up to 2.1.x on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to missing authorization.
The identification of this vulnerability is CVE-2025-3702. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-53502 | FeaturedFeeds Extension 1.39.x/1.42.x/1.43.x on Mediawiki cross site scripting (EUVD-2025-19888)
9 months 3 weeks ago
A vulnerability was found in FeaturedFeeds Extension 1.39.x/1.42.x/1.43.x on Mediawiki. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-53502. The attack may be initiated remotely. There is no exploit available.
vuldb.com