Aggregator
A vulnerability was found in projectworlds Online Notes Sharing Platform 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument User leads to sql injection.
This vulnerability was named CVE-2025-8946. The attack can be initiated remotely. Furthermore, there is an exploit available.
Submit #632003: Projectworlds Visitor Management System Project V1.0 SQL injection [Accepted]
10 months 1 week ago
Submit #632003 / VDB-319914
guoma
Submit #631996: Projectworlds Visitor Management System Project V1.0 SQL injection [Duplicate]
10 months 1 week ago
Submit #631996 / VDB-319913
guoma
Submit #631995: Projectworlds Visitor Management System Project V1.0 SQL injection [Accepted]
10 months 1 week ago
Submit #631995 / VDB-319913
guoma
Голос в трубке стал оружием. Роскомнадзор перекрывает звонки в Telegram и WhatsApp
10 months 1 week ago
Началось частичное отключение звонков.
Patch Tuesday Update – August 2025
10 months 1 week ago
In total, including third-party CVEs, in this Patch Tuesday edition, Microsoft published 119 CVEs, including 8 republished CVEs. Overall, Microsoft announced 1 Zero-Day, 16 Critical, and 92 Important vulnerabilities. From an Impact perspective, Escalation of Privilege vulnerabilities accounted for 40%, while Remove Code Execution for 32% and Information Disclosure for 16%. Patches for this month …
The post Patch Tuesday Update – August 2025 appeared first on Security Boulevard.
Dragos Josanu
Submit #631982: Projectworlds Online Notes Sharing Platform Project V1.0 SQL injection [Accepted]
10 months 1 week ago
Submit #631982 / VDB-319912
guoma
CVE-2025-55668 | Apache Tomcat up to 9.0.105/10.1.41/11.0.7 session fixiation
10 months 1 week ago
A vulnerability was found in Apache Tomcat up to 9.0.105/10.1.41/11.0.7. It has been classified as critical. This affects an unknown part. The manipulation leads to session fixiation. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is uniquely identified as CVE-2025-55668. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2003-0466 | FreeBSD/OpenBSD/MacOS X realpath memory corruption (VU#743092 / EDB-74)
10 months 1 week ago
A vulnerability, which was classified as very critical, has been found in FreeBSD, OpenBSD and MacOS X. Affected by this issue is the function realpath. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2003-0466. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2003-0466 | wu-ftpd 2.5.0/2.6.0/2.6.1/2.6.2 fb_realpath memory corruption (VU#743092 / EDB-22976)
10 months 1 week ago
A vulnerability classified as critical was found in wu-ftpd 2.5.0/2.6.0/2.6.1/2.6.2. Affected by this vulnerability is the function fb_realpath. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2003-0466. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Microsoft removes PowerShell 2.0 from Windows 11, Windows Server
10 months 1 week ago
Microsoft will remove PowerShell 2.0 from Windows starting in August, eight years after announcing its deprecation and keeping it around as an optional feature. [...]
Sergiu Gatlan
电子科技大学 | 针对自定义LLM的指令后门攻击
10 months 1 week ago
本文提出了针对使用自定义化的大语言模型应用的指令后门攻击,攻击者通过精心设计的提示在输入包含预定义触发器时控制自定义 LLM 的输出。
CVE-2023-40028 | Ghost up to 5.59.0 content/ symlink (GHSA-9c9v-w225-v5rg / EDB-52409)
10 months 1 week ago
A vulnerability was found in Ghost up to 5.59.0 and classified as critical. Affected by this issue is some unknown functionality of the file content/. The manipulation leads to symlink following.
This vulnerability is handled as CVE-2023-40028. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
LLM安全漏洞挖掘专场沙龙,PPT+回放来啦!
10 months 1 week ago
下期沙龙见!
Patch the vulnerability: Confirm Sean Plankey as CISA director
10 months 1 week ago
The executive director of the National Technology Security Coalition writes that Plankey is a strong, capable leader who will strengthen public-private partnerships.
The post Patch the vulnerability: Confirm Sean Plankey as CISA director appeared first on CyberScoop.
Greg Otto
CVE-2025-55280 | ZKTeco WL20 Biometric Attendance System up to 3.1.8 cleartext storage (CIVN-2025-0172 / EUVD-2025-24561)
10 months 1 week ago
A vulnerability, which was classified as problematic, was found in ZKTeco WL20 Biometric Attendance System up to 3.1.8. This affects an unknown part. The manipulation leads to cleartext storage of sensitive information.
This vulnerability is uniquely identified as CVE-2025-55280. It is possible to launch the attack on the physical device. There is no exploit available.
vuldb.com
CVE-2024-6875 | Red Hat JBoss Data Grid 7/8 Infinispan memory leak (EUVD-2024-54328)
10 months 1 week ago
A vulnerability, which was classified as problematic, was found in Red Hat JBoss Data Grid 7/8. This affects an unknown part of the component Infinispan. The manipulation leads to memory leak.
This vulnerability is uniquely identified as CVE-2024-6875. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
How an AI-Based 'Pen Tester' Became a Top Bug Hunter on HackerOne
10 months 1 week ago
AI researcher explains how an automated penetration-testing tool became the first non-human member on HackerOne to reach the top of the platform's US leaderboard.
Rob Wright
ChatGPT теперь читает вашу почту, знает ваш график и помнит, кто такой Алексей из HR
10 months 1 week ago
С коннекторами ассистент станет по-настоящему личным.
Zoom and Xerox Release Critical Security Updates Fixing Privilege Escalation and RCE Flaws
10 months 1 week ago
Zoom and Xerox have addressed critical security flaws in Zoom Clients for Windows and FreeFlow Core that could allow privilege escalation and remote code execution.
The vulnerability impacting Zoom Clients for Windows, tracked as CVE-2025-49457 (CVSS score: 9.6), relates to a case of an untrusted search path that could pave the way for privilege escalation.
"Untrusted search path in
The Hacker News