Aggregator
CVE-2024-42645 | halfgaar FlashMQ 1.14.0 Retain Message denial of service
10 months 3 weeks ago
A vulnerability was found in halfgaar FlashMQ 1.14.0. It has been declared as problematic. This vulnerability affects unknown code of the component Retain Message Handler. The manipulation leads to denial of service.
This vulnerability was named CVE-2024-42645. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2025-6175 | DECE Geodi up to 9.0.146 HTTP Request crlf injection
10 months 3 weeks ago
A vulnerability was found in DECE Geodi up to 9.0.146. It has been classified as problematic. This affects an unknown part of the component HTTP Request Handler. The manipulation leads to crlf injection.
This vulnerability is uniquely identified as CVE-2025-6175. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-6060 | DECE Geodi up to 9.0.146 cross site scripting
10 months 3 weeks ago
A vulnerability was found in DECE Geodi up to 9.0.146 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-6060. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-28171 | Grandstream UCM6510 up to 1.0.20.52 Login information disclosure
10 months 3 weeks ago
A vulnerability has been found in Grandstream UCM6510 up to 1.0.20.52 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Login. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2025-28171. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-52358 | Vivaldi iCONTROL+ Server up to 4.7.8.0.eden/5.32 error/edit-menu-item cross site scripting
10 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Vivaldi iCONTROL+ Server up to 4.7.8.0.eden/5.32. Affected is an unknown function. The manipulation of the argument error/edit-menu-item leads to cross site scripting.
This vulnerability is traded as CVE-2025-52358. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-28172 | Grandstream UCM6510 up to 1.0.20.52 excessive authentication
10 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Grandstream UCM6510 up to 1.0.20.52. This issue affects some unknown processing. The manipulation leads to improper restriction of excessive authentication attempts.
The identification of this vulnerability is CVE-2025-28172. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2025-46059 | langchain-ai LangChain 0.3.51 GmailToolkit injection (Issue 30833)
10 months 3 weeks ago
A vulnerability classified as problematic was found in langchain-ai LangChain 0.3.51. This vulnerability affects unknown code of the component GmailToolkit. The manipulation leads to injection.
This vulnerability was named CVE-2025-46059. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-42644 | halfgaar FlashMQ 1.14.0 getNewPublish QoS assertion
10 months 3 weeks ago
A vulnerability classified as problematic has been found in halfgaar FlashMQ 1.14.0. This affects the function PublishCopyFactory::getNewPublish. The manipulation of the argument QoS leads to reachable assertion.
This vulnerability is uniquely identified as CVE-2024-42644. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2025-7458 | SQLite up to 3.41.1 SELECT Statement sqlite3KeyInfoFromExprList integer overflow
10 months 3 weeks ago
A vulnerability was found in SQLite up to 3.41.1. It has been rated as problematic. Affected by this issue is the function sqlite3KeyInfoFromExprList of the component SELECT Statement Handler. The manipulation leads to integer overflow.
This vulnerability is handled as CVE-2025-7458. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-50738 | usememos up to 0.24.3 Markdown Image information disclosure
10 months 3 weeks ago
A vulnerability was found in usememos memos up to 0.24.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Markdown Image Handler. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2025-50738. The attack can be launched remotely. There is no exploit available.
vuldb.com
U.S. Seizes $2.4M in Crypto by Dallas FBI in Ransomware Case
10 months 3 weeks ago
U.S. Seizes $2.4M in Crypto by Dallas FBI in Ransomware Case
Dark Web Informer - Cyber Threat Intelligence
CVE-2025-6505 | Progress Hybrid Data Pipeline up to 4.6.2.3226 on Linux Request improper authorization
10 months 3 weeks ago
A vulnerability was found in Progress Hybrid Data Pipeline up to 4.6.2.3226 on Linux. It has been classified as critical. Affected is an unknown function of the component Request Handler. The manipulation leads to improper authorization.
This vulnerability is traded as CVE-2025-6505. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-41241 | VMware vCenter unusual condition
10 months 3 weeks ago
A vulnerability was found in VMware vCenter, Cloud Foundation, Telco Cloud Platform and Telco Cloud Infrastructure and classified as problematic. This issue affects some unknown processing. The manipulation leads to improper check for unusual conditions.
The identification of this vulnerability is CVE-2025-41241. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-6504 | Progress Hybrid Data Pipeline prior 4.6.2.2978 on Linux Header X-Forwarded-For improper authorization
10 months 3 weeks ago
A vulnerability has been found in Progress Hybrid Data Pipeline on Linux and classified as critical. This vulnerability affects unknown code of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to improper authorization.
This vulnerability was named CVE-2025-6504. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-54422 | sandboxie-plus Sandboxie up to 1.16.1 cleartext storage (GHSA-jp7r-vgv9-43p7)
10 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in sandboxie-plus Sandboxie up to 1.16.1. This affects an unknown part. The manipulation leads to cleartext storage of sensitive information.
This vulnerability is uniquely identified as CVE-2025-54422. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-40686 | Human Resource Management System 1.0 /detailview.php employeeid cross site scripting
10 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Human Resource Management System 1.0. Affected by this issue is some unknown functionality of the file /detailview.php. The manipulation of the argument employeeid leads to cross site scripting.
This vulnerability is handled as CVE-2025-40686. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-40685 | Human Resource Management System 1.0 /state.php searcstate cross site scripting
10 months 3 weeks ago
A vulnerability classified as problematic was found in Human Resource Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /state.php. The manipulation of the argument searcstate leads to cross site scripting.
This vulnerability is known as CVE-2025-40685. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-40684 | Human Resource Management System 1.0 /country.php searccountry cross site scripting
10 months 3 weeks ago
A vulnerability classified as problematic has been found in Human Resource Management System 1.0. Affected is an unknown function of the file /country.php. The manipulation of the argument searccountry leads to cross site scripting.
This vulnerability is traded as CVE-2025-40684. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-51970 | PuneethReddyHC Online Shopping System Advanced 1.0 POST Parameter action.php keyword sql injection
10 months 3 weeks ago
A vulnerability was found in PuneethReddyHC Online Shopping System Advanced 1.0. It has been declared as critical. This vulnerability affects unknown code of the file action.php of the component POST Parameter Handler. The manipulation of the argument keyword leads to sql injection.
This vulnerability was named CVE-2025-51970. The attack can be initiated remotely. There is no exploit available.
vuldb.com