Aggregator
CVE-2023-1030 | SourceCodester/code-projects Online Boat Reservation System 1.0 POST Parameter /boat/login.php un cross site scripting
Submit #546164: PHPGurukul Restaurant Table Booking System 1.0 SQL Injection [Accepted]
Submit #548985: jfinal <=5.2.4 Absolute Path Traversal [Accepted]
CVE-2025-2980 | Legrand SMS PowerView 1.x redirect
Submit #546128: PHPGurukul e-Diary Management V1.0 SQL Injection [Accepted]
从CVE-2025-30208看任意文件读取利用
从CVE-2025-30208看任意文件读取利用
从CVE-2025-30208看任意文件读取利用
从CVE-2025-30208看任意文件读取利用
从CVE-2025-30208看任意文件读取利用
Submit #545964: code-projects patient-record-management-system-in-php 0/1 sql injection [Accepted]
Submit #545962: code-projects patient-record-management-system-in-php 0/1 sql injection [Accepted]
Submit #545961: code-projects patient-record-management-system-in-php 0/1 sql injection [Accepted]
Submit #545960: code-projects patient-record-management-system-in-php 0/1 php sql injection [Accepted]
Submit #545934: code-projects patient-record-management-system-in-php 0/1 php sql injection [Accepted]
Attackers are leveraging Cisco Smart Licensing Utility static admin credentials (CVE-2024-20439)
CVE-2024-20439, a static credential vulnerability in the Cisco Smart Licensing Utility, is being exploited by attackers in the wild, CISA has confirmed on Monday by adding the flaw to its Known Exploited Vulnerabilities catalog. Cisco has followed up with a confirmation by updating the security advisory covering CVE-2024-20439 and CVE-2024-20440, an information disclosure flaw in the same software. “In March 2025, the Cisco Product Security Incident Response Team (PSIRT) became aware of attempted exploitation of … More →
The post Attackers are leveraging Cisco Smart Licensing Utility static admin credentials (CVE-2024-20439) appeared first on Help Net Security.
Cisco AnyConnect VPN Server Vulnerability Allows Attackers to Trigger DoS
Cisco has disclosed a significant vulnerability in its AnyConnect VPN Server for Meraki MX and Z Series devices, allowing authenticated attackers to trigger denial-of-service (DoS) conditions. The flaw (CVE-2025-20212) stems from an uninitialized variable during SSL VPN session establishment and affects over 20 hardware models across enterprise networks. Vulnerability Overview Exploiting this bug requires valid VPN credentials. Attackers can […]
The post Cisco AnyConnect VPN Server Vulnerability Allows Attackers to Trigger DoS appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Submit #545895: code-projects Hospital Management System 1.0 SQL Injection [Accepted]
New Trinda Malware Targets Android Devices by Replacing Phone Numbers During Calls
Kaspersky Lab has uncovered a new version of the Triada Trojan, a sophisticated malware targeting Android devices. This variant has been found pre-installed in the firmware of counterfeit smartphones mimicking popular models, often sold at discounted prices through unauthorized online stores. The malware poses significant risks to users, with more than 2,600 cases reported globally, […]
The post New Trinda Malware Targets Android Devices by Replacing Phone Numbers During Calls appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.