Development

watchTowr Warns of Active Exploitation of SonicWall SMA 100 Devices

watchTowr reveals active exploitation of SonicWall SMA 100 vulnerabilities (CVE-2024-38475 & CVE-2023-44221) potentially leading to full system takeover and session hijacking. Learn about affected mod …
Read more

Published Date:
May 03, 2025 (4 hours, 5 minutes ago)

Vulnerabilities has been mentioned in this article.

CVE-2024-38475

CVE-2023-44221

CVE-2025-2774: Webmin Vulnerability Allows Root-Level Privilege Escalation

Webmin, a popular web-based system administration tool used to manage Unix-like servers and various services with approximately 1,000,000 yearly installations worldwide, has been found to contain a cr …
Read more

Published Date:
May 04, 2025 (1 hour, 1 minute ago)

Vulnerabilities has been mentioned in this article.

CVE ID : CVE-2025-47244

Published : May 3, 2025, 11:15 p.m. | 2 hours, 16 minutes ago

Description : Inedo ProGet through 2024.22 allows remote attackers to reach restricted functionality through the C# reflection layer, as demonstrated by causing a denial of service (when an attacker executes a loop calling RestartWeb) or obtaining potentially sensitive information. Exploitation can occur if Anonymous access is enabled, or if there is a successful CSRF attack.

Severity: 7.3 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-47245

Published : May 4, 2025, 12:15 a.m. | 1 hour, 16 minutes ago

Description : In BlueWave Checkmate through 2.0.2 before d4a6072, an invite request can be modified to specify a privileged role.

Severity: 8.1 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Electron wrapper for the NativePHP framework. Source: Read More 

Billions of Apple Devices at Risk from “AirBorne” AirPlay Vulnerabilities

Oligo Security uncovers “AirBorne,” a set of 23 vulnerabilities in Apple AirPlay affecting billions of devices. Learn how these flaws enable remote control (RCE) and data theft on iPhones, Macs, CarPl …
Read more

Published Date:
May 03, 2025 (2 hours, 45 minutes ago)

Vulnerabilities has been mentioned in this article.

CVE-2025-24132

CVE-2025-24271

CVE-2025-24252

CVE-2025-24129

CVE ID : CVE-2025-4240

Published : May 3, 2025, 6:15 p.m. | 3 hours, 16 minutes ago

Description : A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. This issue affects some unknown processing of the component LCD Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

Severity: 7.3 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-4241

Published : May 3, 2025, 6:15 p.m. | 3 hours, 16 minutes ago

Description : A vulnerability classified as critical has been found in PHPGurukul Teacher Subject Allocation Management System 1.0. Affected is an unknown function of the file /admin/search.php. The manipulation of the argument searchdata leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

Severity: 7.3 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-1838

Published : May 3, 2025, 7:15 p.m. | 2 hours, 16 minutes ago

Description : IBM Cloud Pak for Business Automation

24.0.0 and 24.0.1 through 24.0.1 IF001

Authoring allows an authenticated user to bypass client-side data validation in an authoring user interface which could cause a denial of service.

Severity: 6.5 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-4242

Published : May 3, 2025, 7:15 p.m. | 2 hours, 16 minutes ago

Description : A vulnerability classified as critical was found in PHPGurukul Online Birth Certificate System 2.0. Affected by this vulnerability is an unknown functionality of the file /admin/between-dates-report.php. The manipulation of the argument fromdate leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

Severity: 7.3 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-4243

Published : May 3, 2025, 7:15 p.m. | 2 hours, 16 minutes ago

Description : A vulnerability, which was classified as critical, has been found in code-projects Online Bus Reservation System 1.0. Affected by this issue is some unknown functionality of the file /print.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

Severity: 6.3 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-4244

Published : May 3, 2025, 8:15 p.m. | 1 hour, 16 minutes ago

Description : A vulnerability, which was classified as critical, was found in code-projects Online Bus Reservation System 1.0. This affects an unknown part of the file /seatlocation.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

Severity: 6.3 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more…