🛡 Cybersecurity & Privacy 🛡 - CVEs
Open in Telegram
🔐 Explore the latest CVEs in cybersecurity and privacy. 🔔 Daily updates. 💻 Ensuring your online security. 📩 lalilolalo.dev@gmail.com
Show more431
Subscribers
No data24 hours
No data7 days
-330 days
Posts Archive
‼️ CVE-2025-9009 ‼️
A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Affected is an unknown function of the file adminemailsetup.php. The manipulation of the argument Name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs‼️ CVE-2025-31961 ‼️
HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs‼️ CVE-2025-9008 ‼️
A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file adminsmssetting.php. The manipulation of the argument uname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs‼️ CVE-2025-9007 ‼️
A vulnerability has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function formeditFileName of the file goformeditFileName. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs‼️ CVE-2025-9006 ‼️
A vulnerability was identified in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function formdelFileName of the file goformdelFileName. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs‼️ CVE-2025-9005 ‼️
A vulnerability was determined in mtons mblog up to 3.5.0. Affected is an unknown function of the file register. The manipulation leads to information exposure through error message. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs‼️ CVE-2025-9004 ‼️
A vulnerability was found in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file settingspassword. The manipulation leads to improper restriction of excessive authentication attempts. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs‼️ CVE-2025-9003 ‼️
A vulnerability has been found in DLink DIR818LW 1.04. This vulnerability affects unknown code of the file bsclan.php of the component DHCP Reserved Address Handler. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely. This vulnerability only affects products that are no longer supported by the maintainer.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs‼️ CVE-2025-9002 ‼️
A vulnerability was identified in Surbowl dormitorymanagementphp 1.0. This affects an unknown part of the file login.php. The manipulation of the argument Account leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs‼️ CVE-2025-9001 ‼️
A vulnerability was determined in LemonOS up to nightly20240712 on LemonOS. Affected by this issue is the function HTTPGet of the file ApplicationsStealmain.cpp of the component HTTP Client. The manipulation of the argument chunkSize leads to stackbased buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs‼️ CVE-2025-8867 ‼️
The Graphina Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored CrossSite Scripting via multiple chart widget parameters in version 3.1.3 and below. This is due to insufficient input sanitization and output escaping on user supplied attributes such as chart categories, titles, and tooltip settings. This makes it possible for authenticated attackers, with contributorlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs‼️ CVE-2025-8680 ‼️
The B Slider Gutenberg Slider Block for WP plugin for WordPress is vulnerable to ServerSide Request Forgery in version less than, or equal to, 2.0.0 via the fsapirequest function. This makes it possible for authenticated attackers, with subscriberlevel access and above to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs‼️ CVE-2025-8676 ‼️
The B Slider Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in versions less than, or equal to, 2.0.0 via the getactiveplugins function. This makes it possible for authenticated attackers, with subscriberlevel access and above to extract sensitive data including installed plugin information.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs‼️ CVE-2025-8342 ‼️
The WooCommerce OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass due to insufficient empty value checking in the lwpajaxregister function in all versions up to, and including, 1.8.47. This makes it possible for unauthenticated attackers to bypass OTP verification and gain administrative access to any user account with a configured phone number by exploiting improper Firebase API error handling when the Firebase API key is not configured.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs‼️ CVE-2025-6025 ‼️
The Order Tip for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Improper Input Validation in all versions up to, and including, 1.5.4. This is due to lack of serverside validation on the datatip attribute, which makes it possible for unauthenticated attackers to apply an excessive or even negative tip amount, resulting in unauthorized discount up to free orders depending on the value submitted.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs‼️ CVE-2025-9000 ‼️
A vulnerability was found in Mechrevo Control Center GX V2 5.56.51.48. Affected by this vulnerability is an unknown functionality of the component reg File Handler. The manipulation leads to uncontrolled search path. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs‼️ CVE-2025-8993 ‼️
A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. This affects an unknown part of the file adminexpensereport.php. The manipulation of the argument fromdate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs‼️ CVE-2025-8992 ‼️
A vulnerability has been found in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality. The manipulation leads to crosssite request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs‼️ CVE-2025-8991 ‼️
A vulnerability was identified in linlinjava litemall up to 1.8.0. Affected by this vulnerability is an unknown functionality of the file adminconfigexpress of the component Business Logic Handler. The manipulation of the argument litemallexpressfreightmin leads to business logic errors. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs‼️ CVE-2025-8990 ‼️
A vulnerability was determined in codeprojects Online Medicine Guide 1.0. Affected is an unknown function of the file browsemdcn.php. The manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
📖 Read more.
🔗 Via "National Vulnerability Database"
----------
👁️ Seen on @cibsecurity_CVEs