Seclists

Open Web Analytics SQL Injection

A high-severity SQL injection vulnerability (CVE-2025-59397) has been identified in Open Web Analytics (OWA) version 1.8.0 and likely affects earlier versions. The flaw allows authenticated users to inject arbitrary SQL commands.

Full Disclosure: Current Password not Required When Changing Password

A flaw has been identified in FlatPress v1.4.1 that allows an administrator to change their password without providing the current password. This bug undermines standard authentication practices and could lead to unauthorized access.

Full Disclosure: libelf 0.8.12 Stack-based buffer overflow in gmo2msg (libelf) via unbounded sprintf of lang argument

A stack-based buffer overflow vulnerability has been identified in `libelf` version 0.8.12, specifically within the `gmo2msg` utility. The flaw stems from unbounded `sprintf` operations on a fixed-size buffer when handling user-supplied input.

Stored XSS Vulnerability in Description Field of CubeCart v6.5.9

The flaw resides in the "Description" field of the Address Book edit functionality, allowing attackers to inject persistent JavaScript payloads that execute in the context of the victim's browser.

Windows User Group Policy Bypass via Offline Registry Hive Manipulation

A security bypass in Microsoft Windows allows unprivileged users to circumvent user group policies by leveraging the OFFREG.dll library to create a modified offline registry hive.

Stored XSS Vulnerability in ERPNext v15.53.1 Allows Script Execution via user_image Field

A stored cross-site scripting (XSS) vulnerability has been identified in ERPNext v15.53.1. The flaw resides in the `user_image` field of the user profile page, where an authenticated user can inject malicious JavaScript.

CVE-2025-45542: Time-Based Blind SQL Injection in CloudClassroom PHP Project v1.0

The `pass` parameter is not properly sanitized, allowing an unauthenticated remote attacker to manipulate backend SQL logic and potentially extract sensitive information.

Multiple Vulnerabilities in SAP GuiXT Scripting

Multiple critical vulnerabilities have been identified in SAP GuiXT scripting, enabling attackers to execute remote code, steal NTLM hashes, perform Client-Side Request Forgery (CSRF), and cause Denial-of-Service (DoS).

Structured Query Language Injection in frappe.desk.reportview.get_list Endpoint in Frappe Framework

A critical authenticated SQL injection vulnerability has been identified in the Frappe Framework, specifically affecting the `frappe.desk.reportview.get_list` API endpoint in version v15.56.1.

CVE-2025-30072 Tiiwee X1 Alarm System - Authentication Bypass by Capture-replay

A critical authentication bypass vulnerability (CVE-2025-30072) has been identified in the Tiiwee X1 Alarm System (version TWX1HAKV2). The system's use of unencrypted 433 MHz radio communication allows attackers to perform capture-replay attacks.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags