-
Celebrate Micro-Small, and Medium-sized Enterprises Day with Cloudflare
On June 27, the United Nations celebrates Micro-, Small, and Medium-sized Enterprises Day (MSME) to recognize the critical role these businesses play in the global economy and economic development. According to the World Bank and the UN, small and medium-sized businesses make up about 90 percent of all businesses, between 50-70 percent of global employment,…
-
CVE-2025-8371 – Code-projects Exam Form Submission SQL Injection Vulnerability
CVE ID : CVE-2025-8371 Published : July 31, 2025, 7:15 a.m. | 24 minutes ago Description : A vulnerability has been found in code-projects Exam Form Submission 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/update_s5.php. The manipulation of the argument credits leads to sql injection. The attack…
-
CVE-2025-8370 – Portabilis i-Educar Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-8370 Published : July 31, 2025, 7:15 a.m. | 24 minutes ago Description : A vulnerability, which was classified as problematic, was found in Portabilis i-Educar 2.9. Affected is an unknown function of the file /intranet/educar_escolaridade_lst.php. The manipulation of the argument descricao leads to cross site scripting. It is possible to launch the…
-
CVE-2025-8369 – Portabilis i-Educar Cross Site Scripting Vulnerability
CVE ID : CVE-2025-8369 Published : July 31, 2025, 6:15 a.m. | 1 hour, 24 minutes ago Description : A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.9. This issue affects some unknown processing of the file /intranet/educar_avaliacao_desempenho_lst.php. The manipulation of the argument titulo_avaliacao leads to cross site scripting. The attack may…
-
CVE-2025-8368 – Portabilis i-Educar Cross Site Scripting Vulnerability
CVE ID : CVE-2025-8368 Published : July 31, 2025, 6:15 a.m. | 1 hour, 24 minutes ago Description : A vulnerability classified as problematic was found in Portabilis i-Educar 2.9. This vulnerability affects unknown code of the file /intranet/pesquisa_pessoa_lst.php. The manipulation of the argument campo_busca/cpf leads to cross site scripting. The attack can be initiated remotely. The…
-
CVE-2025-53558 – ZTE Japan K.K. ZXHN-F660T/F660A Default Credential Vulnerability
CVE ID : CVE-2025-53558 Published : July 31, 2025, 6:15 a.m. | 1 hour, 51 minutes ago Description : ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge of the credential, an attacker may log in to the affected devices. Severity: 8.8 | HIGH Visit the link for…
-
CVE-2025-7847 – WordPress AI Engine Plugin Arbitrary File Upload Vulnerability
CVE ID : CVE-2025-7847 Published : July 31, 2025, 5:15 a.m. | 2 hours, 51 minutes ago Description : The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_simpleFileUpload() function in versions 2.9.3 and 2.9.4. This makes it possible for authenticated attackers, with Subscriber-level access and…
-
CVE-2025-54576 – OAuth2-Proxy Regex Pattern Bypass Authentication Vulnerability
CVE ID : CVE-2025-54576 Published : July 30, 2025, 8:15 p.m. | 11 hours, 51 minutes ago Description : OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load balancer setups. In versions 7.10.0 and below, oauth2-proxy deployments are vulnerable when using…
-
CVE-2025-53022 – TrustedFirmware-M Stack Buffer Overflow
CVE ID : CVE-2025-53022 Published : July 30, 2025, 8:15 p.m. | 11 hours, 51 minutes ago Description : TrustedFirmware-M (aka Trusted Firmware for M profile Arm CPUs) before 2.1.3 and 2.2.x before 2.2.1 lacks length validation during a firmware upgrade. While processing a new image, the Firmware Upgrade (FWU) module does not validate the length field…
-
CVE-2025-52187 – Apache GetProjectsIdea School Management System XSS
CVE ID : CVE-2025-52187 Published : July 30, 2025, 8:15 p.m. | 11 hours, 51 minutes ago Description : GetProjectsIdea Create School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in my_profile_update_form1.php. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more… Go to Source