Current Conditions
São Paulo
nuvens quebradas

20 ℃
97%
Temperatura
Umidade
Fonte: OpenWeatherMap. - 12:30:01
  1. [USD] USD 71,331.56
  1. [BRL] BRL 367,321.86 [USD] USD 71,331.56 [GBP] GBP 52,985.65 [EUR] EUR 61,248.49
    Price index provided by blockchain.info.
  2. Bitcoin Core version 29.3 is now available for download. See the release notes for more information about the bug fixes in this release.
    If you have any questions, please stop by the #bitcoin IRC chatroom (IRC, web) and we’ll do our best to help you.

[CVE-2025-12938] [Modified: 17-11-2025] [Analyzed] [V3.1 S7.3:HIGH] A vulnerability was identified in projectworlds Online Admission System 1.0. Affected by this vulnerability is an unknown functionality of the file /process_login.php. The manipulation of the argument keywords leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.

[CVE-2025-12939] [Modified: 17-11-2025] [Analyzed] [V3.1 S6.3:MEDIUM] A security flaw has been discovered in SourceCodester Interview Management System up to 1.0. Affected by this issue is some unknown functionality of the file /addCandidate.php. The manipulation of the argument candName results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be exploited.

[CVE-2025-64456] [Modified: 20-11-2025] [Analyzed] [V3.1 S8.4:HIGH] In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation

[CVE-2025-64457] [Modified: 12-01-2026] [Analyzed] [V3.1 S4.2:MEDIUM] In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition

[CVE-2025-64681] [Modified: 20-11-2025] [Analyzed] [V3.1 S2.7:LOW] In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations

[CVE-2025-64682] [Modified: 20-11-2025] [Analyzed] [V3.1 S2.7:LOW] In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit

[CVE-2025-64683] [Modified: 21-11-2025] [Analyzed] [V3.1 S5.3:MEDIUM] In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API

[CVE-2025-64684] [Modified: 21-11-2025] [Analyzed] [V3.1 S4.3:MEDIUM] In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form

[CVE-2025-64685] [Modified: 21-11-2025] [Analyzed] [V3.1 S8.1:HIGH] In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure

[CVE-2025-12480] [Modified: 14-11-2025] [Analyzed] [V3.1 S9.1:CRITICAL] Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.

[CVE-2025-63710] [Modified: 17-11-2025] [Analyzed] [V3.1 S6.5:MEDIUM] The send_message.php endpoint in SourceCodester Simple Public Chat Room 1.0 is vulnerable to Cross-Site Request Forgery (CSRF). The application does not implement any CSRF-protection mechanisms such as tokens, nonces, or same-site cookie restrictions. An attacker can create a malicious HTML page that, when visited by an authenticated user, will automatically submit a forged POST request to the vulnerable endpoint. This request will be executed with the victim's privileges, allowing the attacker to perform unauthorized actions on their behalf, such as sending arbitrary messages in any chat room.

[CVE-2025-63711] [Modified: 17-11-2025] [Analyzed] [V3.1 S7.1:HIGH] A Cross-Site Request Forgery (CSRF) vulnerability in the SourceCodester Client Database Management System 1.0 allows an attacker to cause an authenticated administrative user to perform user deletion actions without their consent. The application's user deletion endpoint (e.g., superadmin_user_delete.php) accepts POST requests containing a user_id parameter and does not enforce request origin or anti-CSRF tokens. Because the endpoint lacks proper authentication/authorization checks and CSRF protections, a remote attacker can craft a malicious page that triggers deletion when visited by an authenticated admin, resulting in arbitrary removal of user accounts.

[CVE-2025-46430] [Modified: 12-11-2025] [Analyzed] [V3.1 S7.3:HIGH] Dell Display and Peripheral Manager, versions prior to 2.1.2.12, contains an Execution with Unnecessary Privileges vulnerability in the Installer. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

[CVE-2025-63152] [Modified: 17-11-2025] [Analyzed] [V3.1 S7.5:HIGH] Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the wpapsk_crypto parameter of the wlSetExternParameter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

[CVE-2025-63153] [Modified: 17-11-2025] [Analyzed] [V3.1 S7.5:HIGH] TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow in the ssid parameter of the urldecode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

[CVE-2025-63154] [Modified: 17-11-2025] [Analyzed] [V3.1 S7.5:HIGH] TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow in the addEffect parameter of the urldecode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

[CVE-2025-63455] [Modified: 17-11-2025] [Analyzed] [V3.1 S7.5:HIGH] Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGusetBasic function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

[CVE-2025-63497] [Modified: 11-12-2025] [Analyzed] [V3.1 S7.1:HIGH] The patient prescription viewing functionality in his_doc_view_single_patient.php of rickxy Hospital Management System version 1.0 contains an SQL injection vulnerability. The pat_number GET parameter is directly concatenated into SQL queries without proper sanitization, allowing authenticated attackers (doctor role) to execute arbitrary SQL queries.

[CVE-2025-43723] [Modified: 20-02-2026] [Analyzed] [V3.1 S5.9:MEDIUM] Dell PowerScale OneFS, versions prior to 9.10.1.3 and versions 9.11.0.0 through 9.12.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

[CVE-2025-47286] [Modified: 21-11-2025] [Analyzed] [V3.1 S7.2:HIGH] Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by editing the configuration of the iTop instance, execute code on the server. Versions 2.7.13 and 3.2.2 escape and check the config parameter before executing a command based on it.