Current Conditions
São Paulo
nublado

21 ℃
92%
Temperatura
Umidade
Fonte: OpenWeatherMap. - 06:00:01
  1. [USD] USD 68,961.07
  1. [BRL] BRL 354,618.49 [USD] USD 68,961.07 [GBP] GBP 51,938.78 [EUR] EUR 59,605.60
    Price index provided by blockchain.info.
  2. Bitcoin Core version 28.4 is now available for download. See the release notes for more information about the bug fixes in this release.
    If you have any questions, please stop by the #bitcoin IRC chatroom (IRC, web) and we’ll do our best to help you.

[CVE-2025-14218] [Modified: 09-12-2025] [Analyzed] [V3.1 S7.3:HIGH] A security flaw has been discovered in code-projects Currency Exchange System 1.0. The affected element is an unknown function of the file /editotheraccount.php. Performing manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited.

[CVE-2025-14221] [Modified: 09-12-2025] [Analyzed] [V3.1 S3.5:LOW] A vulnerability was detected in SourceCodester Online Banking System 1.0. This impacts an unknown function of the file /?page=user. The manipulation of the argument First Name/Last Name results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used.

[CVE-2025-14222] [Modified: 10-12-2025] [Analyzed] [V3.1 S6.3:MEDIUM] A flaw has been found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of the file /print_personnel_report.php. This manipulation of the argument per_id causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.

[CVE-2025-14223] [Modified: 10-12-2025] [Analyzed] [V3.1 S7.3:HIGH] A vulnerability has been found in code-projects Simple Leave Manager 1.0. Affected by this vulnerability is an unknown functionality of the file /request.php. Such manipulation of the argument staff_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

[CVE-2025-14253] [Modified: 15-01-2026] [Analyzed] [V3.1 S4.9:MEDIUM] Vitals ESP developed by Galaxy Software Services has an Arbitrary File Read vulnerability, allowing privileged remote attackers to exploit Absolute Path Traversal to download arbitrary system files.

[CVE-2025-14254] [Modified: 15-01-2026] [Analyzed] [V3.1 S6.5:MEDIUM] Vitals ESP developed by Galaxy Software Services has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.

[CVE-2025-14255] [Modified: 15-01-2026] [Analyzed] [V3.1 S6.5:MEDIUM] Vitals ESP developed by Galaxy Software Services has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.

[CVE-2025-66320] [Modified: 09-12-2025] [Analyzed] [V3.1 S5.1:MEDIUM] Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.

[CVE-2025-66321] [Modified: 09-12-2025] [Analyzed] [V3.1 S5.1:MEDIUM] Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.

[CVE-2025-66322] [Modified: 09-12-2025] [Analyzed] [V3.1 S5.1:MEDIUM] Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.

[CVE-2025-66323] [Modified: 09-12-2025] [Analyzed] [V3.1 S5.3:MEDIUM] Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerability may affect availability.

[CVE-2025-66324] [Modified: 09-12-2025] [Analyzed] [V3.1 S8.4:HIGH] Input verification vulnerability in the compression and decompression module. Impact: Successful exploitation of this vulnerability may affect app data integrity.

[CVE-2025-66326] [Modified: 09-12-2025] [Analyzed] [V3.1 S6.7:MEDIUM] Race condition vulnerability in the audio module. Impact: Successful exploitation of this vulnerability may affect availability.

[CVE-2025-12956] [Modified: 12-01-2026] [Analyzed] [V3.1 S8.7:HIGH] A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

[CVE-2025-14224] [Modified: 12-12-2025] [Analyzed] [V3.1 S4.3:MEDIUM] A vulnerability was found in Yottamaster DM2, DM3 and DM200 up to 1.2.23/1.9.12. Affected by this issue is some unknown functionality of the component File Upload. Performing manipulation results in path traversal. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

[CVE-2025-26487] [Modified: 22-12-2025] [Analyzed] [V3.1 S8.6:HIGH] Server-Side Request Forgery (SSRF) vulnerability in Infinera MTC-9 version allows remote unauthenticated users to gain access to other network resources using HTTPS requests through the appliance used as a bridge.

[CVE-2025-26488] [Modified: 22-12-2025] [Analyzed] [V3.1 S7.5:HIGH] Improper Input Validation vulnerability in Infinera MTC-9 allows remote unauthenticated users to crash the service and cause a reboot of the appliance, thus causing a DoS condition, via crafted XML payloads.This issue affects MTC-9: from R22.1.1.0275 before R23.0.

[CVE-2025-26489] [Modified: 22-12-2025] [Analyzed] [V3.1 S6.5:MEDIUM] Improper input validation in the Netconf service in Infinera MTC-9 allows remote authenticated users to crash the service and reboot the appliance, thus causing a DoS condition, via crafted XML payloads.This issue affects MTC-9: from R22.1.1.0275 before R23.0.

[CVE-2025-58279] [Modified: 09-12-2025] [Analyzed] [V3.1 S4.4:MEDIUM] Permission control vulnerability in the media library module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

[CVE-2025-66325] [Modified: 09-12-2025] [Analyzed] [V3.1 S6.2:MEDIUM] Permission control vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.