Current Conditions
São Paulo
nuvens quebradas

24 ℃
66%
Temperatura
Umidade
Fonte: OpenWeatherMap. - 12:00:02
  1. [USD] USD 71,600.58
  1. [BRL] BRL 373,268.14 [USD] USD 71,600.58 [GBP] GBP 53,574.99 [EUR] EUR 61,588.03
    Price index provided by blockchain.info.
  2. Bitcoin Core version 29.3 is now available for download. See the release notes for more information about the bug fixes in this release.
    If you have any questions, please stop by the #bitcoin IRC chatroom (IRC, web) and we’ll do our best to help you.

[CVE-2025-12493] [Modified: 26-11-2025] [Analyzed] [V3.1 S9.8:CRITICAL] The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the 'load_template' function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.

[CVE-2025-41111] [Modified: 05-11-2025] [Analyzed] [V3.1 S7.5:HIGH] A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_denuncia' in '/backend/api/buscarComentariosByDenuncia.php'.

[CVE-2025-41112] [Modified: 05-11-2025] [Analyzed] [V3.1 S7.5:HIGH] A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'web' in '/backend/api/buscarConfiguracionParametros2.php'.

[CVE-2025-41113] [Modified: 05-11-2025] [Analyzed] [V3.1 S7.5:HIGH] A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_denuncia' in '/backend/api/buscarDenunciaByPin.php'.

[CVE-2025-41114] [Modified: 05-11-2025] [Analyzed] [V3.1 S7.5:HIGH] A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user' in '/backend/api/buscarDocumentosByIdDenunciaUsuario.php'.

[CVE-2025-41335] [Modified: 05-11-2025] [Analyzed] [V3.1 S7.5:HIGH] A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id' and ' 'id_sociedad' in '/api/buscarEmpresaById.php'.

[CVE-2025-41336] [Modified: 05-11-2025] [Analyzed] [V3.1 S7.5:HIGH] A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'web' in '/backend/api/buscarConfiguracionParametros.php'.

[CVE-2025-41337] [Modified: 05-11-2025] [Analyzed] [V3.1 S7.5:HIGH] A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'web' in '/backend/api/buscarSSOParametros.php'.

[CVE-2025-41338] [Modified: 05-11-2025] [Analyzed] [V3.1 S7.5:HIGH] A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user' in '/backend/api/buscarTestigoByIdDenunciaUsuario.php'.

[CVE-2025-41339] [Modified: 05-11-2025] [Analyzed] [V3.1 S7.5:HIGH] A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_sociedad' in '/backend/api/buscarTipoDenuncia.php'.

[CVE-2025-41340] [Modified: 05-11-2025] [Analyzed] [V3.1 S7.5:HIGH] A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_tp_denuncia' and 'id_sociedad' in '/backend/api/buscarTipoDenunciabyId.php'.

[CVE-2025-41341] [Modified: 05-11-2025] [Analyzed] [V3.1 S7.5:HIGH] A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'seguro' in '/backend/api/buscarUsuarioByDenuncia.php'.

[CVE-2025-41342] [Modified: 05-11-2025] [Analyzed] [V3.1 S7.5:HIGH] A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_user' in '/backend/api/buscarUsuarioId.php'.

[CVE-2025-41343] [Modified: 05-11-2025] [Analyzed] [V3.1 S7.5:HIGH] A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'email' in '/backend/api/users/searchUserByEmail.php'.

[CVE-2025-41344] [Modified: 05-11-2025] [Analyzed] [V3.1 S7.5:HIGH] A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_archivo' in '/backend/api/verArchivo.php'.

[CVE-2025-41345] [Modified: 05-11-2025] [Analyzed] [V3.1 S7.5:HIGH] A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user' in '/backend/api/buscarDenunciasById.php'.

[CVE-2025-63294] [Modified: 04-02-2026] [Analyzed] [V3.1 S6.5:MEDIUM] WorkDo HRM SaaS HR and Payroll Tool 8.1 is affected vulnerable to Insecure Permissions. An authenticated user can create leave or resignation records on behalf of other users.

[CVE-2025-54323] [Modified: 07-11-2025] [Analyzed] [V3.1 S7.5:HIGH] An issue was discovered in the camera in Samsung Mobile Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, and 1580. Improper debug printing leads to information leakage.

[CVE-2025-54329] [Modified: 07-11-2025] [Analyzed] [V3.1 S7.5:HIGH] An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The function used to send a multiple-payloads message (including an SMS message) lacks bounds checking, which can lead to a heap overflow.

[CVE-2025-54330] [Modified: 07-11-2025] [Analyzed] [V3.1 S5.3:MEDIUM] An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Out-of-bounds Read of q->bufs[] in the __is_done_for_me function.