Current Conditions
São Paulo
nuvens dispersas

22 ℃
67%
Temperatura
Umidade
Fonte: OpenWeatherMap. - 17:30:01
  1. [USD] USD 69,040.91
  1. [BRL] BRL 357,410.96 [USD] USD 69,040.91 [GBP] GBP 51,534.69 [EUR] EUR 59,083.20
    Price index provided by blockchain.info.
  2. Bitcoin Core version 29.3 is now available for download. See the release notes for more information about the bug fixes in this release.
    If you have any questions, please stop by the #bitcoin IRC chatroom (IRC, web) and we’ll do our best to help you.

[CVE-2025-12604] [Modified: 05-11-2025] [Analyzed] [V3.1 S7.3:HIGH] A vulnerability has been found in itsourcecode Online Loan Management System 1.0. This affects an unknown part of the file /load_fields.php. The manipulation of the argument loan_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

[CVE-2025-12605] [Modified: 05-11-2025] [Analyzed] [V3.1 S7.3:HIGH] A vulnerability was found in itsourcecode Online Loan Management System 1.0. This vulnerability affects unknown code of the file /manage_loan.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.

[CVE-2025-12606] [Modified: 05-11-2025] [Analyzed] [V3.1 S7.3:HIGH] A vulnerability was determined in itsourcecode Online Loan Management System 1.0. This issue affects some unknown processing of the file /manage_borrower.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

[CVE-2025-12607] [Modified: 05-11-2025] [Analyzed] [V3.1 S7.3:HIGH] A vulnerability was identified in itsourcecode Online Loan Management System 1.0. Impacted is an unknown function of the file /manage_payment.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.

[CVE-2025-12608] [Modified: 05-11-2025] [Analyzed] [V3.1 S7.3:HIGH] A security flaw has been discovered in itsourcecode Online Loan Management System 1.0. The affected element is an unknown function of the file /manage_user.php. Performing manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be exploited.

[CVE-2025-12611] [Modified: 05-11-2025] [Analyzed] [V3.1 S8.8:HIGH] A vulnerability was identified in Tenda AC21 16.03.08.16. This vulnerability affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument startIp leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

[CVE-2025-12614] [Modified: 05-11-2025] [Analyzed] [V3.1 S4.7:MEDIUM] A weakness has been identified in SourceCodester Best House Rental Management System 1.0. Impacted is the function delete_payment of the file /admin_class.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.

[CVE-2025-12615] [Modified: 10-11-2025] [Analyzed] [V3.1 S5.0:MEDIUM] A security vulnerability has been detected in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /onps/settings.py. Such manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is described as difficult. The exploit has been disclosed publicly and may be used.

[CVE-2025-12618] [Modified: 05-11-2025] [Analyzed] [V3.1 S8.8:HIGH] A vulnerability has been found in Tenda AC8 16.03.34.06. This impacts an unknown function of the file /goform/DatabaseIniSet. The manipulation of the argument Time leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

[CVE-2025-12619] [Modified: 05-11-2025] [Analyzed] [V3.1 S8.8:HIGH] A vulnerability was found in Tenda A15 15.13.07.13. Affected is the function fromSetWirelessRepeat of the file /goform/openNetworkGateway. The manipulation of the argument wpapsk_crypto2_4g results in buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.

[CVE-2025-12622] [Modified: 05-11-2025] [Analyzed] [V3.1 S8.8:HIGH] A vulnerability was determined in Tenda AC10 16.03.10.13. Affected by this vulnerability is the function formSysRunCmd of the file /goform/SysRunCmd. This manipulation of the argument getui causes buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

[CVE-2024-51317] [Modified: 05-11-2025] [Analyzed] [V3.1 S6.5:MEDIUM] An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function

[CVE-2025-29699] [Modified: 05-11-2025] [Analyzed] [V3.1 S6.5:MEDIUM] NetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function.

[CVE-2025-45663] [Modified: 05-11-2025] [Analyzed] [V3.1 S6.5:MEDIUM] An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.

[CVE-2025-63442] [Modified: 05-11-2025] [Analyzed] [V3.1 S4.6:MEDIUM] Simple User Management System with PHP-MySQL v1.0 is vulnerable to Cross-Site Scripting (XSS) via the Profile Section. The system fails to properly sanitize user input, allowing attackers to inject and execute arbitrary JavaScript when the input is displayed in the browser

[CVE-2025-63443] [Modified: 03-02-2026] [Analyzed] [V3.1 S5.4:MEDIUM] School Management System PHP v1.0 is vulnerable to Cross Site Scripting (XSS) in /login.php via the password parameter.

[CVE-2025-11761] [Modified: 21-01-2026] [Analyzed] [V3.1 S7.8:HIGH] A potential security vulnerability has been identified in the HP Client Management Script Library software, which might allow escalation of privilege during the installation process. HP is releasing software updates to mitigate the potential vulnerability.

[CVE-2025-36091] [Modified: 05-11-2025] [Analyzed] [V3.1 S4.3:MEDIUM] IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause dashboards to become inaccessible to legitimate users due to invalid ownership assignment.

[CVE-2025-36092] [Modified: 05-11-2025] [Analyzed] [V3.1 S6.5:MEDIUM] IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause a denial of service due to the improper validation of input length.

[CVE-2025-36093] [Modified: 05-11-2025] [Analyzed] [V3.1 S4.8:MEDIUM] IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an attacker to access unauthorized content or perform unauthorized actions using man in the middle techniques due to improper access controls.