Copyparty 1.18.6 – Reflected Cross-Site Scripting (XSS)

/* * Author : Byte Reaper * CVE : CVE-2025-54589 * Title : Copyparty 1.18.6 – Reflected Cross-Site Scripting (XSS) * CVE-2025-54589 is a reflected cross-site scripting (XSS) vulnerability in Copyparty (≤ 1.18.6) where the filter parameter is inserted into the HTML response without proper sanitization, allowing an attacker to inject and execute arbitrary JavaScript…

Read More

Microsoft Edge (Chromium-based) 135.0.7049.114/.115 – Information Disclosure

# Titles: Microsoft Edge (Chromium-based) 135.0.7049.114/.115 – Information Disclosure # Date: 08/02/2025 # Vendor: Microsoft # Software: https://www.microsoft.com/bg-bg/edge/download?form=MA13FJ # Reference: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-49741 ## Description # CVE-2025-49741 Exploit Server **Author:** nu11secur1ty (2025) ## Overview This Python script simulates an exploit targeting a Microsoft Edge (Chromium-based) information disclosure vulnerability identified as **CVE-2025-49741**. It runs…

Read More

Astronomers detect life’s building blocks around a young star

Using the Atacama Large Millimeter/submillimeter Array (ALMA), a team of astronomers led by Abubakar Fadul from the Max Planck Institute for Astronomy (MPIA) has discovered complex organic molecules – including the first tentative detection of ethylene glycol and glycolonitrile – in the protoplanetary disc of the outbursting protostar V883 Orionis. These compounds are considered precursors…

Read More

Client Challenge

Client Challenge JavaScript is disabled in your browser. Please enable JavaScript to proceed. A required part of this site couldn’t load. This may be due to a browser extension, network issues, or browser settings. Please check your connection, disable any ad blockers, or try using a different browser. Source link

Read More

Gandia Integra Total 4.4.2236.1 – SQL Injection

/* * Author : Byte Reaper * CVE : CVE-2025-41373 * Vulnerability : SQL * Affected Path : /encuestas/integraweb_v4/integra/html/view/hislistadoacciones.php?idestudio= * Affected Versions : 2.1.2217.3 to v4.4.2236.1 * Description: * This endpoint concatenates the `idestudio` parameter directly into an SQL query * without proper sanitization or parameterization, allowing an attacker to inject * arbitrary SQL….

Read More