CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

Description: [AI generated] WNY Energy is an energy company based in Western New York, USA. It operates a 115 million gallon per year ethanol plant that produces clean-burning, renewable fuel and various byproducts including CO2 and wet and dry distillers grain that are used in food and feed products. The company focuses on innovative technology and practices for transforming local corn into efficient, sustainable biofuels.
Source: Ransomware.live
May 15th, 2025 (about 1 month ago)
Description: [AI generated] Azpiaran is a family-owned company based in Poland that specializes in the production of high-quality Spanish and Polish meat products. It integrates traditional recipes with modern processing, ensuring the highest standards. The company offers a broad range of products including various hams, sausages, loin, chorizo, and more.
Source: Ransomware.live
May 15th, 2025 (about 1 month ago)

CVE-2024-25419

Description: flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_menu.php.

EPSS Score: 0.14%

SSVC Exploitation: poc

Source: CVE
May 15th, 2025 (about 1 month ago)

CVE-2024-25418

Description: flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_menu.php.

EPSS Score: 0.15%

SSVC Exploitation: poc

Source: CVE
May 15th, 2025 (about 1 month ago)

CVE-2024-25315

Description: Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'rid' parameter in Hotel/admin/roombook.php?rid=2.

EPSS Score: 0.13%

SSVC Exploitation: poc

Source: CVE
May 15th, 2025 (about 1 month ago)

CVE-2024-25305

Description: Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/index.php.

EPSS Score: 0.05%

SSVC Exploitation: poc

Source: CVE
May 15th, 2025 (about 1 month ago)

CVE-2024-25004

Description: KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insufficient bounds checking and input sanitization (at line 2600). This allows an attacker to overwrite adjacent memory, which leads to arbitrary code execution.

EPSS Score: 0.45%

SSVC Exploitation: poc

Source: CVE
May 15th, 2025 (about 1 month ago)

CVE-2024-24495

Description: SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via crafted GET request.

EPSS Score: 0.19%

SSVC Exploitation: poc

Source: CVE
May 15th, 2025 (about 1 month ago)

CVE-2024-24398

Description: Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function.

EPSS Score: 26.53%

SSVC Exploitation: poc

Source: CVE
May 15th, 2025 (about 1 month ago)

CVE-2024-24397

Description: Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the ReportName field.

EPSS Score: 0.99%

SSVC Exploitation: poc

Source: CVE
May 15th, 2025 (about 1 month ago)