Aggregator
在 Laravel 流行的全栈框架 Livewire 中发现新漏洞 CVE-2024-47823
1 year 5 months ago
安全客
在 Windows 版 Apache Subversion 中发现代码执行漏洞(CVE-2024-45720)
1 year 5 months ago
安全客
「推安早报」1010 | 近期漏洞、红蓝工具
1 year 5 months ago
涵盖CUPS打印系统、恶意软件虚拟化、Exchange PowerShell等多领域漏洞,以及Active Directory检测、Zimbra邮件平台远程命令执行等关键威胁
Миллионы вакансий и тысячи безработных: темная сторона индустрии ИБ
1 year 5 months ago
Почему поиск работы становится невыполнимой миссией?
CVE-2024-38348 | CodeProjects Health Care Hospital Management System 1.0 Staff Info Module searvalu sql injection
1 year 5 months ago
A vulnerability classified as critical was found in CodeProjects Health Care Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the component Staff Info Module. The manipulation of the argument searvalu leads to sql injection.
This vulnerability is known as CVE-2024-38348. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-9021 | Relevanssi Plugin up to 4.23.0 on WordPress cross site scripting
1 year 5 months ago
A vulnerability was found in Relevanssi Plugin up to 4.23.0 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-9021. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8983 | Custom Twitter Feeds Plugin up to 2.2.2 on WordPress Setting cross site scripting
1 year 5 months ago
A vulnerability classified as problematic was found in Custom Twitter Feeds Plugin up to 2.2.2 on WordPress. Affected by this vulnerability is an unknown functionality of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-8983. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47823 | Livewire up to 3.5.1 getClientOriginalName unrestricted upload (GHSA-f3cx-396f-7jqp)
1 year 5 months ago
A vulnerability, which was classified as critical, has been found in Livewire up to 3.5.1. This issue affects the function getClientOriginalName. The manipulation leads to unrestricted upload.
The identification of this vulnerability is CVE-2024-47823. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9568 | D-Link DIR-619L B1 2.06 /goform/formAdvNetwork curTime buffer overflow
1 year 5 months ago
A vulnerability, which was classified as critical, was found in D-Link DIR-619L B1 2.06. Affected is the function formAdvNetwork of the file /goform/formAdvNetwork. The manipulation of the argument curTime leads to buffer overflow. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is traded as CVE-2024-9568. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-9569 | D-Link DIR-619L B1 2.06 formEasySetPassword curTime buffer overflow
1 year 5 months ago
A vulnerability has been found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this vulnerability is the function formEasySetPassword of the file /goform/formEasySetPassword. The manipulation of the argument curTime leads to buffer overflow. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is known as CVE-2024-9569. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Palo Alto Networks 的 GlobalProtect MSI 安装程序存在本地权限提升漏洞
1 year 5 months ago
安全客
Без связи и навигации: Земля на пути мощного геомагнитного шторма
1 year 5 months ago
Солнце решило проверить на прочность нашу планету, атаковав сразу несколькими способами.
Internet Archive Breached, 31 Million Records Exposed
1 year 5 months ago
The non-profit digital library was also hit by at least two DDoS attacks in two days
U.S. CISA adds Ivanti CSA and Fortinet bugs to its Known Exploited Vulnerabilities catalog
1 year 5 months ago
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Ivanti CSA and Fortinet bugs to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: This week, Fortinet addressed a critical flaw in FortiOS, tracked as CVE-2024-23113 (CVSS score 9.8). The issue if […]
Pierluigi Paganini
CVE-2014-7546 | Buddhist Prayer 3 X.509 Certificate cryptographic issues (VU#582497)
1 year 5 months ago
A vulnerability was found in Buddhist Prayer 3. It has been classified as critical. This affects an unknown part of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is uniquely identified as CVE-2014-7546. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
Смартфон толщиной с кредитку: новые батареи для сверхлегких гаджетов и электромобилей
1 year 5 months ago
Исследователи представили новый аккумулятор из углеродного волокна.
CVE-2024-48902 | JetBrains YouTrack up to 2024.3.44799 Project Update authorization
1 year 5 months ago
A vulnerability was found in JetBrains YouTrack. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Project Update Handler. The manipulation leads to missing authorization.
This vulnerability is handled as CVE-2024-48902. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45149 | Adobe Commerce up to 2.4.7-p2/2.4.6-p7/2.4.5-p9/2.4.4-p10 access control (apsb24-73)
1 year 5 months ago
A vulnerability was found in Adobe Commerce up to 2.4.7-p2/2.4.6-p7/2.4.5-p9/2.4.4-p10. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2024-45149. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45148 | Adobe Commerce up to 2.4.7-p2/2.4.6-p7/2.4.5-p9/2.4.4-p10 improper authentication (apsb24-73)
1 year 5 months ago
A vulnerability was found in Adobe Commerce up to 2.4.7-p2/2.4.6-p7/2.4.5-p9/2.4.4-p10. It has been classified as critical. Affected is an unknown function. The manipulation leads to improper authentication.
This vulnerability is traded as CVE-2024-45148. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com