Aggregator
CVE-2024-43788 | Webpack up to 5.93.x cross site scripting (GHSA-4vvj-4cpr-p986 / Nessus ID 209968)
1 year 7 months ago
A vulnerability has been found in Webpack up to 5.93.x and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-43788. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-39338 | axios 1.7.2 Relative URL server-side request forgery (Nessus ID 209968)
1 year 7 months ago
A vulnerability was found in axios 1.7.2 and classified as critical. Affected by this issue is some unknown functionality of the component Relative URL Handler. The manipulation leads to server-side request forgery.
This vulnerability is handled as CVE-2024-39338. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-38998 | jrburke requirejs 2.3.6 config prototype pollution (Nessus ID 209968)
1 year 7 months ago
A vulnerability was found in jrburke requirejs 2.3.6. It has been classified as problematic. This affects the function config. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution').
This vulnerability is uniquely identified as CVE-2024-38998. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2024-38355 | socket.io up to 2.5.0/4.6.1 denial of service (GHSA-25hc-qcg6-38wj / Nessus ID 209968)
1 year 7 months ago
A vulnerability was found in socket.io up to 2.5.0/4.6.1. It has been classified as problematic. This affects an unknown part. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2024-38355. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50382 | randombit Botan up to 3.5.x ghash.cpp control flow (Nessus ID 209976)
1 year 7 months ago
A vulnerability was found in randombit Botan up to 3.5.x. It has been classified as problematic. Affected is an unknown function in the library lib/utils/ghash/ghash.cpp. The manipulation leads to incorrect control flow.
This vulnerability is traded as CVE-2024-50382. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50383 | randombit Botan up to 3.5.x donna128 lib/utils/donna128.h information exposure (Nessus ID 209976)
1 year 7 months ago
A vulnerability was found in randombit Botan up to 3.5.x. It has been declared as problematic. Affected by this vulnerability is an unknown functionality in the library lib/utils/donna128.h of the component donna128. The manipulation leads to information exposure through discrepancy.
This vulnerability is known as CVE-2024-50383. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-0727 | OpenSSL 3.0/3.1 ContentInfo null pointer dereference (Nessus ID 209978)
1 year 7 months ago
A vulnerability, which was classified as problematic, was found in OpenSSL 3.0/3.1. Affected is an unknown function. The manipulation of the argument ContentInfo leads to null pointer dereference.
This vulnerability is traded as CVE-2024-0727. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
ATPC网络论坛将重点关注下一代网络安全和人工智能问题
1 year 7 months ago
安全客
Пятилетняя осада: что ищет Китай в госсетях Канады?
1 year 7 months ago
Китай, Индия и Иран несколько лет испытывают киберзащиту страны на прочность.
CVE-2024-10544 | Woo Manage Fraud Orders Plugin up to 6.1.7 on WordPress Log File information disclosure
1 year 7 months ago
A vulnerability was found in Woo Manage Fraud Orders Plugin up to 6.1.7 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Log File Handler. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2024-10544. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-10556 | Codezips Pet Shop Management System 1.0 birdsadd.php id sql injection
1 year 7 months ago
A vulnerability, which was classified as critical, was found in Codezips Pet Shop Management System 1.0. Affected is an unknown function of the file birdsadd.php. The manipulation of the argument id leads to sql injection.
This vulnerability is traded as CVE-2024-10556. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10561 | Codezips Pet Shop Management System 1.0 birdsupdate.php id sql injection
1 year 7 months ago
A vulnerability was found in Codezips Pet Shop Management System 1.0. It has been classified as critical. This affects an unknown part of the file birdsupdate.php. The manipulation of the argument id leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-10561. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
能伪造通话界面,FakeCall恶意软件变种在安卓手机中传播
1 year 7 months ago
主站 分类 漏洞 工具 极客
PyTorch库RPC框架反序列化RCE漏洞(CVE-2024-48063)
1 year 7 months ago
PyTorch库RPC框架反序列化RCE漏洞(CVE-2024-48063)
BUET CTF 2024
1 year 7 months ago
Name: BUET CTF 2024 (an BUET CTF event.)
Date: Oct. 31, 2024, 3 a.m. — 31 Oct. 2024, 09:00 UTC [add to calendar]
Format: Jeopardy
On-site
Location: Bangladesh, Dhaka
Offical URL: http://ctf.buetcsefest2024.com/
Rating weight: 0.00
Event organizers: BUETSec
Date: Oct. 31, 2024, 3 a.m. — 31 Oct. 2024, 09:00 UTC [add to calendar]
Format: Jeopardy
On-site
Location: Bangladesh, Dhaka
Offical URL: http://ctf.buetcsefest2024.com/
Rating weight: 0.00
Event organizers: BUETSec
Cynet delivers 426% ROI in Forrester Total Economic Impact Study
1 year 7 months ago
A commissioned study conducted by Forrester Consulting on behalf of Cynet in October 2024 found that Cynet's All-in-One Cybersecurity Platform generated $2.73 million in savings, paying for itself in under six months, for a return on investment of 426%. [...]
Sponsored by Cynet
Цифровое бессмертие: может ли ИИ сохранить образ ушедших близких?
1 year 7 months ago
Испанское ТВ всколыхнуло этические дебаты.
黑客使用 Microsoft、AWS 诱饵对关键部门进行网络钓鱼
1 year 7 months ago
安全客
CVE-2017-2458 | Apple iOS up to 10.2 Keyboards memory corruption (HT207617 / Nessus ID 99264)
1 year 7 months ago
A vulnerability, which was classified as critical, has been found in Apple iOS up to 10.2. This issue affects some unknown processing of the component Keyboards. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2017-2458. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com