Aggregator
SSRF: Blacklist and Whitelist-Based Input Filters
1 year 10 months ago
SSRF: Blacklist and Whitelist-Based Input Filters
1 year 10 months ago
Persistent XSS Vulnerability on Microsoft Bing’s Video Indexing System
1 year 10 months ago
Android Penetration Testing + Nuclei (Automated Android Pentesting)
1 year 10 months ago
Insecure Webview to Local File Inclusion in Android Pentesting
1 year 10 months ago
[Meachines] [Medium] Cronos DNS 多重解析+子域名查询+SQLI+RCE+TRP00F 自动化权限提升+Crontab计划任务权限提升
1 year 10 months ago
#Cronos DNS 多重解析 #子域名查询 #SQLI #RCE #TRP00F自动化权限提升 #Crontab计划任务权限提升
diff-pdf – 对比 PDF 文档,直观比较两个 PDF 区别[Win/macOS/Linux]
1 year 10 months ago
HomeWindowsdiff-pdf – 对比 PDF 文档,直观比较两个 PDF 区别[Win/macOS/Linux]
CVE-2024-6639 | MDx Plugin up to 2.0.3 on WordPress Shortcode mdx_list_item cross site scripting
1 year 10 months ago
A vulnerability classified as problematic has been found in MDx Plugin up to 2.0.3 on WordPress. This affects the function mdx_list_item of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-6639. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
你喜欢《I Really Want to Stay at Your House》吗?
1 year 10 months ago
你喜欢《I Really Want to Stay at Your House》吗? Matrix 首页推荐 Matrix 是少数派的写作社区,我们主张分享真实的产品体验,有实用价值的经验与思考。我
Уязвимости OpenVPN: от удаленного выполнения кода до захвата системы
1 year 10 months ago
Четыре уязвимости могут поставить под угрозу вашу безопасность.
CVE-2024-5800 | B&R Industrial Automation Automation Runtime up to 6.0.0 SSL/TLS inadequate encryption
1 year 10 months ago
A vulnerability was found in B&R Industrial Automation Automation Runtime up to 6.0.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component SSL/TLS. The manipulation leads to inadequate encryption strength.
This vulnerability is handled as CVE-2024-5800. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6134 | WP-FeedStats wp-cart-for-digital-products Plugin up to 8.5.5 on WordPress cross site scripting
1 year 10 months ago
A vulnerability was found in WP-FeedStats wp-cart-for-digital-products Plugin up to 8.5.5 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-6134. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6692 | smub Easy Digital Downloads Plugin up to 3.3.2 on WordPress Agreement Text cross site scripting
1 year 10 months ago
A vulnerability was found in smub Easy Digital Downloads Plugin up to 3.3.2 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation of the argument Agreement Text leads to cross site scripting.
This vulnerability is traded as CVE-2024-6692. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6691 | smub Easy Digital Downloads Plugin up to 3.3.2 on WordPress currency cross site scripting
1 year 10 months ago
A vulnerability was found in smub Easy Digital Downloads Plugin up to 3.3.2 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation of the argument currency leads to cross site scripting.
The identification of this vulnerability is CVE-2024-6691. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-5801 | B&R Industrial Automation Automation Runtime up to 6.0.1 insecure default initialization of resource
1 year 10 months ago
A vulnerability has been found in B&R Industrial Automation Automation Runtime up to 6.0.1 and classified as critical. This vulnerability affects unknown code. The manipulation leads to insecure default initialization of resource.
This vulnerability was named CVE-2024-5801. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Open-source библиотека ZLUDA прекращает существование
1 year 10 months ago
AMD закрыла проект, оставив разработчиков без ключевого инструмента.
Microsoft Warns of Unpatched Office Vulnerability Leading to Data Breaches
1 year 10 months ago
Vulnerability / Enterprise SecurityMicrosoft has disclosed an unpatched zero-day in Office that, i
Microsoft Warns of Unpatched Office Vulnerability Leading to Data Exposure
1 year 10 months ago
Microsoft has disclosed an unpatched zero-day in Office that, if successfully exploited, could result in unauthorized disclosure of sensitive information to malicious actors.
The vulnerability, tracked as CVE-2024-38200 (CVSS score: 7.5), has been described as a spoofing flaw that affects the following versions of Office -
Microsoft Office 2016 for 32-bit edition and 64-bit editions
Microsoft
The Hacker News
简单清晰地写
1 year 10 months ago
多数人没能力写出简单清晰的作品。