Aggregator
CVE-2024-34158 | Google Go up to 1.22.6/1.23.0 go-build-constraint resource consumption
5 months ago
A vulnerability classified as problematic has been found in Google Go up to 1.22.6/1.23.0. Affected is an unknown function of the component go-build-constraint. The manipulation leads to resource consumption.
This vulnerability is traded as CVE-2024-34158. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8523 | lmxcms up to 1.4 SQL Command Execution Module admin.php formatData data code injection
5 months ago
A vulnerability was found in lmxcms up to 1.4 and classified as critical. Affected by this issue is the function formatData of the file /admin.php?m=Acquisi&a=testcj&lid=1 of the component SQL Command Execution Module. The manipulation of the argument data leads to code injection.
This vulnerability is handled as CVE-2024-8523. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2024-45034 | Apache Airflow up to 2.10.0 DAG Folder unnecessary privileges
5 months ago
A vulnerability was found in Apache Airflow up to 2.10.0 and classified as critical. Affected by this issue is some unknown functionality of the component DAG Folder Handler. The manipulation leads to execution with unnecessary privileges.
This vulnerability is handled as CVE-2024-45034. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-7652 | Mozilla Thunderbird ECMA-262 type confusion
5 months ago
A vulnerability was found in Mozilla Thunderbird. It has been declared as critical. This vulnerability affects unknown code of the component ECMA-262 Handler. The manipulation leads to type confusion.
This vulnerability was named CVE-2024-7652. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8538 | Big File Uploads Plugin up to 2.1.2 on WordPress information disclosure
5 months ago
A vulnerability has been found in Big File Uploads Plugin up to 2.1.2 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to information disclosure.
This vulnerability was named CVE-2024-8538. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-6849 | Preloader Plus Plugin up to 2.2.1 on WordPress SVG File Upload cross site scripting
5 months ago
A vulnerability was found in Preloader Plus Plugin up to 2.2.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component SVG File Upload Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-6849. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-8521 | Wavelog up to 1.8.0 Live QSO /qso index manual cross site scripting
5 months ago
A vulnerability, which was classified as problematic, was found in Wavelog up to 1.8.0. Affected is the function index of the file /qso of the component Live QSO. The manipulation of the argument manual leads to cross site scripting.
This vulnerability is traded as CVE-2024-8521. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
idekCTF 2024 Writeup - Advanced iframe Magic
5 months ago
In idekCTF 2024, there was an interesting problem called srcdoc-memos from @icesfont,
idekCTF 2024 筆記之 iframe 高級魔法
5 months ago
在 idekCTF 2024 中,由 icesfont 所出的一道題目 srcdoc-memos 十分有趣,牽涉到了許多 iframe 的相關知識。我沒有實際參加比賽,但賽
CVE-2024-8317 | WP AdCenter Plugin up to 2.5.6 on WordPress ad_alignment cross site scripting
5 months ago
A vulnerability was found in WP AdCenter Plugin up to 2.5.6 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument ad_alignment leads to cross site scripting.
This vulnerability is handled as CVE-2024-8317. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-8427 | Frontend Post Submission Manager Lite Plugin up to 1.2.2 on WordPress Setting authorization
5 months ago
A vulnerability was found in Frontend Post Submission Manager Lite Plugin up to 1.2.2 on WordPress. It has been classified as problematic. This affects an unknown part of the component Setting Handler. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2024-8427. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-7493 | WPCOM Member Plugin up to 1.5.2.1 on WordPress User Meta privileges management
5 months ago
A vulnerability, which was classified as critical, has been found in WPCOM Member Plugin up to 1.5.2.1 on WordPress. This issue affects some unknown processing of the component User Meta Handler. The manipulation leads to improper privilege management.
The identification of this vulnerability is CVE-2024-7493. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2024-7611 | Enter Addons Plugin up to 2.1.8 on WordPress Events Card Widget cross site scripting
5 months ago
A vulnerability was found in Enter Addons Plugin up to 2.1.8 on WordPress. It has been classified as problematic. This affects an unknown part of the component Events Card Widget. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-7611. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-7599 | Advanced Sermons Plugin up to 3.3 on WordPress cross site scripting
5 months ago
A vulnerability was found in Advanced Sermons Plugin up to 3.3 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-7599. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-44739 | SourceCodester Simple Forum Website 1.0 id sql injection
5 months ago
A vulnerability has been found in SourceCodester Simple Forum Website 1.0 and classified as critical. This vulnerability affects unknown code of the file /php-sqlite-forum/?page=manage_user. The manipulation of the argument id leads to sql injection.
This vulnerability was named CVE-2024-44739. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-44401 | D-Link DI-8100G 17.12.20A1 upgrade_filter.asp sub47A60C command injection
5 months ago
A vulnerability classified as critical was found in D-Link DI-8100G 17.12.20A1. Affected by this vulnerability is the function sub47A60C of the file upgrade_filter.asp. The manipulation leads to command injection.
This vulnerability is known as CVE-2024-44401. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-44408 | D-Link DIR-823G 1.0.2B05_20181207 Configuration File information disclosure
5 months ago
A vulnerability, which was classified as problematic, was found in D-Link DIR-823G 1.0.2B05_20181207. Affected is an unknown function of the component Configuration File Handler. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-44408. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2024-44402 | D-Link DI-8100G 17.12.20A1 msp_info.htm command injection
5 months ago
A vulnerability, which was classified as critical, was found in D-Link DI-8100G 17.12.20A1. Affected is an unknown function of the file msp_info.htm. The manipulation leads to command injection.
This vulnerability is traded as CVE-2024-44402. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
Meow
5 months ago
cohenido