Aggregator
libFuzzer模糊测试引擎调研与自定义开发
5 months 2 weeks ago
看雪论坛作者ID:Loserme
SDC2024议题聚焦 | ExpAttack大语言模型越狱风险持续追踪框架(内含赠票)
5 months 2 weeks ago
大语言模型Prompt越狱的自动化攻防
宵明CSPM:助力跨国企业解锁云上安全新技能
5 months 2 weeks ago
管理云上安全态势
CVE-2024-49244 | cmssoft CSV Product Import Export for WooCommerce Plugin up to 1.0.0 on WordPress sql injection
5 months 2 weeks ago
A vulnerability was found in cmssoft CSV Product Import Export for WooCommerce Plugin up to 1.0.0 on WordPress. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2024-49244. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-48633 | D-Link DIR-878/DIR-882 POST SetVirtualServerSettings command injection
5 months 2 weeks ago
A vulnerability was found in D-Link DIR-878 and DIR-882. It has been declared as critical. Affected by this vulnerability is the function SetVirtualServerSettings of the component POST Handler. The manipulation of the argument ExternalPort/InternalPort/ProtocolNumber/LocalIPAddress leads to command injection.
This vulnerability is known as CVE-2024-48633. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-48632 | D-Link DIR-878/DIR-882 FW130 POST SetPortForwardingSettings LocalIPAddress/TCPPorts/UDPPorts command injection
5 months 2 weeks ago
A vulnerability was found in D-Link DIR-878 and DIR-882 FW130. It has been classified as critical. Affected is the function SetPortForwardingSettings of the component POST Handler. The manipulation of the argument LocalIPAddress/TCPPorts/UDPPorts leads to command injection.
This vulnerability is traded as CVE-2024-48632. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-49246 | anand23 Ajax Rating with Custom Login Plugin up to 1.1 on WordPress sql injection
5 months 2 weeks ago
A vulnerability was found in anand23 Ajax Rating with Custom Login Plugin up to 1.1 on WordPress and classified as critical. This issue affects some unknown processing. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2024-49246. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-49297 | Zoho CRM Lead Magnet Plugin up to 1.7.9.0 on WordPress sql injection
5 months 2 weeks ago
A vulnerability has been found in Zoho CRM Lead Magnet Plugin up to 1.7.9.0 on WordPress and classified as critical. This vulnerability affects unknown code. The manipulation leads to sql injection.
This vulnerability was named CVE-2024-49297. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-47312 | WPGrim Classic Editor and Classic Widgets Plugin up to 1.4.1 on WordPress sql injection
5 months 2 weeks ago
A vulnerability, which was classified as critical, was found in WPGrim Classic Editor and Classic Widgets Plugin up to 1.4.1 on WordPress. This affects an unknown part. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-47312. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-47304 | WPManageNinja Fluent Support Plugin up to 1.8.0 on WordPress sql injection
5 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in WPManageNinja Fluent Support Plugin up to 1.8.0 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2024-47304. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-48638 | D-Link DIR-822/DIR-878 FW130 POST SetGuestZoneRouterSettings SubnetMask command injection
5 months 2 weeks ago
A vulnerability classified as critical was found in D-Link DIR-822 and DIR-878 FW130. Affected by this vulnerability is the function SetGuestZoneRouterSettings of the component POST Handler. The manipulation of the argument SubnetMask leads to command injection.
This vulnerability is known as CVE-2024-48638. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-48637 | D-Link DIR-822/DIR-878 FW130 POST SetVLANSettings VID command injection
5 months 2 weeks ago
A vulnerability classified as critical has been found in D-Link DIR-822 and DIR-878 FW130. Affected is the function SetVLANSettings of the component POST Handler. The manipulation of the argument VID leads to command injection.
This vulnerability is traded as CVE-2024-48637. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-48636 | D-Link DIR-822/DIR-878 FW130 POST SetVLANSettings VID command injection
5 months 2 weeks ago
A vulnerability was found in D-Link DIR-822 and DIR-878 FW130. It has been rated as critical. This issue affects the function SetVLANSettings of the component POST Handler. The manipulation of the argument VID leads to command injection.
The identification of this vulnerability is CVE-2024-48636. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-48635 | D-Link DIR-822/DIR-878 FW130 POST SetVLANSettings VID command injection
5 months 2 weeks ago
A vulnerability was found in D-Link DIR-822 and DIR-878 FW130. It has been declared as critical. This vulnerability affects the function SetVLANSettings of the component POST Handler. The manipulation of the argument VID leads to command injection.
This vulnerability was named CVE-2024-48635. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-48634 | D-Link DIR-822/DIR-878 FW130 POST SetWLanRadioSecurity key command injection
5 months 2 weeks ago
A vulnerability was found in D-Link DIR-822 and DIR-878 FW130. It has been classified as critical. This affects the function SetWLanRadioSecurity of the component POST Handler. The manipulation of the argument key leads to command injection.
This vulnerability is uniquely identified as CVE-2024-48634. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-48631 | D-Link DIR-822/DIR-878 FW130 POST SetWLanRadioSettings SSID command injection
5 months 2 weeks ago
A vulnerability was found in D-Link DIR-822 and DIR-878 FW130 and classified as critical. Affected by this issue is the function SetWLanRadioSettings of the component POST Handler. The manipulation of the argument SSID leads to command injection.
This vulnerability is handled as CVE-2024-48631. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-48630 | D-Link DIR-822/DIR-878 FW130 POST SetMACFilters2 MacAddress command injection
5 months 2 weeks ago
A vulnerability has been found in D-Link DIR-822 and DIR-878 FW130 and classified as critical. Affected by this vulnerability is the function SetMACFilters2 of the component POST Handler. The manipulation of the argument MacAddress leads to command injection.
This vulnerability is known as CVE-2024-48630. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-48629 | D-Link DIR-822/DIR-878 FW130 POST SetGuestZoneRouterSettings IPAddress command injection
5 months 2 weeks ago
A vulnerability, which was classified as critical, was found in D-Link DIR-822 and DIR-878 FW130. Affected is the function SetGuestZoneRouterSettings of the component POST Handler. The manipulation of the argument IPAddress leads to command injection.
This vulnerability is traded as CVE-2024-48629. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-49285 | Moridrin SSV MailChimp Plugin up to 3.1.5 on WordPress path traversal
5 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in Moridrin SSV MailChimp Plugin up to 3.1.5 on WordPress. This issue affects some unknown processing. The manipulation leads to path traversal.
The identification of this vulnerability is CVE-2024-49285. The attack may be initiated remotely. There is no exploit available.
vuldb.com