Aggregator
.NET 安全攻防知识交流社区
9 months ago
从.NET审计视角剖析 IDOR,发现高危的越权漏洞
9 months ago
CVE-2024-38601 | Linux Kernel up to 6.9.2 ring_buffer.c rb_get_reader_page buffer overflow (Nessus ID 207776)
9 months ago
A vulnerability has been found in Linux Kernel up to 6.9.2 and classified as critical. This affects the function rb_get_reader_page of the file kernel/trace/ring_buffer.c. The manipulation leads to buffer overflow.
This vulnerability is referenced as CVE-2024-38601. The attack needs to be initiated within the local network. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2025-43750 | Liferay Portal/DXP Attachment Field unrestricted upload
9 months ago
A vulnerability has been found in Liferay Portal and DXP and classified as critical. This vulnerability affects unknown code of the component Attachment Field Handler. This manipulation causes unrestricted upload.
This vulnerability is registered as CVE-2025-43750. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2025-10603 | PHPGurukul Online Discussion Forum 1.0 search_result.php Search sql injection
9 months ago
A vulnerability was found in PHPGurukul Online Discussion Forum 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/admin_forum/search_result.php. Executing manipulation of the argument Search can lead to sql injection.
This vulnerability is tracked as CVE-2025-10603. The attack can be launched remotely. Moreover, an exploit is present.
vuldb.com
CVE-2025-58432 | IceWhaleTech ZimaOS up to 1.4.1 uploadV2 unnecessary privileges (GHSA-3gp9-43rg-xrcc)
9 months ago
A vulnerability was found in IceWhaleTech ZimaOS up to 1.4.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /v2_1/files/file/uploadV2. Performing manipulation results in execution with unnecessary privileges.
This vulnerability is known as CVE-2025-58432. Attacking locally is a requirement. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-59341 | esm-dev esm.sh up to 136 URL path traversal (GHSA-49pv-gwxp-532r)
9 months ago
A vulnerability identified as problematic has been detected in esm-dev esm.sh up to 136. This vulnerability affects unknown code of the component URL Handler. The manipulation leads to relative path traversal.
This vulnerability is uniquely identified as CVE-2025-59341. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2025-58431 | IceWhaleTech ZimaOS up to 1.4.1 download unnecessary privileges (GHSA-vqrw-9v9m-6g87)
9 months ago
A vulnerability labeled as critical has been found in IceWhaleTech ZimaOS up to 1.4.1. This issue affects some unknown processing of the file /v2_1/files/file/download. The manipulation results in execution with unnecessary privileges.
This vulnerability was named CVE-2025-58431. The attack needs to be approached locally. There is no available exploit.
vuldb.com
CVE-2025-10605 | Portabilis i-Educar up to 2.10 /agenda_preferencias.php tipoacao cross site scripting
9 months ago
A vulnerability was found in Portabilis i-Educar up to 2.10. It has been declared as problematic. This vulnerability affects unknown code of the file /agenda_preferencias.php. The manipulation of the argument tipoacao results in cross site scripting.
This vulnerability is cataloged as CVE-2025-10605. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-10606 | Portabilis i-Educar up to 2.10 ConfiguracaoMovimentoGeral tipoacao cross site scripting
9 months ago
A vulnerability was found in Portabilis i-Educar up to 2.10. It has been rated as problematic. This issue affects some unknown processing of the file /module/Configuracao/ConfiguracaoMovimentoGeral. This manipulation of the argument tipoacao causes cross site scripting.
This vulnerability is registered as CVE-2025-10606. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
vuldb.com
CVE-2025-10608 | Portabilis i-Educar up to 2.10 /enrollment-history/ access control
9 months ago
A vulnerability identified as critical has been detected in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /enrollment-history/. Performing manipulation results in improper access controls.
This vulnerability is reported as CVE-2025-10608. The attack is possible to be carried out remotely. Moreover, an exploit is present.
vuldb.com
CVE-2025-10607 | Portabilis i-Educar up to 2.10 diarioApi information disclosure
9 months ago
A vulnerability categorized as problematic has been discovered in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Avaliacao/diarioApi. Such manipulation leads to information disclosure.
This vulnerability is documented as CVE-2025-10607. The attack can be executed remotely. Additionally, an exploit exists.
vuldb.com
Play
9 months ago
You must login to view this content
cohenido
派早报:TikTok 美国业务将出售、Google 推出 Windows 版搜索应用等
9 months ago
甲骨文等财团计划收购TikTok美国业务;Google推出Windows桌面搜索应用;Comet浏览器集成1Password密码管理功能;AMD发布EPYC嵌入式4005系列处理器。
CVE-2023-21506 | Samsung Blockchain Keystore prior 1.3.12.1 BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY out-of-bounds write (EUVD-2023-25674)
9 months ago
A vulnerability classified as critical was found in Samsung Blockchain Keystore. This affects the function BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY. Such manipulation leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2023-21506. Local access is required to approach this attack. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2023-21504 | Samsung Smart Phone Shannon Baseband mm_Plmncoordination.c buffer overflow (EUVD-2023-25672)
9 months ago
A vulnerability classified as critical has been found in Samsung Smart Phone. This issue affects some unknown processing of the file mm_Plmncoordination.c of the component Shannon Baseband. Performing manipulation results in buffer overflow.
This vulnerability is known as CVE-2023-21504. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-21505 | Samsung Core Service prior 2.1.00.36 improper authorization (EUVD-2023-25673)
9 months ago
A vulnerability was found in Samsung Core Service. It has been classified as critical. Affected is an unknown function. Performing manipulation results in improper authorization.
This vulnerability is identified as CVE-2023-21505. The attack is only possible with local access. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2023-21503 | Samsung Smart Phone Shannon Baseband mm_LteInterRatManagement.c buffer overflow (EUVD-2023-25671)
9 months ago
A vulnerability described as critical has been identified in Samsung Smart Phone. This vulnerability affects unknown code of the file mm_LteInterRatManagement.c of the component Shannon Baseband. Such manipulation leads to buffer overflow.
This vulnerability is traded as CVE-2023-21503. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2023-21502 | Samsung Smart Phone FactoryTest Application input validation (EUVD-2023-25670)
9 months ago
A vulnerability marked as problematic has been reported in Samsung Smart Phone. This affects an unknown function of the component FactoryTest Application. The manipulation leads to improper input validation.
This vulnerability is documented as CVE-2023-21502. It is possible to launch the attack on the physical device. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com