Aggregator
美国政府电话通讯录曝光(24年10月最新版)
10 months 4 weeks ago
美国国务院电话通讯录是一本由美国政府出版的重要工具书,该通讯录中包含组织目录、外交职务主要官员、美国国家办事
F5 的报告:近 30% 面向客户的 API 未受 Https 保护
10 months 4 weeks ago
安全客
CVE-2016-1987 | HP HP-UX IPFilter UDP Packet input validation (ID 185119 / SBV-57676)
10 months 4 weeks ago
A vulnerability has been found in HP HP-UX and classified as problematic. This vulnerability affects unknown code of the component IPFilter. The manipulation as part of UDP Packet leads to improper input validation.
This vulnerability was named CVE-2016-1987. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
5 критических багов: GitLab теряет контроль над безопасностью
10 months 4 weeks ago
Запуск пайплайнов теперь сопряжён с неожиданными рисками.
AI Cleanup: как Wikipedia противостоит засилию ИИ-контента
10 months 4 weeks ago
Редакторы рассказывают о своем опыте ожесточенной борьбы с фейками.
Coinbase 进行重大升级,用户现在可以向 Taproot 地址发送比特币
10 months 4 weeks ago
安全客
开源身份和访问管理平台 Keycloak 发布了安全更新以解决一个高严重性漏洞
10 months 4 weeks ago
安全客
美国证券交易委员会与贸易公司达成和解,称其利用人工智能“流行语”欺骗投资者
10 months 4 weeks ago
安全客
CVE-2016-2016 | Base-VxFS/VxFS ACL Inheritance access control (ID 185123 / ID 1035816)
10 months 4 weeks ago
A vulnerability was found in Base-VxFS and VxFS. It has been declared as problematic. This vulnerability affects unknown code of the component ACL Inheritance Handler. The manipulation leads to improper access controls.
This vulnerability was named CVE-2016-2016. Attacking locally is a requirement. There is no exploit available.
vuldb.com
AsyncRAT 恶意软件活动利用 Bitbucket 发起多阶段攻击
10 months 4 weeks ago
安全客
Progress 修补 Telerik 报告服务器中的重大安全漏洞 CVE-2024-8015 (CVSS 9.1)
10 months 4 weeks ago
安全客
CVE-2024-41713 (CVSS 9.8): 未修补的 MiCollab 漏洞允许未经授权的访问
10 months 4 weeks ago
安全客
Zyxel 设备遭恶意攻击: 需要紧急固件更新
10 months 4 weeks ago
安全客
Palo Alto Expedition 中的 CVE-2024-9465 (CVSS 9.2) SQLi 漏洞曝光: 发布完整漏洞利用和 PoC
10 months 4 weeks ago
安全客
Veeam曝出关键漏洞,勒索团伙趁火打劫利用RCE攻击全球企业
10 months 4 weeks ago
主站 分类 漏洞 工具 极客
伊朗黑客使用ChatGPT策划ICS攻击
10 months 4 weeks ago
据OPENAI本月最新发布的报告《Influence and cyber operations: an update》,伊朗黑客组织CyberAv3ngers利用人工智能模型ChatGPT策划针对工业
诺贝尔和平奖授予日本核爆受害者团体
10 months 4 weeks ago
2024 年诺贝尔和平奖授予了日本原子弹氢弹爆炸受害者团体协议会(简称被团协)。被团协由
广岛、长崎核爆幸存者组成,因其为实现无核世界所做的努力以及通过证人证词表明绝不能再次使用核武器而获得和平奖。挪威诺贝尔委员会希望借此承认一个事实:核武器在接近 80 年里没有在战争中使用过。日本被团协等组织为核禁忌的建立做出了巨大贡献。但令人担忧的是今天反对使用核武器的禁忌正面临压力。核大国正对其核武库进行现代化和升级;新兴国家似乎正准备获取核武器;当前正发生的战争出现了使用核武器的威胁。在人类历史的这一时刻,我们需要提醒自己核武器是什么:它们是世界上迄今为止最具破坏性的武器。
CVE-2024-9817 | code-projects Blood Bank System 1.0 /update.php name sql injection
10 months 4 weeks ago
A vulnerability was found in code-projects Blood Bank System 1.0. It has been classified as critical. This affects an unknown part of the file /update.php. The manipulation of the argument name leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-9817. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-9818 | SourceCodester Online Veterinary Appointment System 1.0 manage_category.php id sql injection
10 months 4 weeks ago
A vulnerability classified as critical has been found in SourceCodester Online Veterinary Appointment System 1.0. Affected is an unknown function of the file /admin/categories/manage_category.php. The manipulation of the argument id leads to sql injection.
This vulnerability is traded as CVE-2024-9818. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com