Aggregator
.NET 安全攻防知识交流社区
3 months ago
.NET内网实战:通过系统白名单文件 Fodhelper.exe 绕过 UAC 实现提权
3 months ago
新型RL窃密木马样本分析
3 months ago
新型RL窃密木马样本分析
Deep Java Library (DJL) CVE-2025-0851 漏洞复现与深度剖析
3 months ago
Java开发者注意!DJL框架中的一个漏洞可能让你的服务器面临被攻击的风险!
Deep Java Library (DJL) CVE-2025-0851 漏洞复现与深度剖析
3 months ago
Java开发者注意!DJL框架中的一个漏洞可能让你的服务器面临被攻击的风险!
Deep Java Library (DJL) CVE-2025-0851 漏洞复现与深度剖析
3 months ago
Java开发者注意!DJL框架中的一个漏洞可能让你的服务器面临被攻击的风险!
Deep Java Library (DJL) CVE-2025-0851 漏洞复现与深度剖析
3 months ago
Java开发者注意!DJL框架中的一个漏洞可能让你的服务器面临被攻击的风险!
CVE-2000-0139 | True North Internet Anywhere Mail Server 3.1.3 RETR Command denial of service (EDB-19748 / XFDB-3988)
3 months ago
A vulnerability was found in True North Internet Anywhere Mail Server 3.1.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component RETR Command Handler. The manipulation leads to denial of service.
This vulnerability is known as CVE-2000-0139. Local access is required to approach this attack. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6270 | Community Events Plugin up to 1.5.0 on WordPress Setting cross site scripting
3 months ago
A vulnerability classified as problematic was found in Community Events Plugin up to 1.5.0 on WordPress. This vulnerability affects unknown code of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-6270. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6498 | Collect.chat Chatbot Plugin up to 2.4.3 on WordPress Setting cross site scripting
3 months ago
A vulnerability, which was classified as problematic, has been found in Collect.chat Chatbot Plugin up to 2.4.3 on WordPress. This issue affects some unknown processing of the component Setting Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-6498. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6710 | Ditty Plugin up to 3.1.44 on WordPress cross site scripting
3 months ago
A vulnerability, which was classified as problematic, was found in Ditty Plugin up to 3.1.44 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-6710. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-5081 | WP-FeedStats wp-eMember Plugin up to 10.6.x on WordPress cross site scripting
3 months ago
A vulnerability has been found in WP-FeedStats wp-eMember Plugin up to 10.6.x on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-5081. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-2232 | Macaron Himer Plugin up to 2.1.2 on WordPress Private Group cross-site request forgery
3 months ago
A vulnerability was found in Macaron Himer Plugin up to 2.1.2 on WordPress and classified as problematic. Affected by this issue is some unknown functionality of the component Private Group Handler. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2024-2232. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-2334 | 274056675 springboot-openai-chatgpt e84f6f5 Chat History chat deleteChat chatListId access control
3 months ago
A vulnerability classified as problematic has been found in 274056675 springboot-openai-chatgpt e84f6f5. This affects the function deleteChat of the file /api/mjkj-chat/chat/ai/delete/chat of the component Chat History Handler. The manipulation of the argument chatListId leads to improper access controls.
This vulnerability is uniquely identified as CVE-2025-2334. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-7485 | Traffic Manager Plugin up to 1.4.5 on WordPress cross site scripting
3 months ago
A vulnerability was found in Traffic Manager Plugin up to 1.4.5 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-7485. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-41381 | microweber 2.0.16 admin.php cross site scripting (Issue 1110)
3 months ago
A vulnerability, which was classified as problematic, was found in microweber 2.0.16. This affects an unknown part of the file userfiles\modules\settings\admin.php. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-41381. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-41380 | microweber 2.0.16 add_tagging_tagged.php cross site scripting (Issue 1111)
3 months ago
A vulnerability has been found in microweber 2.0.16 and classified as problematic. This vulnerability affects unknown code of the file userfiles\modules\tags\add_tagging_tagged.php. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-41380. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-6472 | LibreOffice up to 24.2.4 Signed Macro certificate validation (Nessus ID 208051)
3 months ago
A vulnerability was found in LibreOffice up to 24.2.4. It has been rated as problematic. This issue affects some unknown processing of the component Signed Macro Handler. The manipulation leads to improper certificate validation.
The identification of this vulnerability is CVE-2024-6472. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6361 | OpenText ALM Octane. up to 23.3 cross site scripting
3 months ago
A vulnerability was found in OpenText ALM Octane. up to 23.3 and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-6361. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com