Aggregator
CVE-2024-42019 | Veeam ONE up to 12.1.0.3208 Reporter Service information disclosure (kb4649)
4 months 1 week ago
A vulnerability was found in Veeam ONE up to 12.1.0.3208. It has been declared as very critical. Affected by this vulnerability is an unknown functionality of the component Reporter Service. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2024-42019. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42024 | Veeam ONE up to 12.1.0.3208 Agent Service unnecessary privileges (kb4649)
4 months 1 week ago
A vulnerability was found in Veeam ONE up to 12.1.0.3208. It has been classified as critical. Affected is an unknown function of the component Agent Service. The manipulation leads to execution with unnecessary privileges.
This vulnerability is traded as CVE-2024-42024. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42023 | Veeam ONE up to 12.1.0.3208 access control (kb4649)
4 months 1 week ago
A vulnerability was found in Veeam ONE up to 12.1.0.3208. It has been rated as very critical. Affected by this issue is some unknown functionality. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2024-42023. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42021 | Veeam ONE up to 12.1.0.3208 Access Token access control (kb4649)
4 months 1 week ago
A vulnerability classified as problematic has been found in Veeam ONE up to 12.1.0.3208. This affects an unknown part of the component Access Token Handler. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2024-42021. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42022 | Veeam ONE up to 12.1.0.3208 Configuration File access control (kb4649)
4 months 1 week ago
A vulnerability classified as problematic was found in Veeam ONE up to 12.1.0.3208. This vulnerability affects unknown code of the component Configuration File Handler. The manipulation leads to improper access controls.
This vulnerability was named CVE-2024-42022. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42020 | Veeam ONE up to 12.1.0.3208 Reporter Widgets cross site scripting (kb4649)
4 months 1 week ago
A vulnerability, which was classified as problematic, has been found in Veeam ONE up to 12.1.0.3208. This issue affects some unknown processing of the component Reporter Widgets. The manipulation leads to basic cross site scripting.
The identification of this vulnerability is CVE-2024-42020. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8559 | SourceCodester Online Food Menu 1.0 delete-menu.php menu sql injection
4 months 1 week ago
A vulnerability, which was classified as critical, has been found in SourceCodester Online Food Menu 1.0. This issue affects some unknown processing of the file /endpoint/delete-menu.php. The manipulation of the argument menu leads to sql injection.
The identification of this vulnerability is CVE-2024-8559. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-8560 | SourceCodester Simple Invoice Generator System 1.0 /save_invoice.php sql injection
4 months 1 week ago
A vulnerability, which was classified as critical, was found in SourceCodester Simple Invoice Generator System 1.0. Affected is an unknown function of the file /save_invoice.php. The manipulation of the argument invoice_code/customer/cashier/total_amount/discount_percentage/discount_amount/tendered_amount leads to sql injection.
This vulnerability is traded as CVE-2024-8560. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-8561 | SourceCodester PHP CRUD 1.0 Delete Person /endpoint/delete.php person sql injection
4 months 1 week ago
A vulnerability has been found in SourceCodester PHP CRUD 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /endpoint/delete.php of the component Delete Person Handler. The manipulation of the argument person leads to sql injection.
This vulnerability is known as CVE-2024-8561. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-8562 | SourceCodester PHP CRUD 1.0 /endpoint/Add.php first_name/middle_name/last_name cross site scripting
4 months 1 week ago
A vulnerability was found in SourceCodester PHP CRUD 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /endpoint/Add.php. The manipulation of the argument first_name/middle_name/last_name leads to cross site scripting.
This vulnerability is handled as CVE-2024-8562. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-8563 | SourceCodester PHP CRUD 1.0 /endpoint/update.php first_name/middle_name/last_name cross site scripting
4 months 1 week ago
A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/update.php. The manipulation of the argument first_name/middle_name/last_name leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-8563. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-8564 | SourceCodester PHP CRUD 1.0 /endpoint/update.php tbl_person_id/first_name/middle_name/last_name sql injection
4 months 1 week ago
A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/update.php. The manipulation of the argument tbl_person_id/first_name/middle_name/last_name leads to sql injection.
This vulnerability was named CVE-2024-8564. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-8565 | SourceCodesters Clinics Patient Management System 2.0 /print_diseases.php disease/from/to sql injection
4 months 1 week ago
A vulnerability was found in SourceCodesters Clinics Patient Management System 2.0. It has been rated as critical. This issue affects some unknown processing of the file /print_diseases.php. The manipulation of the argument disease/from/to leads to sql injection.
The identification of this vulnerability is CVE-2024-8565. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
2023年度CNVD优秀单位(个人)表彰名单
4 months 1 week ago
为激励和引导各单位个人勇于团结协作和积极贡献,进一步凝聚国内网安技术力量,协同提高网络安全能力。依照《国家信息安全漏洞共享平台(CNVD)支撑单位能力评价》办法,CNVD完成2023年度技术组支撑单位的能力评价工作。
CVE-2017-13688 | tcpdump up to 4.9.1 OLSR Parser print-olsr.c olsr_print memory corruption (Nessus ID 103257 / ID 370625)
4 months 1 week ago
A vulnerability has been found in tcpdump up to 4.9.1 and classified as critical. This vulnerability affects the function olsr_print of the file print-olsr.c of the component OLSR Parser. The manipulation leads to memory corruption.
This vulnerability was named CVE-2017-13688. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
“Unstripping” binaries: Restoring debugging information in GDB with Pwndbg
4 months 1 week ago
CIS Benchmarks September 2024 Update
4 months 1 week ago
Here is an overview of the CIS Benchmarks that the Center for Internet Security updated or released for September 2024.
CVE-2017-13687 | Apple macOS up to 10.13.1 tcpdump memory corruption (HT208221 / Nessus ID 100472)
4 months 1 week ago
A vulnerability was found in Apple macOS up to 10.13.1 and classified as very critical. This issue affects some unknown processing of the component tcpdump. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2017-13687. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
达斯·维德配音演员 James Earl Jones 去世,享年 93 岁
4 months 1 week ago
达斯·维德配音演员 James Earl Jones 于周一去世,享年 93 岁。Jones 是少数获得艾美奖、格莱美奖、奥斯卡奖、托尼奖的艺人之一,虽然他的奥斯卡奖是荣誉奖。他被誉为是最伟大的舞台和银幕演员之一。他首次出演电影是在库布里克的 1964 年电影《奇爱博士或我如何学会停止恐惧并爱上炸弹》,先后在动画版和 CGI 版《狮子王》中为 Mufasa 配音,他最为人熟知的角色是在《星球大战》系列中为达斯·维德配音,他在 2022 年与卢卡斯影业签署协议,授权在未来的《星战》系列影视剧中利用其声音去合成达斯·维德的声音。