Aggregator
【安全圈】黑客声称侵入安全公司 Check Point, 声称掌握内部资料
5 months 1 week ago
关键词数据泄露事件背景:黑客 "CoreInjection" 在地下论坛 BreachForums 发帖声称,
【安全圈】GitHub一年泄漏3900万秘密信息
5 months 1 week ago
关键词泄露1. 问题的严重性:数据泄露规模:2024年,GitHub检测到超过 3900万个泄露秘密,较202
【安全圈】英伟达驱动噩梦!572.83版本秒变“黑屏王”
5 months 1 week ago
关键词关键信息整理:驱动版本:WHQL 572.83发布时间:2024年3月19日官方说明:声称修复了RTX
MCP 的现状和未来
5 months 1 week ago
安全行业很多年没有新叙事了,AI 时代将大量没有受过系统计算机科学训练的伙计引入进来,不仅所有漏洞会被重新实现一遍,新技术的引入还会带来新的安全问题。
MCP 的现状和未来
5 months 1 week ago
安全行业很多年没有新叙事了,AI 时代将大量没有受过系统计算机科学训练的伙计引入进来,不仅所有漏洞会被重新实现一遍,新技术的引入还会带来新的安全问题。
MCP 的现状和未来
5 months 1 week ago
安全行业很多年没有新叙事了,AI 时代将大量没有受过系统计算机科学训练的伙计引入进来,不仅所有漏洞会被重新实现一遍,新技术的引入还会带来新的安全问题。
CVE-2025-3318 | Kenj_Frog 肯尼基蛙 company-financial-management 公司财务管理系统 ShangpinleixingController.java page sql injection (IBM6D9)
5 months 1 week ago
A vulnerability classified as critical was found in Kenj_Frog 肯尼基蛙 company-financial-management 公司财务管理系统 1.0. Affected by this vulnerability is the function page of the file src/main/java/com/controller/ShangpinleixingController.java. The manipulation of the argument sort leads to sql injection.
This vulnerability is known as CVE-2025-3318. The attack can be launched remotely. Furthermore, there is an exploit available.
This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.
vuldb.com
Учёные предложили новый закон природы — и он за разум во Вселенной
5 months 1 week ago
Кажется, Вселенная любит усложнять. В хорошем смысле.
CVE-2025-3317 | fumiao opencms up to a0fafa5cff58719e9b27c2a2eec204cc165ce14f dataPage.jsp path path traversal (IBLJLM)
5 months 1 week ago
A vulnerability classified as problematic has been found in fumiao opencms up to a0fafa5cff58719e9b27c2a2eec204cc165ce14f. Affected is an unknown function of the file opencms-dev/src/main/webapp/view/admin/document/dataPage.jsp. The manipulation of the argument path leads to path traversal.
This vulnerability is traded as CVE-2025-3317. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
vuldb.com
CVE-2024-30950 | FUDforum 3.1.3 /adm/admsql.php statements cross site scripting
5 months 1 week ago
A vulnerability was found in FUDforum 3.1.3. It has been declared as problematic. This vulnerability affects unknown code of the file /adm/admsql.php. The manipulation of the argument statements leads to cross site scripting.
This vulnerability was named CVE-2024-30950. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-3914 | Google Chrome up to 123.0.6312.122 V8 use after free (ID 330759)
5 months 1 week ago
A vulnerability was found in Google Chrome. It has been classified as critical. This affects an unknown part of the component V8. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2024-3914. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-38272
5 months 1 week ago
Currently trending CVE - Hype Score: 8 - There exists a vulnerability in Quick Share/Nearby, where an attacker can bypass the accept file dialog on Quick Share Windows. Normally in Quick Share Windows app we can't send a file without the user accept from the receiving device if the visibility is set to everyone mode or ...
CVE-2025-3316 | PHPGurukul Men Salon Management System 1.0 search-invoices.php searchdata sql injection
5 months 1 week ago
A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/search-invoices.php. The manipulation of the argument searchdata leads to sql injection.
The identification of this vulnerability is CVE-2025-3316. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Hunters
5 months 1 week ago
cohenido
CVE-2025-32352 | ZendTo up to 5.04-6 MD5 lib/NSSAuthenticator.php type confusion
5 months 1 week ago
A vulnerability was found in ZendTo up to 5.04-6. It has been declared as problematic. This vulnerability affects unknown code in the library lib/NSSAuthenticator.php of the component MD5 Handler. The manipulation leads to type confusion.
This vulnerability was named CVE-2025-32352. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-47667 | ZendTo up to 6.10-6 lib/NSSDropoff.php tmp_name os command injection
5 months 1 week ago
A vulnerability was found in ZendTo up to 6.10-6. It has been classified as very critical. This affects an unknown part in the library lib/NSSDropoff.php. The manipulation of the argument tmp_name leads to os command injection.
This vulnerability is uniquely identified as CVE-2021-47667. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Hunters
5 months 1 week ago
cohenido
CVE-2016-8808 | NVIDIA Graphics Driver up to 341/369.58/375.62 on Quadro/NVS/GeForce Kernel Mode Layer nvlddmkm.sys DxgDdiEscape access control (EDB-40666 / Nessus ID 94576)
5 months 1 week ago
A vulnerability has been found in NVIDIA Graphics Driver up to 341/369.58/375.62 on Quadro/NVS/GeForce and classified as critical. Affected by this vulnerability is the function DxgDdiEscape in the library nvlddmkm.sys of the component Kernel Mode Layer. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2016-8808. An attack has to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Submit #551749: PHPGurukul Men Salon Management System V1.0 SQL Injection [Accepted]
5 months 1 week ago
Submit #551749 / VDB-303515
zhaoluzhizhi