Aggregator
【安全圈】大量Chrome扩展程序遭黑客攻击,60万用户数据危险
8 months 1 week ago
【安全圈】大众集团80万电动汽车车主个人数据被泄露
8 months 1 week ago
在 Invoice Ninja 中发现的严重 SSRF 漏洞 (CVE-2024-53353)
8 months 1 week ago
安全客
CVE-2024-47920 | TikiWiki up to 27.x cross site scripting
8 months 1 week ago
A vulnerability classified as problematic was found in TikiWiki up to 27.x. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-47920. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47925 | Tecnick TCExam up to 16.3.4 cross site scripting
8 months 1 week ago
A vulnerability classified as problematic has been found in Tecnick TCExam up to 16.3.4. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-47925. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47924 | Boa cross site scripting
8 months 1 week ago
A vulnerability was found in Boa. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
The identification of this vulnerability is CVE-2024-47924. The attack may be initiated remotely. There is no exploit available.
It is recommended to replace the affected component with an alternative.
vuldb.com
CVE-2024-47917 | Mobotix CCTV FW up to MX-V3.4.2.16 cross site scripting
8 months 1 week ago
A vulnerability was found in Mobotix CCTV FW up to MX-V3.4.2.16. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-47917. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-47919 | TikiWiki up to 27.x os command injection
8 months 1 week ago
A vulnerability was found in TikiWiki up to 27.x. It has been classified as very critical. This affects an unknown part. The manipulation leads to os command injection.
This vulnerability is uniquely identified as CVE-2024-47919. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47923 | Mashov up to 3.8.31 information disclosure
8 months 1 week ago
A vulnerability was found in Mashov up to 3.8.31 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2024-47923. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47922 | Priority PRI WEB up to 24.0 information disclosure
8 months 1 week ago
A vulnerability has been found in Priority PRI WEB up to 24.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2024-47922. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47918 | TikiWiki up to 27 os command injection
8 months 1 week ago
A vulnerability, which was classified as critical, was found in TikiWiki up to 27. Affected is an unknown function. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2024-47918. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47926 | Tecnick TCExam up to 16.3.4 sql injection
8 months 1 week ago
A vulnerability, which was classified as critical, has been found in Tecnick TCExam up to 16.3.4. This issue affects some unknown processing. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2024-47926. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47921 | Smadar SPS up to 4.x risky encryption
8 months 1 week ago
A vulnerability classified as critical was found in Smadar SPS up to 4.x. This vulnerability affects unknown code. The manipulation leads to risky cryptographic algorithm.
This vulnerability was named CVE-2024-47921. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-22063 | ZTE ZENIC ONE R58 up to 16.24.20SP01 csv injection
8 months 1 week ago
A vulnerability classified as critical has been found in ZTE ZENIC ONE R58 up to 16.24.20SP01. This affects an unknown part. The manipulation leads to csv injection.
This vulnerability is uniquely identified as CVE-2024-22063. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
免费加入NVIDIA初创加速计划,即可有机会享受NVIDIA软硬件产品折扣!
8 months 1 week ago
登录 注册
免费加入NVIDIA初创加速计划,即可有机会享受NVIDIA软硬件产品折扣!
8 months 1 week ago
NVIDIA初创加速计划是NVIDIA为全球创业公司打造的加速平台,旨在为创新企业提供全方位的支持。在中国,已有超过千家创业公司加入,并获得融资机会、客户对接、路演展示、技术支持、市场推广,以及NVIDIA软硬件产品折扣等独家资源支持。现在免费申请加入,您将有机会获得行业领先的助力,加速您的企业成长。
免费申请通道:https://jinshuju.net/f/SsRLbl
免费申请通道:https://jinshuju.net/f/SsRLbl
CVE-2024-33112 及更多: FICORA 和 CAPSAICIN 僵尸网络如何利用 D-Link 设备
8 months 1 week ago
安全客
When Good Extensions Go Bad: Takeaways from the Campaign Targeting Browser Extensions
8 months 1 week ago
News has been making headlines over the weekend of the extensive attack campaign targeting browser extensions and injecting them with malicious code to steal user credentials. Currently, over 25 extensions, with an install base of over two million users, have been found to be compromised, and customers are now working to figure out their exposure (LayerX, one of the companies involved in
The Hacker News
When Good Extensions Go Bad: Takeaways from the Campaign Targeting Browser Extensions
8 months 1 week ago
Browser Security / GenAI SecurityNews has been making headlines over the weekend of the extensive