Aggregator
CVE-2011-4040 | NJStar NJStar Communicator 3.0.11818 memory corruption (VU#819630 / EDB-18196)
8 months 3 weeks ago
A vulnerability was found in NJStar NJStar Communicator 3.0.11818. It has been declared as very critical. This vulnerability affects unknown code. The manipulation leads to memory corruption.
This vulnerability was named CVE-2011-4040. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-0467 | Apple Mac OS X 10.4.8 symlink (VU#363112 / EDB-3219)
8 months 3 weeks ago
A vulnerability was found in Apple Mac OS X 10.4.8 and classified as critical. Affected by this issue is some unknown functionality in the library library/logs/crashreporter/. The manipulation leads to symlink following.
This vulnerability is handled as CVE-2007-0467. An attack has to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-40332 | idcCMS 1.35 moneyRecord_deal.php?mudi=delRecord cross-site request forgery
8 months 3 weeks ago
A vulnerability was found in idcCMS 1.35. It has been classified as problematic. Affected is an unknown function of the file /admin/moneyRecord_deal.php?mudi=delRecord. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2024-40332. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-40333 | idcCMS 1.35 softBak_deal.php?mudi=del&dataID=2 cross-site request forgery
8 months 3 weeks ago
A vulnerability was found in idcCMS 1.35. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/softBak_deal.php?mudi=del&dataID=2. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2024-40333. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-40336 | idcCMS 1.35 Image Advertising Management cross site scripting
8 months 3 weeks ago
A vulnerability classified as problematic has been found in idcCMS 1.35. This affects an unknown part of the component Image Advertising Management. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-40336. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-28828 | Checkmk up to 2.0.0p39/2.1.0p44/2.2.0p28/2.3.0p7 cross-site request forgery
8 months 3 weeks ago
A vulnerability classified as problematic was found in Checkmk up to 2.0.0p39/2.1.0p44/2.2.0p28/2.3.0p7. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2024-28828. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-40334 | idcCMS 1.35 serverFile_deal.php?mudi=upFileDel&dataID=3 cross-site request forgery
8 months 3 weeks ago
A vulnerability was found in idcCMS 1.35. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/serverFile_deal.php?mudi=upFileDel&dataID=3. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2024-40334. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-27095 | Decidim up to 0.27.5/0.28.0 Record cross site scripting (GHSA-529p-jj47-w3m3)
8 months 3 weeks ago
A vulnerability was found in Decidim up to 0.27.5/0.28.0 and classified as problematic. This issue affects some unknown processing of the component Record Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-27095. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-32469 | Decidim up to 0.27.5/0.28.0 GET Parameter per_page cross site scripting (GHSA-7cx8-44pc-xv3q)
8 months 3 weeks ago
A vulnerability was found in Decidim up to 0.27.5/0.28.0. It has been classified as problematic. Affected is an unknown function of the component GET Parameter Handler. The manipulation of the argument per_page leads to cross site scripting.
This vulnerability is traded as CVE-2024-32469. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-38354 | hackmdio codimd up to 2.5.3 HTML Tag Name HTML injection (GHSA-22jv-vch8-2vp9)
8 months 3 weeks ago
A vulnerability was found in hackmdio codimd up to 2.5.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component HTML Tag Handler. The manipulation of the argument Name leads to HTML injection.
This vulnerability is known as CVE-2024-38354. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CLOP
8 months 3 weeks ago
cohenido
CLOP
8 months 3 weeks ago
cohenido
CLOP
8 months 3 weeks ago
cohenido
ChatGPT SSRF 漏洞迅速成为攻击者首选攻击载体
8 months 3 weeks ago
安全客
【安全圈】伪装成安全文档查看器的 DocSwap 恶意软件对全球安卓用户发动攻击
8 months 3 weeks ago
关键词恶意软件一场名为 “DocSwap” 的复杂恶意软件攻击活动浮出水面,它伪装成一款合法的文档安全与查看应
【安全圈】ChatGPT 漏洞遭超一万个 IP 地址主动利用,美国政府机构惨遭攻击
8 months 3 weeks ago
关键词攻击者正在积极利用 OpenAI 的 ChatGPT 基础设施中的一个服务器端请求伪造(SSRF)漏洞。
【安全圈】StilachiRAT 技术分析:规避技术、攻击场景与安全建议
8 months 3 weeks ago
关键词StilachiRAT深入分析规避技术反分析与沙盒规避StilachiRAT 设计了强大的反分析功能,以
【安全圈】2025年2月数据泄露态势:千万级数据外泄,匿名社交平台风险加剧
8 months 3 weeks ago
关键词网络安全在数字化互联的时代,数据作为第五大生产要素,只有实现充分流动,才能激发出无限价值。
Weekoverzicht Defensieoperaties
8 months 3 weeks ago
Commandant Luchtstrijdkrachten luitenant-generaal André Steur bezocht de Nederlandse militairen in Roemenië. Een MQ-9 Reaper-detachement verzamelt daar met 3 onbemande toestellen informatie aan de oostflank van de NAVO. Een overzicht van Defensieoperaties in de week van 12 tot en met 18 maart 2025.