Aggregator
CVE-2024-41765 | IBM Engineering Lifecycle Optimization Publishing 7.0.2/7.0.3 URL path traversal
8 months 4 weeks ago
A vulnerability was found in IBM Engineering Lifecycle Optimization Publishing 7.0.2/7.0.3 and classified as critical. This issue affects some unknown processing of the component URL Handler. The manipulation leads to path traversal: '/../filedir'.
The identification of this vulnerability is CVE-2024-41765. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41768 | IBM Engineering Lifecycle Optimization Publishing 7.0.2/7.0.3 missing standardized error handling mechanism
8 months 4 weeks ago
A vulnerability was found in IBM Engineering Lifecycle Optimization Publishing 7.0.2/7.0.3. It has been classified as critical. Affected is an unknown function. The manipulation leads to missing standardized error handling mechanism.
This vulnerability is traded as CVE-2024-41768. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41767 | IBM Engineering Lifecycle Optimization Publishing 7.0.2/7.0.3 sql injection
8 months 4 weeks ago
A vulnerability was found in IBM Engineering Lifecycle Optimization Publishing 7.0.2/7.0.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection.
This vulnerability is known as CVE-2024-41767. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41763 | IBM Engineering Lifecycle Optimization Publishing 7.0.2/7.0.3 risky encryption
8 months 4 weeks ago
A vulnerability was found in IBM Engineering Lifecycle Optimization Publishing 7.0.2/7.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to risky cryptographic algorithm.
This vulnerability is handled as CVE-2024-41763. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41766 | IBM Engineering Lifecycle Optimization Publishing 7.0.2/7.0.3 redos
8 months 4 weeks ago
A vulnerability classified as critical has been found in IBM Engineering Lifecycle Optimization Publishing 7.0.2/7.0.3. This affects an unknown part. The manipulation leads to inefficient regular expression complexity.
This vulnerability is uniquely identified as CVE-2024-41766. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-57971 | KNOWAGE up to 8.1.29 SpagoBI API DataSourceResource.java JNDI Name resource injection
8 months 4 weeks ago
A vulnerability classified as critical has been found in KNOWAGE up to 8.1.29. Affected is an unknown function of the file DataSourceResource.java of the component SpagoBI API. The manipulation of the argument JNDI Name leads to improper control of resource identifiers.
This vulnerability is traded as CVE-2024-57971. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-25302 | danielgatis rembg up to 2.0.57 origin validation (GHSL-2024-161)
8 months 4 weeks ago
A vulnerability classified as problematic was found in danielgatis rembg up to 2.0.57. This vulnerability affects unknown code. The manipulation leads to origin validation error.
This vulnerability was named CVE-2025-25302. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-30197 | Zoho QEngine Plugin up to 1.0.29.vfa_cc23396502 on Jenkins QEngine API Key Form Field missing password field masking
8 months 4 weeks ago
A vulnerability, which was classified as problematic, has been found in Zoho QEngine Plugin up to 1.0.29.vfa_cc23396502 on Jenkins. Affected by this issue is some unknown functionality of the component QEngine API Key Form Field. The manipulation leads to missing password field masking.
This vulnerability is handled as CVE-2025-30197. Attacking locally is a requirement. There is no exploit available.
vuldb.com
CVE-2024-56062 | WP Royal Royal Elementor Addons Plugin up to 1.3.987 on WordPress cross site scripting
8 months 4 weeks ago
A vulnerability was found in WP Royal Royal Elementor Addons Plugin up to 1.3.987 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-56062. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-56227 | WP Royal Royal Elementor Addons Plugin up to 1.7.1001 on WordPress authorization
8 months 4 weeks ago
A vulnerability has been found in WP Royal Royal Elementor Addons Plugin up to 1.7.1001 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to missing authorization.
This vulnerability was named CVE-2024-56227. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-56226 | WP Royal Royal Elementor Addons Plugin up to 1.7.1001 on WordPress cross site scripting
8 months 4 weeks ago
A vulnerability has been found in WP Royal Royal Elementor Addons Plugin up to 1.7.1001 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-56226. The attack can be initiated remotely. There is no exploit available.
vuldb.com
实战中的WebService利⽤⽅法
8 months 4 weeks ago
声明:该公众号大部分文章来自作者日常学习笔记,未经授权,严禁转载,如需转载,联系洪椒攻防实验室公众号。请勿利
实战中的WebService利⽤⽅法
8 months 4 weeks ago
声明:该公众号大部分文章来自作者日常学习笔记,未经授权,严禁转载,如需转载,联系洪椒攻防实验室公众号。请勿利
CVE-2025-23120 :Veeam Backup & Replication 严重 RCE 漏洞已修复,尽快修补!
8 months 4 weeks ago
安全客
A Peek on Cloud Security: JSSI 2025
8 months 4 weeks ago
At JSSI 2025, French IT security experts discussed the cloud's impact on security. Presentations covered strategy and technical analysis. GitGuardian’s researchers shared insights on detecting secrets in the cloud and responsibly disclosing them to companies.
The post A Peek on Cloud Security: JSSI 2025 appeared first on Security Boulevard.
Gaëtan Ferry
Tenable 警告称 DeepSeek AI 模型易遭破解用于生成恶意软件
8 months 4 weeks ago
安全客
Albabat Ransomware Evolves to Target Linux and macOS
8 months 4 weeks ago
Trend Micro observed a continuous development of Albabat ransomware, designed to expand attacks and streamline operations
CVE-2025-2608 | PHPGurukul Banquet Booking System 1.2 view-user-queries.php viewid sql injection
8 months 4 weeks ago
A vulnerability classified as critical has been found in PHPGurukul Banquet Booking System 1.2. This affects an unknown part of the file /admin/view-user-queries.php. The manipulation of the argument viewid leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-2608. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #518587: PHPGurukul Banquet Booking System 1.2 SQL Injection [Accepted]
8 months 4 weeks ago
Submit #518587 / VDB-300591