Aggregator
.NET内网实战:通过 API 函数实现 Windows 键盘日志记录
9 months 2 weeks ago
英伟达市值一夜蒸发 2 万亿;雷军入手鹦鹉绿小米 SU7 Ultra;蚂蚁集团新 CEO 上任 | 极客早知道
9 months 2 weeks ago
软银洽谈从银行融资 160 亿美元投资AI;中国电视出货量在 2024 年首次超过韩国品牌;苹果上架首款「成人」app
上下文感知的聚合页广告优化实践
9 months 2 weeks ago
聚合页广告将商家和优惠信息以多种形式聚合展示给用户,是美团广告业务中一个重要的业务场景。本文从最能影响用户决策的“发券”和“排序”两个方向出发,介绍了上下文感知建模在广告场景的落地方案,证明了聚合页上下文感知的收益空间。希望能对从事相关研究的同学带来一些启发或帮助。
美团技术团队
CVE-2024-8597 | Autodesk AutoCAD 2025.1 STP File ASMDATAX230A.dll memory corruption
9 months 2 weeks ago
A vulnerability classified as critical has been found in Autodesk AutoCAD 2025.1. Affected is an unknown function in the library ASMDATAX230A.dll of the component STP File Handler. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2024-8597. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-8598 | Autodesk AutoCAD 2025.1 STP File ACTranslators.exe memory corruption
9 months 2 weeks ago
A vulnerability classified as critical was found in Autodesk AutoCAD 2025.1. Affected by this vulnerability is an unknown functionality of the file ACTranslators.exe of the component STP File Handler. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2024-8598. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-8599 | Autodesk AutoCAD 2025.1 STP File ACTranslators.exe memory corruption
9 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in Autodesk AutoCAD 2025.1. Affected by this issue is some unknown functionality of the file ACTranslators.exe of the component STP File Handler. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2024-8599. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-9826 | Autodesk AutoCAD 2025.1 3DM File Parser atf_api.dll use after free
9 months 2 weeks ago
A vulnerability has been found in Autodesk AutoCAD 2025.1 and classified as critical. This vulnerability affects unknown code in the library atf_api.dll of the component 3DM File Parser. The manipulation leads to use after free.
This vulnerability was named CVE-2024-9826. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-9827 | Autodesk AutoCAD 2025.1 CATPART File CC5Dll.dll out-of-bounds
9 months 2 weeks ago
A vulnerability was found in Autodesk AutoCAD 2025.1 and classified as critical. This issue affects some unknown processing in the library CC5Dll.dll of the component CATPART File Handler. The manipulation leads to out-of-bounds read.
The identification of this vulnerability is CVE-2024-9827. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-8587 | Autodesk AutoCAD 2025.1 SLDPRT File odxsw_dll.dll heap-based overflow (Nessus ID 210051)
9 months 2 weeks ago
A vulnerability was found in Autodesk AutoCAD 2025.1. It has been classified as critical. Affected is an unknown function in the library odxsw_dll.dll of the component SLDPRT File Handler. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2024-8587. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-44080 | Jitsi Meet up to 2.0.9778 Giphy Image Sharing information disclosure (JSA-2024-0002)
9 months 2 weeks ago
A vulnerability was found in Jitsi Meet up to 2.0.9778. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Giphy Image Sharing. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2024-44080. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-44081 | Jitsi Meet up to 2.0.9778 Video File Sharing information disclosure (JSA-2024-0003)
9 months 2 weeks ago
A vulnerability was found in Jitsi Meet up to 2.0.9778. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Video File Sharing. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2024-44081. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-48461 | TeslaLogger Admin Panel up to 1.59.5 New Journey cross site scripting
9 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in TeslaLogger Admin Panel up to 1.59.5. Affected by this issue is some unknown functionality. The manipulation of the argument New Journey leads to cross site scripting.
This vulnerability is handled as CVE-2024-48461. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50348 | InstantSoft icms2 up to 2.16.2 Photo Album Page cross site scripting (GHSA-f6cf-jg84-fw29)
9 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in InstantSoft icms2 up to 2.16.2. This affects an unknown part of the component Photo Album Page. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-50348. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-10223 | HT Team Member Plugin up to 1.1.4 on WordPress Shortcode cross site scripting
9 months 2 weeks ago
A vulnerability was found in HT Team Member Plugin up to 1.1.4 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-10223. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-10108 | WPAdverts Plugin up to 2.1.6 on WordPress Shortcode adverts_add cross site scripting
9 months 2 weeks ago
A vulnerability classified as problematic has been found in WPAdverts Plugin up to 2.1.6 on WordPress. This affects the function adverts_add of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-10108. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-50344 | mkucej i-librarian-free up to 5.11.1 cross site scripting
9 months 2 weeks ago
A vulnerability classified as problematic was found in mkucej i-librarian-free up to 5.11.1. This vulnerability affects unknown code. The manipulation leads to basic cross site scripting.
This vulnerability was named CVE-2024-50344. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-24777 | LevelOne WBR-6012 R0.40e6 HTTP Request cross-site request forgery (TALOS-2024-1981)
9 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in LevelOne WBR-6012 R0.40e6. Affected by this issue is some unknown functionality of the component HTTP Request Handler. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2024-24777. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-9708 | Easy SVG Upload Plugin up to 1.0 on WordPress SVG File Upload cross site scripting
9 months 2 weeks ago
A vulnerability classified as problematic has been found in Easy SVG Upload Plugin up to 1.0 on WordPress. This affects an unknown part of the component SVG File Upload Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-9708. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-8444 | Download Manager Plugin up to 3.2.x on WordPress Shortcode cross site scripting
9 months 2 weeks ago
A vulnerability was found in Download Manager Plugin up to 3.2.x on WordPress. It has been declared as problematic. This vulnerability affects unknown code of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-8444. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com