Aggregator
WhatsApp惊现漏洞!黑客可借此执行恶意代码,Windows用户赶紧更新
1 year ago
WhatsApp Windows版存在漏洞,攻击者可借此运行恶意代码,用户需尽快更新至最新版本。
aliyunctf 2025 babygame bevy Engine探索与rust逆向
1 year ago
看雪论坛作者ID:SleepAlone
本周六20:30开课!直播教学-ARM系统深度调试与逆向(欢迎报名)
1 year ago
直播授课,小班教学
CVE-2025-20952 | Samsung Devices Mdecservice improper export of android application components
1 year ago
A vulnerability was found in Samsung Devices. It has been declared as problematic. This vulnerability affects unknown code of the component Mdecservice. The manipulation leads to improper export of android application components.
This vulnerability was named CVE-2025-20952. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-25056 | Inaba Denki Sangyo AC-WPS-11ac cross-site request forgery
1 year ago
A vulnerability was found in Inaba Denki Sangyo AC-WPS-11ac, AC-WPS-11ac-P, AC-WPSM-11ac, AC-WPSM-11ac-P, AC-PD-WPS-11ac and AC-PD-WPS-11ac-P. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2025-25056. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-8243 | Plugin Upgrade Time Out Plugin up to 1.0 on WordPress WordPress/Plugin cross-site request forgery
1 year ago
A vulnerability was found in Plugin Upgrade Time Out Plugin up to 1.0 on WordPress and classified as problematic. Affected by this issue is some unknown functionality of the file WordPress/Plugin. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2024-8243. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-3442 | TP-Link Tapo H200 V1 IoT Smart Hub up to 1.4.0 cleartext storage (CIVN-2025-0072)
1 year ago
A vulnerability has been found in TP-Link Tapo H200 V1 IoT Smart Hub up to 1.4.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cleartext storage of sensitive information.
This vulnerability is known as CVE-2025-3442. It is possible to launch the attack on the physical device. There is no exploit available.
vuldb.com
CVE-2025-29988 | Dell Client Platform BIOS up to 1.32.x/1.34.x/2.1.4/2.23.x stack-based overflow (dsa-2025-088)
1 year ago
A vulnerability, which was classified as critical, was found in Dell Client Platform BIOS up to 1.32.x/1.34.x/2.1.4/2.23.x. Affected is an unknown function. The manipulation leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2025-29988. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6857 | WP MultiTasking Plugin up to 0.1.12 on WordPress Setting cross-site request forgery
1 year ago
A vulnerability, which was classified as problematic, has been found in WP MultiTasking Plugin up to 0.1.12 on WordPress. This issue affects some unknown processing of the component Setting Handler. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2024-6857. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-32464 | HAProxy up to 3.1.6 sample_conv_regsub heap-based overflow
1 year ago
A vulnerability classified as critical was found in HAProxy up to 3.1.6. This vulnerability affects the function sample_conv_regsub. The manipulation leads to heap-based buffer overflow.
This vulnerability was named CVE-2025-32464. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-25213 | Inaba Denki Sangyo AC-WPS-11ac ui layer
1 year ago
A vulnerability classified as problematic has been found in Inaba Denki Sangyo AC-WPS-11ac, AC-WPS-11ac-P, AC-WPSM-11ac, AC-WPSM-11ac-P, AC-PD-WPS-11ac and AC-PD-WPS-11ac-P. This affects an unknown part. The manipulation leads to improper restriction of rendered ui layers.
This vulnerability is uniquely identified as CVE-2025-25213. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-29870 | Inaba Denki Sangyo AC-WPS-11ac missing authentication
1 year ago
A vulnerability was found in Inaba Denki Sangyo AC-WPS-11ac, AC-WPS-11ac-P, AC-WPSM-11ac, AC-WPSM-11ac-P, AC-PD-WPS-11ac and AC-PD-WPS-11ac-P. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to missing authentication.
This vulnerability is handled as CVE-2025-29870. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-27797 | Inaba Denki Sangyo AC-WPS-11ac os command injection
1 year ago
A vulnerability was found in Inaba Denki Sangyo AC-WPS-11ac, AC-WPS-11ac-P, AC-WPSM-11ac, AC-WPSM-11ac-P, AC-PD-WPS-11ac and AC-PD-WPS-11ac-P. It has been declared as very critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to os command injection.
This vulnerability is known as CVE-2025-27797. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-27722 | Inaba Denki Sangyo AC-WPS-11ac cleartext transmission
1 year ago
A vulnerability was found in Inaba Denki Sangyo AC-WPS-11ac, AC-WPS-11ac-P, AC-WPSM-11ac, AC-WPSM-11ac-P, AC-PD-WPS-11ac and AC-PD-WPS-11ac-P. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cleartext transmission of sensitive information.
This vulnerability is traded as CVE-2025-27722. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-25053 | Inaba Denki Sangyo AC-WPS-11ac Web UI os command injection
1 year ago
A vulnerability was found in Inaba Denki Sangyo AC-WPS-11ac, AC-WPS-11ac-P, AC-WPSM-11ac, AC-WPSM-11ac-P, AC-PD-WPS-11ac and AC-PD-WPS-11ac-P and classified as critical. This issue affects some unknown processing of the component Web UI. The manipulation leads to os command injection.
The identification of this vulnerability is CVE-2025-25053. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-23407 | Inaba Denki Sangyo AC-WPS-11ac Setting privileges assignment
1 year ago
A vulnerability has been found in Inaba Denki Sangyo AC-WPS-11ac, AC-WPS-11ac-P, AC-WPSM-11ac, AC-WPSM-11ac-P, AC-PD-WPS-11ac and AC-PD-WPS-11ac-P and classified as problematic. This vulnerability affects unknown code of the component Setting Handler. The manipulation leads to incorrect privilege assignment.
This vulnerability was named CVE-2025-23407. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-27934 | Inaba Denki Sangyo AC-WPS-11ac exposure of sensitive system information to an unauthorized control sphere
1 year ago
A vulnerability, which was classified as problematic, was found in Inaba Denki Sangyo AC-WPS-11ac, AC-WPS-11ac-P, AC-WPSM-11ac, AC-WPSM-11ac-P, AC-PD-WPS-11ac and AC-PD-WPS-11ac-P. This affects an unknown part. The manipulation leads to exposure of sensitive system information to an unauthorized control sphere.
This vulnerability is uniquely identified as CVE-2025-27934. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-6860 | WP MultiTasking Plugin up to 0.1.12 on WordPress Setting cross-site request forgery
1 year ago
A vulnerability, which was classified as problematic, has been found in WP MultiTasking Plugin up to 0.1.12 on WordPress. Affected by this issue is some unknown functionality of the component Setting Handler. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2024-6860. The attack may be launched remotely. There is no exploit available.
vuldb.com
微软4月补丁星期二值得关注的漏洞
1 year ago
速修复