Aggregator
第118篇:Redis未授权访问漏洞与SSH免密登录的简易操作方法
1 year ago
第118篇:Redis未授权访问漏洞与SSH免密登录的简易操作方法
1 year ago
CVE-2006-0737 | eStara softphone 3.0.1.47 denial of service (EDB-27211 / XFDB-24677)
1 year ago
A vulnerability classified as problematic has been found in eStara softphone 3.0.1.47. Affected is an unknown function. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2006-0737. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-9953 | CERTCC VINCE up to 3.0.7 deserialization
1 year ago
A vulnerability was found in CERTCC VINCE up to 3.0.7. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to deserialization.
This vulnerability was named CVE-2024-9953. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-38769 | Tyche Softwares Arconix Shortcodes Plugin up to 2.1.11 on WordPress authorization
1 year ago
A vulnerability was found in Tyche Softwares Arconix Shortcodes Plugin up to 2.1.11 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2024-38769. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-38783 | Tyche Softwares Arconix FAQ Plugin up to 1.9.4 on WordPress authorization
1 year ago
A vulnerability classified as problematic has been found in Tyche Softwares Arconix FAQ Plugin up to 1.9.4 on WordPress. Affected is an unknown function. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2024-38783. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-20176 | Cisco IOS/IOS XE SNMP Subsystem denial of service (cisco-sa-snmp-dos-sdxnSUcW / Nessus ID 215126)
1 year ago
A vulnerability, which was classified as critical, has been found in Cisco IOS and IOS XE. Affected by this issue is some unknown functionality of the component SNMP Subsystem. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2025-20176. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-20653 | MediaTek MT8390 Da integer overflow (MSV-2046 / ALPS09291064)
1 year ago
A vulnerability was found in MediaTek MT6781, MT6789, MT6835, MT6855, MT6878, MT6879, MT6886, MT6895, MT6897, MT6983, MT6985, MT6989, MT8370 and MT8390. It has been classified as problematic. This affects an unknown part of the component Da. The manipulation leads to integer overflow.
This vulnerability is uniquely identified as CVE-2025-20653. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-7804 | PyTorch up to up to 2.3.1 internal.py PythonUDF deserialization
1 year ago
A vulnerability classified as critical was found in PyTorch up to up to 2.3.1. This vulnerability affects unknown code of the file pytorch/torch/distributed/rpc/internal.py. The manipulation of the argument PythonUDF leads to deserialization.
This vulnerability was named CVE-2024-7804. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-7773 | ollama up to 0.3.x ZIP File parseFromZipFile path traversal
1 year ago
A vulnerability was found in ollama up to 0.3.x. It has been declared as critical. This vulnerability affects the function parseFromZipFile of the component ZIP File Handler. The manipulation leads to path traversal: '../filedir'.
This vulnerability was named CVE-2024-7773. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-7776 | onnx Framework up to 1.16.1 download_model path traversal
1 year ago
A vulnerability, which was classified as critical, has been found in onnx Framework up to 1.16.1. Affected by this issue is the function download_model. The manipulation leads to path traversal.
This vulnerability is handled as CVE-2024-7776. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-6829 | aimhubio aim up to 3.19.3 tarfile.extractall file inclusion
1 year ago
A vulnerability has been found in aimhubio aim up to 3.19.3 and classified as critical. This vulnerability affects the function tarfile.extractall. The manipulation leads to file inclusion.
This vulnerability was named CVE-2024-6829. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-7779 | danswer-ai danswer redos
1 year ago
A vulnerability was found in danswer-ai danswer and classified as critical. This issue affects some unknown processing. The manipulation leads to inefficient regular expression complexity.
The identification of this vulnerability is CVE-2024-7779. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CISA tags NAKIVO backup flaw as actively exploited in attacks
1 year ago
CISA has warned U.S. federal agencies to secure their networks against attacks exploiting a high-severity vulnerability in NAKIVO's Backup & Replication software. [...]
Sergiu Gatlan
CVE-2024-5616 | mudler localai up to 2.16 cross-site request forgery
1 year ago
A vulnerability was found in mudler localai up to 2.16 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2024-5616. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-37234 | Kodezen Limited Academy LMS Plugin up to 2.0.4 on WordPress redirect
1 year ago
A vulnerability was found in Kodezen Limited Academy LMS Plugin up to 2.0.4 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to open redirect.
The identification of this vulnerability is CVE-2024-37234. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-37541 | StaxWP Elementor Addons, Widgets and Enhancements Plugin up to 1.4.4.1 on WordPress cross site scripting
1 year ago
A vulnerability classified as problematic was found in StaxWP Elementor Addons, Widgets and Enhancements Plugin up to 1.4.4.1 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-37541. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-37539 | Delower WP To Do Plugin up to 1.3.0 on WordPress cross site scripting
1 year ago
A vulnerability, which was classified as problematic, has been found in Delower WP To Do Plugin up to 1.3.0 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-37539. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-37546 | biplob018 Image Hover Effects Plugin up to 3.0.2 on WordPress cross site scripting
1 year ago
A vulnerability has been found in biplob018 Image Hover Effects Plugin up to 3.0.2 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-37546. The attack can be initiated remotely. There is no exploit available.
vuldb.com