Aggregator
AWS CloudTrail在检测潜在安全威胁中的应用及最佳实践
1 year 6 months ago
安全客
针对 Android 和 iPhone 用户的新网络钓鱼方法
1 year 6 months ago
安全客
NIST最终确定量子加密新标准
1 year 6 months ago
美国国家标准与技术研究所选择了全球首批三种后量子加密算法作为其后量子安全策略的基础:ML-KEM、ML-DSA 和 SLH-DSA。
博通赛门铁克的研究人员发现了一个名为 Msupedge 的以前未被发现的后门
1 year 6 months ago
安全客
报告发现,四分之三的公司保留了越来越多的敏感数据
1 year 6 months ago
安全客
微软的托管 Azure Kubernetes Service(AKS)存在严重的特权升级漏洞
1 year 6 months ago
安全客
黑客利用PHP漏洞部署隐蔽的Msupedge后门
1 year 6 months ago
安全客
Oracle NetSuite 配置漏洞可能导致数据泄露
1 year 6 months ago
安全客
“源”聚创新力量,“洞”见安全未来:360漏洞云亮相GOGC,共促开源漏洞安全发展
1 year 6 months ago
安全客
捷克移动用户成为新银行凭证盗窃计划的目标
1 year 6 months ago
安全客
XCon2024完整版参会攻略,速速来看,果断收藏~~
1 year 6 months ago
距离XCon2024安全焦点信息安全技术峰会正式开幕仅剩1天
后台仍在不断激增的购票数量
也足见各位对本届XCon的热切期待~~
那今天小编就作为大会的前站路透官
为各位盘上一波XCon2024参会攻略~~
XCon组委会
CVE-2024-7998 | Octopus Server prior 2024.1.12931/2024.2.9313 OIDC Cookie session expiration
1 year 6 months ago
A vulnerability was found in Octopus Server. It has been rated as problematic. This issue affects some unknown processing of the component OIDC Cookie Handler. The manipulation leads to session expiration.
The identification of this vulnerability is CVE-2024-7998. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-7795 | Autel MaxiCharger AC Elite Business C50 AppAuthenExchangeRandomNum stack-based overflow (ZDI-24-1154)
1 year 6 months ago
A vulnerability was found in Autel MaxiCharger AC Elite Business C50. It has been declared as critical. This vulnerability affects the function AppAuthenExchangeRandomNum. The manipulation leads to stack-based buffer overflow.
This vulnerability was named CVE-2024-7795. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43440 | Moodle Block Backup Restore file inclusion
1 year 6 months ago
A vulnerability was found in Moodle. It has been classified as critical. This affects an unknown part of the component Block Backup Restore. The manipulation leads to file inclusion.
This vulnerability is uniquely identified as CVE-2024-43440. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-43439 | Moodle H5P Error Message cross site scripting
1 year 6 months ago
A vulnerability was found in Moodle and classified as problematic. Affected by this issue is some unknown functionality of the component H5P Error Message Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-43439. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-43438 | Moodle Feedback Non-Respondents Report resource injection
1 year 6 months ago
A vulnerability has been found in Moodle and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Feedback Non-Respondents Report. The manipulation leads to improper control of resource identifiers.
This vulnerability is known as CVE-2024-43438. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-43437 | Moodle Backup File Restore cross site scripting
1 year 6 months ago
A vulnerability, which was classified as problematic, was found in Moodle. Affected is an unknown function of the component Backup File Restore. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-43437. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-43436 | Moodle XMLDB Editor sql injection
1 year 6 months ago
A vulnerability, which was classified as critical, has been found in Moodle. This issue affects some unknown processing of the component XMLDB Editor. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2024-43436. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-43435 | Moodle Global Glossary improper authorization
1 year 6 months ago
A vulnerability classified as problematic was found in Moodle. This vulnerability affects unknown code of the component Global Glossary Handler. The manipulation leads to improper authorization.
This vulnerability was named CVE-2024-43435. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com