Aggregator
Habitica 用游戏来养成你的习惯
1 year 8 months ago
介绍:
Habitica是一个开源的习惯构建程序,它将你的生活视为一个角色扮演游戏。当你成功完成你设定的目标时,你的角色将升级;当你失败时,你的角色将失去这个游戏中的HP;你还可以通过养成计划来...
黑海洋
CVE-2013-3307 | Linksys X3000 1.0.03 build 001 apply.cgi ping_ip/Add_Account_Password memory corruption (EDB-26415 / OSVDB-94518)
1 year 8 months ago
A vulnerability classified as very critical has been found in Linksys X3000 1.0.03 build 001. This affects the function ping_ip/Add_Account_Password of the file apply.cgi. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2013-3307. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
VDB-278247 | Backdoor.Win32.BlackAngel.13 Service Port 1850 backdoor
1 year 8 months ago
A vulnerability, which was classified as critical, was found in Backdoor.Win32.BlackAngel.13. This affects an unknown part of the component Service Port 1850. The manipulation leads to backdoor.
It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply restrictive firewalling.
vuldb.com
VDB-278246 | Backdoor.Win32.CCInvader.10 FTP Server improper authentication
1 year 8 months ago
A vulnerability, which was classified as critical, has been found in Backdoor.Win32.CCInvader.10. Affected by this issue is some unknown functionality of the component FTP Server. The manipulation leads to improper authentication.
The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to apply restrictive firewalling.
vuldb.com
VDB-278245 | Backdoor.Win32.Delf.yj Service Port 8080 information disclosure
1 year 8 months ago
A vulnerability classified as problematic was found in Backdoor.Win32.Delf.yj. Affected by this vulnerability is an unknown functionality of the component Service Port 8080. The manipulation leads to information disclosure.
The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to apply restrictive firewalling.
vuldb.com
Submit #409906: Backdoor.Win32.BlackAngel.13 d1523df44da5fd40df92602b8ded59c8 d1523df44da5fd40df92602b8ded59c8 Unauthenticated Remote Command Execution [Accepted]
1 year 8 months ago
Submit #409906 / VDB-278247
malvuln
CVE-2024-9077 | dingfangzu up to 29d67d9044f6f93378e6eb6ff92272217ff7225c Order Checkout scripts/order.js address-name cross site scripting
1 year 8 months ago
A vulnerability classified as problematic has been found in dingfangzu up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. Affected is an unknown function of the file scripts/order.js of the component Order Checkout. The manipulation of the argument address-name leads to cross site scripting.
This vulnerability is traded as CVE-2024-9077. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
vuldb.com
Submit #409905: Backdoor.Win32.CCInvader.10 cb86af8daa35f6977c80814ec6e40d63 cb86af8daa35f6977c80814ec6e40d63 Authentication Bypass [Accepted]
1 year 8 months ago
Submit #409905 / VDB-278246
malvuln
Submit #409904: Backdoor.Win32.Delf.yj f991c25f1f601cc8d14dca4737415238 f991c25f1f601cc8d14dca4737415238 Information Disclosure [Accepted]
1 year 8 months ago
Submit #409904 / VDB-278245
malvuln
CVE-2024-9076 | DedeCMS up to 5.7.115 article_string_mix.php os command injection
1 year 8 months ago
A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affects some unknown processing of the file article_string_mix.php. The manipulation leads to os command injection.
The identification of this vulnerability is CVE-2024-9076. The attack may be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
Submit #407527: GitHub dingfangzu 1 Basic Cross Site Scripting [Accepted]
1 year 8 months ago
Submit #407527 / VDB-278244
fjjwebray.com.cn
CVE-2024-9075 | Stirling-Tools Stirling-PDF up to 0.28.3 Markdown-to-PDF cross site scripting
1 year 8 months ago
A vulnerability was found in Stirling-Tools Stirling-PDF up to 0.28.3. It has been declared as problematic. This vulnerability affects unknown code of the component Markdown-to-PDF. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-9075. The attack can be initiated remotely. There is no exploit available.
The vendor explains that "this functionality was removed in 0.29.0 already" and "we plan to re-add at later date with issue resolved".
It is recommended to upgrade the affected component.
vuldb.com
От травм до краж: роботы Starship сеют хаос в университетском городке
1 year 8 months ago
Как робот-доставщик стал причиной несчастного случая?
Submit #407461: dedecms DedeCMS V5.7.115 rce [Accepted]
1 year 8 months ago
Submit #407461 / VDB-278243
Kuinyoe
CVE-2024-8680 | MailChimp Plugin up to 4.9.16 on WordPress cross site scripting
1 year 8 months ago
A vulnerability was found in MailChimp Plugin up to 4.9.16 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-8680. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
Submit #406335: Stirling-Tools Stirling-PDF - Cross Site Scripting [Accepted]
1 year 8 months ago
Submit #406335 / VDB-278242
nilesh
CVE-2024-42323 | Apache HertzBeat up to 1.5.x snakeYaml deserialization
1 year 8 months ago
A vulnerability was found in Apache HertzBeat up to 1.5.x and classified as critical. Affected by this issue is some unknown functionality of the component snakeYaml. The manipulation leads to deserialization.
This vulnerability is handled as CVE-2024-42323. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-6887 | EXPRESS 2.5.3 X.509 Certificate cryptographic issues (VU#582497)
1 year 8 months ago
A vulnerability classified as critical has been found in EXPRESS 2.5.3. Affected is an unknown function of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is traded as CVE-2014-6887. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
Play
1 year 8 months ago
cohenido