Aggregator
Ivanti 云服务设备再遭攻击:新漏洞广泛利用,安全问题频发
1 year 8 months ago
安全客
威胁行为者在复杂的凭证窃取活动中利用与HR相关的钓鱼战术
1 year 8 months ago
安全客
黑客从亚洲加密平台 BingX 窃取了超过 4400 万美元
1 year 8 months ago
安全客
Sam Altman表示ChatGPT将带来难以想象的繁荣并解决气候问题
1 year 8 months ago
安全客
Windows Server 2025 将获得无需重启的热补丁选项
1 year 8 months ago
安全客
ESET 修复了其产品中的两个权限提升漏洞
1 year 8 months ago
安全客
新Necro特洛伊木马通过Google Play和非官方应用程序瞄准超过1100万台Android设备
1 year 8 months ago
安全客
WordPress 主题“Houzez”和相关插件漏洞暴露了数千个网站
1 year 8 months ago
安全客
开挂神器能让企业管理有多轻松?这才是真正的职场爽文
1 year 8 months ago
安全客
CVE-2024-36399 | Kanboard up to 1.2.36 URL Parameter ProjectPermissionController.php addUser project_id access control (GHSA-x8v7-3ghx-65cv)
1 year 8 months ago
A vulnerability has been found in Kanboard up to 1.2.36 and classified as critical. This vulnerability affects the function addUser of the file app/Controller/ProjectPermissionController.php of the component URL Parameter Handler. The manipulation of the argument project_id leads to improper access controls.
This vulnerability was named CVE-2024-36399. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-3404 | gaizhenbiao chuanhuchatgpt History File access control
1 year 8 months ago
A vulnerability classified as critical was found in gaizhenbiao chuanhuchatgpt. Affected by this vulnerability is an unknown functionality of the component History File Handler. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2024-3404. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-3234 | gaizhenbiao chuanhuchatgpt prior 20240305 web_assets path traversal
1 year 8 months ago
A vulnerability classified as critical was found in gaizhenbiao chuanhuchatgpt. Affected by this vulnerability is an unknown functionality of the file web_assets. The manipulation leads to path traversal.
This vulnerability is known as CVE-2024-3234. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-3402 | gaizhenbiao chuanhuchatgpt up to 20240121 cross site scripting
1 year 8 months ago
A vulnerability classified as problematic was found in gaizhenbiao chuanhuchatgpt up to 20240121. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-3402. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-5186 | imartinez privategpt up to 0.5.0 Requests path server-side request forgery
1 year 8 months ago
A vulnerability, which was classified as critical, has been found in imartinez privategpt up to 0.5.0. Affected by this issue is some unknown functionality of the component Requests Handler. The manipulation of the argument path leads to server-side request forgery.
This vulnerability is handled as CVE-2024-5186. The attack may be launched remotely. There is no exploit available.
vuldb.com
盛邦安全入选IDC《中国WAAP厂商技术能力评估,2024》报告,获满分评价!
1 year 8 months ago
盛邦安全
盛邦安全权小文:多源异构数据融合技术在威胁情报实战化趋势下将“大有可为”
1 year 8 months ago
盛邦安全
CVE-2008-6644 | DotNetNuke up to 4.8.3 Default.aspx cross site scripting (EDB-31865 / XFDB-42752)
1 year 8 months ago
A vulnerability classified as problematic has been found in DotNetNuke. Affected is an unknown function of the file Default.aspx. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2008-6644. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Generative AI Security: Getting ready for Salesforce Einstein Copilot
1 year 8 months ago
Salesforce's Einstein Copilot can provide insights and perform tasks help streamline daily processes. However, it also comes with risks that you should takes steps to mitigate. Learn more from Varonis on how to prepare for Salesforce Einstein Copilot, [...]
Sponsored by Varonis
CVE-2024-30368 | A10 Thunder ADC CsrRequestView command injection
1 year 8 months ago
A vulnerability has been found in A10 Thunder ADC and classified as critical. This vulnerability affects the function CsrRequestView. The manipulation leads to command injection.
This vulnerability was named CVE-2024-30368. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com