Aggregator
CVE-2018-14592 | CWJoomla CW Article Attachments PRO Extension up to 2.0.6 on Joomla download.php sql injection (EDB-45447)
3 months 1 week ago
A vulnerability, which was classified as critical, was found in CWJoomla CW Article Attachments PRO Extension and CW Article Attachments FREE Extension up to 2.0.6 on Joomla. Affected is an unknown function of the file download.php. The manipulation leads to sql injection.
This vulnerability is traded as CVE-2018-14592. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2005-3237 | Cyphor 0.19 footer.php t_login cross site scripting (EDB-26339 / XFDB-22550)
3 months 1 week ago
A vulnerability was found in Cyphor 0.19 and classified as problematic. This issue affects some unknown processing of the file footer.php. The manipulation of the argument t_login leads to basic cross site scripting.
The identification of this vulnerability is CVE-2005-3237. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2010-3695 | Horde IMP up to 4.3.7 fetchmailprefs.php fm_id cross site scripting (Bug 641069 / EDB-34773)
3 months 1 week ago
A vulnerability, which was classified as problematic, was found in Horde IMP. This affects an unknown part of the file fetchmailprefs.php. The manipulation of the argument fm_id leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2010-3695. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
绕过无 Python 环境,红队通过 Sharp4Python 执行脚本和命令
3 months 1 week ago
.NET 内网攻防实战电子报刊
3 months 1 week ago
01.NET内网安全攻防报刊小报童电子报刊【.NET内网安全攻防】也正式上线了,引入小报童也是为了弥补知识星球
.NET 2025年第 75 期工具库和资源汇总
3 months 1 week ago
CVE-2007-0056 | Ashopsoftware AShop Administration Panel 4.5 ashop/catalogue.php resultpage cross site scripting (EDB-29378 / XFDB-31178)
3 months 1 week ago
A vulnerability, which was classified as problematic, has been found in Ashopsoftware AShop Administration Panel 4.5. Affected by this issue is some unknown functionality of the file ashop/catalogue.php of the component Administration Panel. The manipulation of the argument resultpage leads to basic cross site scripting.
This vulnerability is handled as CVE-2007-0056. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-2378 | Jtr Jax FormMailer 3.0.0 formmailer.admin.inc.php BASE_DIR[jax_formmailer] code injection (EDB-9051 / XFDB-51443)
3 months 1 week ago
A vulnerability was found in Jtr Jax FormMailer 3.0.0. It has been rated as critical. This issue affects some unknown processing of the file formmailer.admin.inc.php. The manipulation of the argument BASE_DIR[jax_formmailer] leads to code injection.
The identification of this vulnerability is CVE-2009-2378. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2006-1090 | PunBB 1.2.10 register.php denial of service (EDB-1517 / XFDB-24837)
3 months 1 week ago
A vulnerability classified as critical has been found in PunBB 1.2.10. This affects an unknown part of the file register.php. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2006-1090. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-9994 | Essential Addons for Elementor Plugin up to 6.1.12 on WordPress Pricing Table Widget eael_pricing_item_tooltip_content cross site scripting (EUVD-2024-54656)
3 months 1 week ago
A vulnerability was found in Essential Addons for Elementor Plugin up to 6.1.12 on WordPress. It has been classified as problematic. Affected is an unknown function of the component Pricing Table Widget. The manipulation of the argument eael_pricing_item_tooltip_content leads to cross site scripting.
This vulnerability is traded as CVE-2024-9994. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-9993 | Essential Addons for Elementor Plugin up to 6.1.12 on WordPress Event Calendar Widget eael_event_details_text cross site scripting (EUVD-2024-54655)
3 months 1 week ago
A vulnerability was found in Essential Addons for Elementor Plugin up to 6.1.12 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Event Calendar Widget. The manipulation of the argument eael_event_details_text leads to cross site scripting.
This vulnerability is known as CVE-2024-9993. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-5528 | Social Sharing Plugin Plugin up to 3.3.75 on WordPress heateor_mastodon_share cross site scripting (EUVD-2025-17373)
3 months 1 week ago
A vulnerability classified as problematic has been found in Social Sharing Plugin Plugin up to 3.3.75 on WordPress. This affects an unknown part. The manipulation of the argument heateor_mastodon_share leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-5528. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
逆向SSO登录加密
3 months 1 week ago
CVE-2000-0046 | Mirabilis ICQ 0.99b 1.1.1.1 Message URL memory corruption (EDB-19724 / Nessus ID 11572)
3 months 1 week ago
A vulnerability classified as critical was found in Mirabilis ICQ 0.99b 1.1.1.1. This vulnerability affects unknown code of the component Message Handler. The manipulation as part of URL leads to memory corruption.
This vulnerability was named CVE-2000-0046. The attack can be initiated remotely. Furthermore, there is an exploit available. This vulnerability has a historic impact due to its background and reception.
It is recommended to upgrade the affected component.
vuldb.com
Пучок кальция, лютециевая мишень и чуть удачи: в Китае родился протактий-210
3 months 1 week ago
Физики нашли предел существования вещества — и он тоньше, чем ожидалось.
CVE-2013-3893 | Microsoft Internet Explorer up to 11 HTML Rendering Engine mshtml.dll CDoc::SetMouseCapture location.href resource management (MS13-080 / EDB-49872)
3 months 1 week ago
A vulnerability was found in Microsoft Internet Explorer up to 11. It has been rated as very critical. This issue affects the function CDoc::SetMouseCapture in the library mshtml.dll of the component HTML Rendering Engine. The manipulation of the argument location.href with the input ms-help:// leads to improper resource management.
The identification of this vulnerability is CVE-2013-3893. The attack may be initiated remotely. Furthermore, there is an exploit available. Due to its background and reception, this vulnerability has an historic impact.
It is recommended to apply a patch to fix this issue.
vuldb.com
175 тысяч ядер, 2,3 ТБ ОЗУ и 0 жёстких дисков: как устроен SpiNNaker 2
3 months 1 week ago
Почему будущее вычислений — это не скорость, а структура.
CVE-2006-1549 | PHP 4.4.2/5.1.2 resource management (EDB-29693 / Nessus ID 31649)
3 months 1 week ago
A vulnerability was found in PHP 4.4.2/5.1.2. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to improper resource management.
This vulnerability was named CVE-2006-1549. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-4328 | EasyRealtorPRO 2008 site_search.php sql injection (EDB-32418 / XFDB-45418)
3 months 1 week ago
A vulnerability was found in EasyRealtorPRO 2008. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file site_search.php. The manipulation leads to sql injection.
This vulnerability is known as CVE-2008-4328. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com