Aggregator
【漏洞挖掘技巧】新手师傅从0到1如何挖洞
1 year 3 months ago
[Meachines] [Easy] Knife PHP 8.1.0-dev RCE+knife权限提升
1 year 3 months ago
#PHP 8.1.0-dev RCE #knife权限提升
CVE-2025-21716
1 year 3 months ago
Currently trending CVE - Hype Score: 1 - In the Linux kernel, the following vulnerability has been resolved:
vxlan: Fix uninit-value in vxlan_vnifilter_dump()
KMSAN reported an uninit-value access in vxlan_vnifilter_dump() [1].
If the length of the netlink message payload is less than
sizeof(struct tunnel_msg), ...
CVE-2025-21715
1 year 3 months ago
Currently trending CVE - Hype Score: 1 - In the Linux kernel, the following vulnerability has been resolved:
net: davicom: fix UAF in dm9000_drv_remove
dm is netdev private data and it cannot be
used after free_netdev() call. Using dm after free_netdev()
can cause UAF bug. Fix it by moving free_netdev() at the end of ...
CVE-2024-51506 | Tiki up to 27.0 Create a Wiki Pages description cross site scripting
1 year 3 months ago
A vulnerability has been found in Tiki up to 27.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Create a Wiki Pages. The manipulation of the argument description leads to cross site scripting.
This vulnerability is known as CVE-2024-51506. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-51507 | Tiki up to 27.0 External Wiki Name cross site scripting
1 year 3 months ago
A vulnerability was found in Tiki up to 27.0 and classified as problematic. Affected by this issue is some unknown functionality of the component External Wiki. The manipulation of the argument Name leads to cross site scripting.
This vulnerability is handled as CVE-2024-51507. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-51508 | Tiki up to 27.0 External Wiki Index cross site scripting
1 year 3 months ago
A vulnerability was found in Tiki up to 27.0. It has been classified as problematic. This affects an unknown part of the component External Wiki. The manipulation of the argument Index leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-51508. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-10233 | SMSAlert Plugin up to 3.7.5 on WordPress Shortcode sa_subscribe cross site scripting
1 year 3 months ago
A vulnerability has been found in SMSAlert Plugin up to 3.7.5 on WordPress and classified as problematic. This vulnerability affects the function sa_subscribe of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-10233. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-9505 | Beaver Builder Plugin up to 2.8.4.2 on WordPress Button Widget cross site scripting
1 year 3 months ago
A vulnerability was found in Beaver Builder Plugin up to 2.8.4.2 on WordPress. It has been declared as problematic. This vulnerability affects unknown code of the component Button Widget. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-9505. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-10226 | Arconix Shortcodes Plugin up to 2.1.13 on WordPress Shortcode box cross site scripting
1 year 3 months ago
A vulnerability was found in Arconix Shortcodes Plugin up to 2.1.13 on WordPress. It has been classified as problematic. Affected is the function box of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-10226. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-10181 | Newsletters Plugin up to 4.9.9.4 on WordPress Shortcode newsletters_video cross site scripting
1 year 3 months ago
A vulnerability was found in Newsletters Plugin up to 4.9.9.4 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function newsletters_video of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-10181. The attack can be launched remotely. There is no exploit available.
vuldb.com
[Meachines] [Easy] Spectra Wordpress Plugins Shell+initctl权限提升
1 year 3 months ago
#Wordpress Plugins Shell #initctl权限提升
语音识别之CapsWriter-Offline
1 year 3 months ago
我试了,很强大,快速、准确、省资源
CVE-2025-21694 | Linux Kernel up to 6.12.10 cond_resched denial of service (Nessus ID 216985)
1 year 3 months ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.12.10. Affected is the function cond_resched. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2025-21694. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
ICICS 2025 CFP
1 year 3 months ago
ICICS 2025, 中国计算机学会CCF C
ICICS 2025 CFP
1 year 3 months ago
ICICS 2025, 中国计算机学会CCF C
二维码钓鱼攻击的兴起:诈骗者如何利用二维码及如何防范
1 year 3 months ago
二维码钓鱼(quishing)正迅速兴起,诈骗者通过恶意二维码窃取信息、安装恶意软件或重定向至诈骗网站。
CVE-2006-1518 | MySQL up to 5.0.20 sql_base.cc open_table memory corruption (VU#602457 / EDB-1741)
1 year 3 months ago
A vulnerability classified as critical was found in MySQL. Affected by this vulnerability is the function open_table of the file sql_base.cc. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2006-1518. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-10185 | StreamWeasels YouTube Integration Plugin up to 1.3.2 on WordPress Shortcode sw-youtube-embed cross site scripting
1 year 3 months ago
A vulnerability was found in StreamWeasels YouTube Integration Plugin up to 1.3.2 on WordPress. It has been rated as problematic. Affected by this issue is the function sw-youtube-embed of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-10185. The attack may be launched remotely. There is no exploit available.
vuldb.com