Aggregator
CVE-2025-55746漏洞预警:Directus高危漏洞曝出 未授权文件上传可致服务器沦陷
1 month 1 week ago
安全客
CVE-2025-9288安全警报:热门JS库曝关键漏洞 全球网络安全受严重威胁
1 month 1 week ago
安全客
新型QUIC-LEAK漏洞曝光 攻击者可耗尽服务器内存引发拒绝服务攻击
1 month 1 week ago
安全客
首批智能体创新计划合作伙伴授牌 360以AI与安全优势上榜
1 month 1 week ago
安全客
IDC权威认证:360终端安全智能体获多维度五星满分评价领跑行业
1 month 1 week ago
安全客
$50 000 за головы хакеров? Оказалось, это всего лишь тщательно подготовленный обман
1 month 1 week ago
Липовое объявление о вознаграждении раскрывает тайное противостояние между группировками.
Interpol Arrests Over 1K Cybercriminals in 'Operation Serengeti 2.0'
1 month 1 week ago
The operation disrupted countless scams, and authorities seized a significant amount of evidence and recovered nearly $100 million in lost funds.
Kristina Beek
CVE-2024-36123 | StarCitizenTools mediawiki-skins-Citizen up to 2.15.x cross site scripting (GHSA-jhm6-qjhq-5mf9)
1 month 1 week ago
A vulnerability labeled as problematic has been found in StarCitizenTools mediawiki-skins-Citizen up to 2.15.x. This affects an unknown function. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2024-36123. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2022-1242 | Canonical Apport up to 2.20.x Socket input validation (USN-5427-1)
1 month 1 week ago
A vulnerability was found in Canonical Apport up to 2.20.x and classified as critical. Impacted is an unknown function of the component Socket Handler. Such manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2022-1242. The attack can only be initiated within the local network. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-0344 | leiyuxi cy-fast 1.0 /commpara/listData order sql injection
1 month 1 week ago
A vulnerability was found in leiyuxi cy-fast 1.0. It has been declared as critical. Impacted is the function listData of the file /commpara/listData. The manipulation of the argument order results in sql injection.
This vulnerability is identified as CVE-2025-0344. The attack can be executed remotely. Additionally, an exploit exists.
vuldb.com
CVE-2025-0345 | leiyuxi cy-fast 1.0 /sys/menu/listData order sql injection
1 month 1 week ago
A vulnerability was found in leiyuxi cy-fast 1.0. It has been rated as critical. The affected element is the function listData of the file /sys/menu/listData. This manipulation of the argument order causes sql injection.
This vulnerability is tracked as CVE-2025-0345. The attack is possible to be carried out remotely. Moreover, an exploit is present.
vuldb.com
CVE-2024-39760 | Wavlink AC3000 M33A8.V5030.210505 login.cgi set_sys_init restart_min_value command injection (TALOS-2024-2018)
1 month 1 week ago
A vulnerability categorized as critical has been discovered in Wavlink AC3000 M33A8.V5030.210505. This affects the function set_sys_init of the file login.cgi. Such manipulation of the argument restart_min_value leads to command injection.
This vulnerability is referenced as CVE-2024-39760. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2024-39759 | Wavlink AC3000 M33A8.V5030.210505 login.cgi set_sys_init restart_hour_value command injection (TALOS-2024-2018)
1 month 1 week ago
A vulnerability labeled as critical has been found in Wavlink AC3000 M33A8.V5030.210505. Affected is the function set_sys_init of the file login.cgi. Executing manipulation of the argument restart_hour_value can lead to command injection.
This vulnerability is tracked as CVE-2024-39759. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2024-29072 | Foxit Reader 2024.2.0.25138 access control (TALOS-2024-1989)
1 month 1 week ago
A vulnerability, which was classified as critical, has been found in Foxit Reader 2024.2.0.25138. The affected element is an unknown function. The manipulation leads to improper access controls.
This vulnerability is listed as CVE-2024-29072. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2024-52599 | Enalean Tuleap Community Edition/Tuleap Enterprise Edition Gantt Chart cross site scripting
1 month 1 week ago
A vulnerability was found in Enalean Tuleap Community Edition and Tuleap Enterprise Edition. It has been rated as problematic. The affected element is an unknown function of the component Gantt Chart. Performing manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2024-52599. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2024-13201 | wander-chu SpringBoot-Blog 1.0 Admin Attachment AttachtController.java upload File unrestricted upload
1 month 1 week ago
A vulnerability classified as critical has been found in wander-chu SpringBoot-Blog 1.0. This affects the function Upload of the file src/main/java/com/my/blog/website/controller/admin/AttachtController.java of the component Admin Attachment Handler. Performing manipulation of the argument File results in unrestricted upload.
This vulnerability was named CVE-2024-13201. The attack may be initiated remotely. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2024-13202 | wander-chu SpringBoot-Blog 1.0 Blog Article PageController.java modifiyArticle content cross site scripting
1 month 1 week ago
A vulnerability classified as problematic was found in wander-chu SpringBoot-Blog 1.0. This impacts the function modifiyArticle of the file src/main/java/com/my/blog/website/controller/admin/PageController.java of the component Blog Article Handler. Executing manipulation of the argument content can lead to cross site scripting.
The identification of this vulnerability is CVE-2024-13202. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-0333 | leiyuxi cy-fast 1.0 /sys/role/listData order sql injection
1 month 1 week ago
A vulnerability marked as critical has been reported in leiyuxi cy-fast 1.0. Affected by this issue is the function listData of the file /sys/role/listData. The manipulation of the argument order leads to sql injection.
This vulnerability is traded as CVE-2025-0333. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-0334 | leiyuxi cy-fast 1.0 /sys/user/listData order sql injection
1 month 1 week ago
A vulnerability described as critical has been identified in leiyuxi cy-fast 1.0. This affects the function listData of the file /sys/user/listData. The manipulation of the argument order results in sql injection.
This vulnerability is known as CVE-2025-0334. It is possible to launch the attack remotely. Furthermore, an exploit is available.
vuldb.com