Aggregator
39套.NET系统漏洞威胁情报(10.02更新)
国庆福利 | .NET矩阵星球优惠券大放送
CVE-2024-35293 | Schneider Elektronik Series 700 up to 0.1.17.6 missing authentication
CVE-2024-35294 | Schneider Elektronik Series 700 up to 0.1.17.6 missing authentication
CVE-2024-8038 | Canonical Juju up to 2.9.50/3.1.9/3.3.6/3.4.5/3.5.3 Unix Domain Socket unprotected alternate channel (GHSA-xwgj-vpm9-q2rq)
CVE-2024-8037 | Canonical Juju up to 2.9.50/3.1.9/3.3.6/3.4.5/3.5.3 Unix Domain Socket agent.socket Local Privilege Escalation (GHSA-8v4w-f4r9-7h6x)
因机房网络故障,目前论坛出现间歇性无法访问的情况。机房正在积极处理此问题,给大家带来的不便我们深表歉意,感谢大家的理解与支持。
CVE-2024-7558 | Canonical Juju up to 2.9.50/3.1.9/3.3.6/3.4.5/3.5.3 JUJU_CONTEXT_ID weak credentials (GHSA-mh98-763h-m9v4)
CVE-2024-44030 | Mestres do WP Checkout Mestres WP Plugin up to 8.6 on WordPress path traversal
CVE-2024-44017 | MinHyeong Lim MH Board Plugin up to 1.3.2.1 on WordPress path traversal
Microsoft blocks Windows 11 24H2 on some Intel PCs over BSOD issues
CVE-2014-7327 | magzter Macau Business 3 X.509 Certificate cryptographic issues (VU#582497)
如何使用 pip 安装 requirements.txt 文件中的依赖包,以及如何生成 requirements.txt
Alert: Adobe Commerce and Magento Stores Under Attack from CosmicSting Exploit
Роботы разрушили мир: что нас ждёт в «The Electric State»?
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.
- CVE-2024-29824 Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.