Aggregator
Meow
1 year 6 months ago
cohenido
CVE-2024-44893 | jeecg-boot JimuReport 1.7.8 GET Request list Privilege Escalation
1 year 6 months ago
A vulnerability classified as critical has been found in jeecg-boot JimuReport 1.7.8. This affects an unknown part of the file /jeecg-boot/jmreport/dict/list of the component GET Request Handler. The manipulation leads to Privilege Escalation.
This vulnerability is uniquely identified as CVE-2024-44893. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2023-36103 | Tenda AC15 15.03.05.20 POST Request goform/SetIPTVCfg command injection
1 year 6 months ago
A vulnerability was found in Tenda AC15 15.03.05.20. It has been rated as critical. Affected by this issue is some unknown functionality of the file goform/SetIPTVCfg of the component POST Request Handler. The manipulation leads to command injection.
This vulnerability is handled as CVE-2023-36103. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-45591 | xwiki-platform up to 15.10.8/16.3.0-rc-0 REST API history authorization (GHSA-pvmm-55r5-g3mm)
1 year 6 months ago
A vulnerability was found in xwiki-platform up to 15.10.8/16.3.0-rc-0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /xwiki/rest/wikis/xwiki/spaces/Main/pages/WebHome/history of the component REST API. The manipulation leads to missing authorization.
This vulnerability is known as CVE-2024-45591. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45590 | expressjs body-parser up to 1.20.2 amplification (GHSA-qwcr-r2fm-qrc7)
1 year 6 months ago
A vulnerability was found in expressjs body-parser up to 1.20.2. It has been classified as critical. Affected is an unknown function. The manipulation leads to asymmetric resource consumption.
This vulnerability is traded as CVE-2024-45590. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45592 | DamienHarper auditor-bundle up to 5.x Twig Macro source_label cross site scripting (GHSA-78vg-7v27-hj67)
1 year 6 months ago
A vulnerability was found in DamienHarper auditor-bundle up to 5.x and classified as problematic. This issue affects some unknown processing of the component Twig Macro Handler. The manipulation of the argument source_label leads to cross site scripting.
The identification of this vulnerability is CVE-2024-45592. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-6841 | Red Hat Quarkus HTTP Request extra values
1 year 6 months ago
A vulnerability, which was classified as critical, was found in Red Hat Quarkus, JBoss Fuse, Mobile Application Platform, OpenShift Application Runtimes, Process Automation, Single Sign-On and Support for Spring Boot. This affects an unknown part of the component HTTP Request Handler. The manipulation leads to improper handling of extra values.
This vulnerability is uniquely identified as CVE-2023-6841. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-45595 | man-group dtale up to 3.14.0 cross site scripting (GHSA-pw44-4h99-wqff)
1 year 6 months ago
A vulnerability has been found in man-group dtale up to 3.14.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-45595. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Как заправить электромобиль бесплатно? Подсказали хакеры с Pwn2Own
1 year 6 months ago
Уязвимость в Autel MaxiCharger не требует от атакующего особых навыков или оборудования.
CVE-2024-8232 | iniNet Solutions SpiderControl SCADA Web Server up to 2.09 File unrestricted upload (icsa-24-254-02)
1 year 6 months ago
A vulnerability, which was classified as critical, has been found in iniNet Solutions SpiderControl SCADA Web Server up to 2.09. Affected by this issue is some unknown functionality of the component File Handler. The manipulation leads to unrestricted upload.
This vulnerability is handled as CVE-2024-8232. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-7721 | HTML5 Video Player Plugin up to 2.5.34 on WordPress Options Update authorization
1 year 6 months ago
A vulnerability classified as problematic was found in HTML5 Video Player Plugin up to 2.5.34 on WordPress. Affected by this vulnerability is an unknown functionality of the component Options Update Handler. The manipulation leads to missing authorization.
This vulnerability is known as CVE-2024-7721. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-8253 | Post Grid and Gutenberg Blocks Plugin 2.2.87/2.2.88/2.2.89/2.2.90 on WordPress Privilege Escalation
1 year 6 months ago
A vulnerability classified as critical has been found in Post Grid and Gutenberg Blocks Plugin 2.2.87/2.2.88/2.2.89/2.2.90 on WordPress. Affected is an unknown function. The manipulation leads to Privilege Escalation.
This vulnerability is traded as CVE-2024-8253. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-7727 | HTML5 Video Player Plugin up to 2.5.32 on WordPress h5vp_ajax_handler authorization
1 year 6 months ago
A vulnerability was found in HTML5 Video Player Plugin up to 2.5.32 on WordPress. It has been rated as critical. This issue affects the function h5vp_ajax_handler. The manipulation leads to missing authorization.
The identification of this vulnerability is CVE-2024-7727. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-44677 | eladmin up to 2.7 DatabaseController.java server-side request forgery
1 year 6 months ago
A vulnerability was found in eladmin up to 2.7. It has been declared as critical. This vulnerability affects unknown code of the file DatabaseController.java. The manipulation leads to server-side request forgery.
This vulnerability was named CVE-2024-44677. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2023-37234 | Loftware Spectrum up to 4.6 JMX Registry access control
1 year 6 months ago
A vulnerability was found in Loftware Spectrum up to 4.6. It has been classified as critical. This affects an unknown part of the component JMX Registry Handler. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2023-37234. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-45593 | NixOS nix up to 2.24.5 NAR path traversal (GHSA-h4vv-h3jq-v493)
1 year 6 months ago
A vulnerability was found in NixOS nix up to 2.24.5 and classified as critical. Affected by this issue is some unknown functionality of the component NAR Handler. The manipulation leads to path traversal.
This vulnerability is handled as CVE-2024-45593. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Highline Public Schools Forced to Close By Cyber-Attack
1 year 6 months ago
Highline Public Schools in Washington State have now been closed for two days following the incident
Тихий свидетель: смарт-колонки выдают информацию полиции
1 year 6 months ago
Amazon Echo знает больше, чем кажется.
Akira
1 year 6 months ago
cohenido