作者:0x7F@知道创宇404实验室
日期:2025年2月17日
1. 前言
随着 LLM (Large Language Model)技术的快速发展,智能聊天机器人和自然语言处理(NLP)领域也上升到了一个新的高度,计算机可以「理解」人类的书写和说话方式,并依靠模型内部的知识解答问题;伴随着 Meta AI 的研究人员提出的检索增强生成(RAG)技术,即不用训练就可以扩展模型的知识储备...
A vulnerability, which was classified as problematic, was found in phpcmsv9 9.6.3. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-25958. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability, which was classified as problematic, has been found in Ajax Search Lite Plugin up to 4.12.4 on WordPress. Affected by this issue is some unknown functionality of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-13585. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic was found in WP Carousel Plugin up to 2.7.3 on WordPress. Affected by this vulnerability is an unknown functionality of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-13314. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in amothemo AMO Team Showcase Plugin up to 1.1.4 on WordPress. Affected is the function amoteam_skills of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-1407. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability was found in s56bouya Newpost Catch Plugin up to 1.3.19 on WordPress. It has been rated as problematic. This issue affects the function npc of the component Shortcode Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-1406. The attack may be initiated remotely. There is no exploit available.
A vulnerability was found in victorfreitas WPUpper Share Buttons Plugin up to 3.51 on WordPress. It has been declared as problematic. This vulnerability affects the function save_custom_css_request. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2024-13883. The attack can be initiated remotely. There is no exploit available.
A vulnerability was found in ttoomey C9 Admin Dashboard Plugin up to 1.3.5 on WordPress. It has been classified as problematic. This affects an unknown part of the component SVG File Upload. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-13379. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in labibahmed42 3D Photo Gallery Plugin up to 1.3 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument des[] leads to cross site scripting.
This vulnerability is handled as CVE-2024-13751. The attack may be launched remotely. There is no exploit available.
A vulnerability has been found in minicoursegenerator Mini Course Generator Plugin up to 1.0.5 on WordPress and classified as problematic. Affected by this vulnerability is the function mcg of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-13672. The attack can be launched remotely. There is no exploit available.
A vulnerability, which was classified as problematic, was found in tcoder TCBD Tooltip Plugin up to 1.0 on WordPress. Affected is the function tcbdtooltip_text of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-13388. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability, which was classified as critical, has been found in Tenda AC10 15.03.06.23. This issue affects the function formexeCommand of the component POST Request Handler. The manipulation of the argument cmdinput leads to command injection.
The identification of this vulnerability is CVE-2025-25675. The attack may be initiated remotely. There is no exploit available.
A vulnerability classified as critical was found in Tenda AC8V4 16.03.34.06. This vulnerability affects the function SUB_0046AC38 of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow.
This vulnerability was named CVE-2025-25663. The attack can be initiated remotely. There is no exploit available.
A vulnerability classified as critical has been found in Ivanti Connect Secure and Policy Secure up to 22.7. This affects an unknown part. The manipulation leads to file inclusion.
This vulnerability is uniquely identified as CVE-2024-38657. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in treeverse lakeFS up to 1.49.x. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Environment Variable Handler. The manipulation of the argument LAKEFS_BLOCKSTORE_S3_DISABLE_PRE_SIGNED_MULTIPART leads to resource consumption.
This vulnerability is handled as CVE-2025-27100. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Medixant RadiAnt DICOM Viewer 2024.02. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper certificate validation.
This vulnerability is known as CVE-2025-1001. Access to the local network is required for this attack to succeed. There is no exploit available.
A vulnerability was found in genetechproducts Registration Forms Plugin up to 3.8.3.9 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation leads to sensitive information in log files.
This vulnerability is traded as CVE-2024-13818. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability was found in Qibosoft QiboCMS X1 1.0 and classified as problematic. This issue affects the function http_curl of the file /application/common. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2025-22973. The attack may be initiated remotely. There is no exploit available.