Aggregator
哪吒电影里的 “情报与安全” 密码,你看懂了吗?
1 year ago
CVE-2025-23715 | RaymondDesign Post & Page Notes Plugin up to 0.1.1 on WordPress cross-site request forgery
1 year ago
A vulnerability was found in RaymondDesign Post & Page Notes Plugin up to 0.1.1 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2025-23715. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-23710 | Mayur Sojitra Flying Twitter Birds Plugin up to 1.8 on WordPress cross-site request forgery
1 year ago
A vulnerability classified as problematic has been found in Mayur Sojitra Flying Twitter Birds Plugin up to 1.8 on WordPress. This affects an unknown part. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2025-23710. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-23713 | Artem Anikeev Hack Me If You Can Plugin up to 1.2 on WordPress cross-site request forgery
1 year ago
A vulnerability classified as problematic was found in Artem Anikeev Hack Me If You Can Plugin up to 1.2 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2025-23713. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-23712 | Kapost Plugin up to 2.2.9 on WordPress cross-site request forgery
1 year ago
A vulnerability, which was classified as problematic, has been found in Kapost Plugin up to 2.2.9 on WordPress. This issue affects some unknown processing. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2025-23712. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-23745 | Tussendoor Internet & Marketing Call me Now Plugin up to 1.0.5 on WordPress cross-site request forgery
1 year ago
A vulnerability, which was classified as problematic, was found in Tussendoor Internet & Marketing Call me Now Plugin up to 1.0.5 on WordPress. Affected is an unknown function. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2025-23745. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-23743 | Martijn Scheybeler Social Analytics Plugin up to 0.2 on WordPress cross-site request forgery
1 year ago
A vulnerability has been found in Martijn Scheybeler Social Analytics Plugin up to 0.2 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2025-23743. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-23749 | Mahdi Khaksar mybb Last Topics Plugin up to 1.0 on WordPress cross-site request forgery
1 year ago
A vulnerability was found in Mahdi Khaksar mybb Last Topics Plugin up to 1.0 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2025-23749. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-23793 | Turcu Ciprian Auto FTP Plugin up to 1.0.1 on WordPress cross-site request forgery
1 year ago
A vulnerability was found in Turcu Ciprian Auto FTP Plugin up to 1.0.1 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2025-23793. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-23801 | Benjamin Guy Style Admin Plugin up to 1.4.3 on WordPress cross-site request forgery
1 year ago
A vulnerability was found in Benjamin Guy Style Admin Plugin up to 1.4.3 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2025-23801. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-23765 | W3speedster Plugin up to 7.33 on WordPress cross-site request forgery
1 year ago
A vulnerability was found in W3speedster Plugin up to 7.33 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2025-23765. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2002-2425 | Sun Solaris Answerbook2 up to 1.4.2 Administrative Script AdminAddadmin access control (EDB-21677 / XFDB-9756)
1 year ago
A vulnerability was found in Sun Solaris Answerbook2 up to 1.4.2. It has been classified as critical. This affects an unknown part of the file AdminViewError/AdminAddadmin of the component Administrative Script. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2002-2425. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Beelzebub: Open-source honeypot framework
1 year ago
Beelzebub is an open-source honeypot framework engineered to create a secure environment for detecting and analyzing cyber threats. It features a low-code design for seamless deployment and leverages AI to emulate the behavior of a high-interaction honeypot. “I created Beelzebub because my research activities require deploying numerous honeypots from different families (e.g., WordPress, Joomla, SSH, MySQL). With Beelzebub, configuring and managing this is streamlined through simple YAML files, enabling rapid setup and scalability,” Mario Candela, … More →
The post Beelzebub: Open-source honeypot framework appeared first on Help Net Security.
Mirko Zorz
CVE-2020-25540 | ThinkAdmin V6 GET Request path traversal (EDB-48812)
1 year ago
A vulnerability was found in ThinkAdmin V6. It has been rated as critical. This issue affects some unknown processing. The manipulation as part of GET Request leads to path traversal.
The identification of this vulnerability is CVE-2020-25540. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
9 - CVE-2024-40890
1 year ago
Currently trending CVE - hypeScore: 1 - **UNSUPPORTED WHEN ASSIGNED**
A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected
8 - CVE-2025-23114
1 year ago
Currently trending CVE - hypeScore: 1 - A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected server. This issue occurs due to a failure to properly validate TLS certificate.
CVE-2025-23828 | OriginalTips WordPress Data Guard Plugin up to 8 on WordPress cross site scripting
1 year ago
A vulnerability, which was classified as problematic, has been found in OriginalTips WordPress Data Guard Plugin up to 8 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-23828. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-23842 | Nilesh Shiragave Gallery Plugin up to 1.4 on WordPress cross-site request forgery
1 year ago
A vulnerability, which was classified as problematic, was found in Nilesh Shiragave Gallery Plugin up to 1.4 on WordPress. Affected is an unknown function. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2025-23842. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2018-11784 | Oracle MICROS Retail XBRi Loss Prevention 10.8.0/10.8.1/10.8.2/10.8.3 Apache Tomcat redirect (EDB-50118 / Nessus ID 118036)
1 year ago
A vulnerability was found in Oracle MICROS Retail XBRi Loss Prevention 10.8.0/10.8.1/10.8.2/10.8.3. It has been rated as problematic. This issue affects some unknown processing of the component Apache Tomcat. The manipulation leads to open redirect.
The identification of this vulnerability is CVE-2018-11784. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com