Aggregator
Please support the site operations by clicking ads.
Polyglot漏洞浅析
1 year 2 months ago
Polyglot漏洞浅析
1Panel 代理证书验证绕过导致任意命令执行漏洞(CVE-2025-54424)
1 year 2 months ago
1Panel 代理证书验证绕过导致任意命令执行漏洞(CVE-2025-54424)
调查性报道
1 year 2 months ago
记者,有责任推开一扇扇紧闭的门
CVE-2024-1881 | significant-gravitas AutoGPT up to 5.0.x os command injection
1 year 2 months ago
A vulnerability was found in significant-gravitas AutoGPT up to 5.0.x. It has been classified as critical. This affects an unknown part. The manipulation leads to os command injection.
This vulnerability is uniquely identified as CVE-2024-1881. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6091 | significant-gravitas AutoGPT up to 0.5.0 Denylist Setting os command injection
1 year 2 months ago
A vulnerability, which was classified as critical, was found in significant-gravitas AutoGPT up to 0.5.0. Affected is an unknown function of the component Denylist Setting Handler. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2024-6091. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-13041 | GitLab Community Edition/Enterprise Edition up to 17.5.4/17.6.2/17.7.0 incorrect user management (Nessus ID 213635)
1 year 2 months ago
A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 17.5.4/17.6.2/17.7.0. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to incorrect user management.
The identification of this vulnerability is CVE-2024-13041. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-54418 | CodeIgniter up to 4.6.1 Image os command injection (GHSA-9952-gv64-x94c)
1 year 2 months ago
A vulnerability was found in CodeIgniter up to 4.6.1. It has been rated as critical. Affected by this issue is some unknown functionality of the component Image Handler. The manipulation leads to os command injection.
This vulnerability is handled as CVE-2025-54418. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-53944 | Significant-Gravitas AutoGPT up to 0.6.15 get_graph_execution_results graph_exec_id improper authorization (GHSA-x77j-qg2x-fgg6)
1 year 2 months ago
A vulnerability, which was classified as critical, has been found in Significant-Gravitas AutoGPT up to 0.6.15. Affected by this issue is the function get_graph_execution_results. The manipulation of the argument graph_exec_id leads to improper authorization.
This vulnerability is handled as CVE-2025-53944. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-8499 | code-projects Online Medicine Guide 1.0 /cusfindambulence2.php Search sql injection (EUVD-2025-23467)
1 year 2 months ago
A vulnerability was found in code-projects Online Medicine Guide 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /cusfindambulence2.php. The manipulation of the argument Search leads to sql injection.
This vulnerability was named CVE-2025-8499. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-8500 | code-projects Human Resource Integrated System 1.0 action.php content sql injection (EUVD-2025-23466)
1 year 2 months ago
A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /insert-and-view/action.php. The manipulation of the argument content leads to sql injection.
The identification of this vulnerability is CVE-2025-8500. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-8501 | code-projects Human Resource Integrated System 1.0 action.php content cross site scripting (EUVD-2025-23468)
1 year 2 months ago
A vulnerability classified as problematic has been found in code-projects Human Resource Integrated System 1.0. Affected is an unknown function of the file /insert-and-view/action.php. The manipulation of the argument content leads to cross site scripting.
This vulnerability is traded as CVE-2025-8501. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-8502 | code-projects Online Medicine Guide 1.0 /changepass.php ups sql injection (EUVD-2025-23470)
1 year 2 months ago
A vulnerability classified as critical was found in code-projects Online Medicine Guide 1.0. Affected by this vulnerability is an unknown functionality of the file /changepass.php. The manipulation of the argument ups leads to sql injection.
This vulnerability is known as CVE-2025-8502. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-53537 | OISF libhtp up to 0.5.50 suricata.yaml memory leak (EUVD-2025-22472)
1 year 2 months ago
A vulnerability classified as problematic has been found in OISF libhtp up to 0.5.50. This affects an unknown part of the file suricata.yaml. The manipulation leads to memory leak.
This vulnerability is uniquely identified as CVE-2025-53537. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-31401 | Cybozu Garoon up to 5.15.2 cross site scripting
1 year 2 months ago
A vulnerability was found in Cybozu Garoon up to 5.15.2. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-31401. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-8156 | significant-gravitas autogpt up to 0.5.0 Pull Request workflow-checker.yml code injection
1 year 2 months ago
A vulnerability, which was classified as critical, has been found in significant-gravitas autogpt up to 0.5.0. This issue affects some unknown processing of the file workflow-checker.yml of the component Pull Request Handler. The manipulation leads to code injection.
The identification of this vulnerability is CVE-2024-8156. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6324 | GitLab Community Edition/Enterprise Edition up to 17.5.4/17.6.2/17.7.0 algorithmic complexity (Issue 468914 / Nessus ID 213595)
1 year 2 months ago
A vulnerability has been found in GitLab Community Edition and Enterprise Edition up to 17.5.4/17.6.2/17.7.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to inefficient algorithmic complexity.
This vulnerability is known as CVE-2024-6324. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-12431 | GitLab Community Edition/Enterprise Edition up to 17.5.4/17.6.2/17.7.0 Public Project authorization (Nessus ID 213577)
1 year 2 months ago
A vulnerability has been found in GitLab Community Edition and Enterprise Edition up to 17.5.4/17.6.2/17.7.0 and classified as problematic. This vulnerability affects unknown code of the component Public Project Handler. The manipulation leads to missing authorization.
This vulnerability was named CVE-2024-12431. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-4853 | Wireshark up to 3.6.22/4.0.14/4.2.4 editcap mismatched memory management routines (ID 19724 / Nessus ID 207910)
1 year 2 months ago
A vulnerability has been found in Wireshark up to 3.6.22/4.0.14/4.2.4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component editcap. The manipulation leads to mismatched memory management routines.
This vulnerability is known as CVE-2024-4853. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Dell security advisory (AV25-479)
1 year 2 months ago
Canadian Centre for Cyber Security