Aggregator
在 Windows 版 Apache Subversion 中发现代码执行漏洞(CVE-2024-45720)
11 months 2 weeks ago
安全客
「推安早报」1010 | 近期漏洞、红蓝工具
11 months 2 weeks ago
涵盖CUPS打印系统、恶意软件虚拟化、Exchange PowerShell等多领域漏洞,以及Active Directory检测、Zimbra邮件平台远程命令执行等关键威胁
Миллионы вакансий и тысячи безработных: темная сторона индустрии ИБ
11 months 2 weeks ago
Почему поиск работы становится невыполнимой миссией?
CVE-2024-38348 | CodeProjects Health Care Hospital Management System 1.0 Staff Info Module searvalu sql injection
11 months 2 weeks ago
A vulnerability classified as critical was found in CodeProjects Health Care Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the component Staff Info Module. The manipulation of the argument searvalu leads to sql injection.
This vulnerability is known as CVE-2024-38348. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-9021 | Relevanssi Plugin up to 4.23.0 on WordPress cross site scripting
11 months 2 weeks ago
A vulnerability was found in Relevanssi Plugin up to 4.23.0 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-9021. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8983 | Custom Twitter Feeds Plugin up to 2.2.2 on WordPress Setting cross site scripting
11 months 2 weeks ago
A vulnerability classified as problematic was found in Custom Twitter Feeds Plugin up to 2.2.2 on WordPress. Affected by this vulnerability is an unknown functionality of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-8983. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47823 | Livewire up to 3.5.1 getClientOriginalName unrestricted upload (GHSA-f3cx-396f-7jqp)
11 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in Livewire up to 3.5.1. This issue affects the function getClientOriginalName. The manipulation leads to unrestricted upload.
The identification of this vulnerability is CVE-2024-47823. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9379 | Ivanti Cloud Services Appliance up to 5.0.1 Admin Web Console sql injection
11 months 2 weeks ago
A vulnerability classified as critical was found in Ivanti Cloud Services Appliance up to 5.0.1. Affected by this vulnerability is an unknown functionality of the component Admin Web Console. The manipulation leads to sql injection.
This vulnerability is known as CVE-2024-9379. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9568 | D-Link DIR-619L B1 2.06 /goform/formAdvNetwork curTime buffer overflow
11 months 2 weeks ago
A vulnerability, which was classified as critical, was found in D-Link DIR-619L B1 2.06. Affected is the function formAdvNetwork of the file /goform/formAdvNetwork. The manipulation of the argument curTime leads to buffer overflow. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is traded as CVE-2024-9568. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-9569 | D-Link DIR-619L B1 2.06 formEasySetPassword curTime buffer overflow
11 months 2 weeks ago
A vulnerability has been found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this vulnerability is the function formEasySetPassword of the file /goform/formEasySetPassword. The manipulation of the argument curTime leads to buffer overflow. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is known as CVE-2024-9569. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Palo Alto Networks 的 GlobalProtect MSI 安装程序存在本地权限提升漏洞
11 months 2 weeks ago
安全客
Без связи и навигации: Земля на пути мощного геомагнитного шторма
11 months 2 weeks ago
Солнце решило проверить на прочность нашу планету, атаковав сразу несколькими способами.
Internet Archive Breached, 31 Million Records Exposed
11 months 2 weeks ago
The non-profit digital library was also hit by at least two DDoS attacks in two days
U.S. CISA adds Ivanti CSA and Fortinet bugs to its Known Exploited Vulnerabilities catalog
11 months 2 weeks ago
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Ivanti CSA and Fortinet bugs to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: This week, Fortinet addressed a critical flaw in FortiOS, tracked as CVE-2024-23113 (CVSS score 9.8). The issue if […]
Pierluigi Paganini
CVE-2014-7546 | Buddhist Prayer 3 X.509 Certificate cryptographic issues (VU#582497)
11 months 2 weeks ago
A vulnerability was found in Buddhist Prayer 3. It has been classified as critical. This affects an unknown part of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is uniquely identified as CVE-2014-7546. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
Смартфон толщиной с кредитку: новые батареи для сверхлегких гаджетов и электромобилей
11 months 2 weeks ago
Исследователи представили новый аккумулятор из углеродного волокна.
CVE-2024-48902 | JetBrains YouTrack up to 2024.3.44799 Project Update authorization
11 months 2 weeks ago
A vulnerability was found in JetBrains YouTrack. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Project Update Handler. The manipulation leads to missing authorization.
This vulnerability is handled as CVE-2024-48902. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45149 | Adobe Commerce up to 2.4.7-p2/2.4.6-p7/2.4.5-p9/2.4.4-p10 access control (apsb24-73)
11 months 2 weeks ago
A vulnerability was found in Adobe Commerce up to 2.4.7-p2/2.4.6-p7/2.4.5-p9/2.4.4-p10. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2024-45149. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45148 | Adobe Commerce up to 2.4.7-p2/2.4.6-p7/2.4.5-p9/2.4.4-p10 improper authentication (apsb24-73)
11 months 2 weeks ago
A vulnerability was found in Adobe Commerce up to 2.4.7-p2/2.4.6-p7/2.4.5-p9/2.4.4-p10. It has been classified as critical. Affected is an unknown function. The manipulation leads to improper authentication.
This vulnerability is traded as CVE-2024-45148. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com