Aggregator
.NET 一款替代cmd.exe的交互式命令渗透工具
1 year 4 months ago
双十一狂欢,.NET安全矩阵星球优惠来袭!
1 year 4 months ago
CVE-2024-51626 | Mansur Ahamed Woocommerce Quote Calculator Plugin up to 1.1 on WordPress sql injection
1 year 4 months ago
A vulnerability has been found in Mansur Ahamed Woocommerce Quote Calculator Plugin up to 1.1 on WordPress and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection.
This vulnerability is known as CVE-2024-51626. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-51672 | WPDeveloper BetterLinks Plugin up to 2.1.7 on WordPress sql injection
1 year 4 months ago
A vulnerability, which was classified as critical, has been found in WPDeveloper BetterLinks Plugin up to 2.1.7 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2024-51672. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-51665 | Noor Alam Magical Addons For Elementor Plugin up to 1.2.1 on WordPress server-side request forgery
1 year 4 months ago
A vulnerability was found in Noor Alam Magical Addons For Elementor Plugin up to 1.2.1 on WordPress. It has been classified as critical. This affects an unknown part. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2024-51665. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-48050 | agentscope up to 0.0.4 workflow_utils.py is_callable_expression behavioral workflow
1 year 4 months ago
A vulnerability, which was classified as critical, was found in agentscope up to 0.0.4. Affected is the function is_callable_expression of the file agentscope\web\workstation\workflow_utils.py. The manipulation leads to enforcement of behavioral workflow.
This vulnerability is traded as CVE-2024-48050. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-48052 | Gradio up to 4.42.0 gr.DownloadButton server-side request forgery
1 year 4 months ago
A vulnerability was found in Gradio up to 4.42.0 and classified as critical. Affected by this issue is the function gr.DownloadButton. The manipulation leads to server-side request forgery.
This vulnerability is handled as CVE-2024-48052. It is possible to launch the attack on the local host. There is no exploit available.
vuldb.com
CVE-2016-1850 | Apple Mac OS X up to 10.11.4 SceneKit memory corruption (HT206567 / Nessus ID 91228)
1 year 4 months ago
A vulnerability classified as critical has been found in Apple Mac OS X up to 10.11.4. This affects an unknown part of the component SceneKit. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2016-1850. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
安全隐患层出不穷,移动存储介质防护该从何入手?
1 year 4 months ago
工控生产环境移动存储介质接入的闭环管控。
智能化软件开发微访谈·第三十五期 神经符号融合软件
1 year 4 months ago
本次微访谈于11月5日举行,邀请了8位来自国内外高校的学术界专家分享自己的观点和看法。
2024第四届“网鼎杯”玄武组 writeup
1 year 4 months ago
Smashing Security podcast #392: Pasta spies and private eyes, and are you applying for a ghost job?
1 year 4 months ago
Skip to content
Скрытая угроза в Teams и SharePoint: как атака VEILDrive ударила по инфраструктуре США
1 year 4 months ago
Кибербандиты явились оттуда, откуда их никто не ждал.
D-Link NAS Command Injection(CVE-2024-10914、CVE-2024-10915)
1 year 4 months ago
D-Link NAS Command Injection(CVE-2024-10914、CVE-2024-10915)
自动升级Docker容器
1 year 4 months ago
我有一些自托管软件,都是以Docker容器的形式运行的。之前都是隔段时间手动升级,不够方便。因此花了点时间写了一个
Windows 记事本引入生成式 AI 功能
1 year 4 months ago
微软官方博客宣布,它向 Windows 11 预览版用户(Windows Insiders)推送了新版本的画图和记事本,为两款经典程序加入了流行的生成式 AI 功能。Paint (version 11.2410.28.0)加入了生成式填充(暂时仅限于 Copilot+ PC)和生成式擦除(所有用户);Image Creator in Paint 预览版提供给更多国家和地区(中国大陆不包括);Notepad (version 11.2410.15.0)支持在生成式 AI 帮助下重写内容,选择文本然后右键菜单里选择重写或者使用快捷键 Ctrl + I,该功能目前只提供给美国、法国、英国、加拿大、意大利和德国地区用户。
CVE-2023-5816 | Code Explorer Plugin up to 1.4.5 on WordPress information disclosure
1 year 4 months ago
A vulnerability was found in Code Explorer Plugin up to 1.4.5 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2023-5816. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-10491 | express up to 3.21.2 dynamic injection
1 year 4 months ago
A vulnerability was found in express up to 3.21.2 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument dynamic leads to injection.
This vulnerability is handled as CVE-2024-10491. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-50459 | HM Plugin Stripe Donation and Payment Plugin up to 3.2.3 on WordPress authorization
1 year 4 months ago
A vulnerability was found in HM Plugin Stripe Donation and Payment Plugin up to 3.2.3 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to missing authorization.
The identification of this vulnerability is CVE-2024-50459. The attack may be initiated remotely. There is no exploit available.
vuldb.com