Aggregator
CVE-2024-9007 | jeanmarc77 123solar 1.8.4.5 /detailed.php date1 cross site scripting (Issue 73)
1 year 5 months ago
A vulnerability classified as problematic has been found in jeanmarc77 123solar 1.8.4.5. This affects an unknown part of the file /detailed.php. The manipulation of the argument date1 leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-9007. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-9006 | jeanmarc77 123solar 1.8.4.5 config/config_invt1.php PASSOx code injection (Issue 74)
1 year 5 months ago
A vulnerability was found in jeanmarc77 123solar 1.8.4.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file config/config_invt1.php. The manipulation of the argument PASSOx leads to code injection.
This vulnerability is handled as CVE-2024-9006. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
APIFinderPlus:JS响应信息提取工具内测
1 year 5 months ago
APIFinderPlus:JS响应信息提取工具内测
1 year 5 months ago
Google Password Manager now automatically syncs your passkeys
1 year 5 months ago
Google announced that starting today, passkeys added to Google Password Manager will automatically sync between Windows, macOS, Linux, Android, and ChromeOS devices for logged-in users. [...]
Sergiu Gatlan
SecWiki News 2024-09-19 Review
1 year 5 months ago
今日暂未更新资讯~
更多最新文章,请访问SecWiki
更多最新文章,请访问SecWiki
一次十分详细的漏洞挖掘记录,新思路+多个高危
1 year 5 months ago
[Meachines] [Medium] Jeeves Jenkins-RCE+KeePass-Crack+Pass-the-Hash+(NTFS)ADS攻击
1 year 5 months ago
#Jenkins-RCE #KeePass-Crack #Pass-the-Hash #(NTFS)ADS攻击
CVE-2024-45862 | Kastle Systems Access Control System cleartext storage (icsa-24-263-05)
1 year 5 months ago
A vulnerability was found in Kastle Systems Access Control System. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cleartext storage of sensitive information.
This vulnerability is known as CVE-2024-45862. The attack can be launched remotely. There is no exploit available.
This product is available as a managed service. Users are not able to maintain vulnerability countermeasures themselves.
vuldb.com
Submit #408299: 123Solar 1.8.4.5 Cross Site Scripting [Accepted]
1 year 5 months ago
Submit #408299 / VDB-278163
hejiasheng
Submit #408298: jeanmarc77 123Solar 1.8.4.5 Code Injection [Accepted]
1 year 5 months ago
Submit #408298 / VDB-278162
hejiasheng
CVE-2024-45861 | Kastle Systems Access Control System hard-coded credentials (icsa-24-263-05)
1 year 5 months ago
A vulnerability was found in Kastle Systems Access Control System. It has been classified as critical. Affected is an unknown function. The manipulation leads to hard-coded credentials.
This vulnerability is traded as CVE-2024-45861. It is possible to launch the attack remotely. There is no exploit available.
This product is a managed service. This means that users are not able to maintain vulnerability countermeasures themselves.
vuldb.com
CVE-2024-6404 | MegaSys Computer Technologies Telenium Online Web Application up to 8.3 HTTP code injection (icsa-24-263-04)
1 year 5 months ago
A vulnerability was found in MegaSys Computer Technologies Telenium Online Web Application up to 8.3 and classified as very critical. This issue affects some unknown processing of the component HTTP Handler. The manipulation leads to code injection.
The identification of this vulnerability is CVE-2024-6404. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Police dismantles phone unlocking ring linked to 483,000 victims
1 year 5 months ago
A joint law enforcement operation has dismantled an international criminal network that used the iServer automated phishing-as-a-service platform to unlock the stolen or lost mobile phones of 483,000 victims worldwide. [...]
Sergiu Gatlan
CVE-2024-41721 | FreeBSD bhyve out-of-bounds
1 year 5 months ago
A vulnerability has been found in FreeBSD and classified as critical. This vulnerability affects unknown code of the component bhyve. The manipulation leads to out-of-bounds read.
This vulnerability was named CVE-2024-41721. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
中国和全世界的排放可能提前达到峰值
1 year 5 months ago
世界最大排放国的排放可能提前达到峰值,远早于此前承诺的 2030 年。分析师 Dave Jones 表示,一旦中国的排放达到峰值,全世界的排放可能很快也会达到峰值。跟踪中国排放的分析师 Lauri Myllyvirta 通过分析来自中国政府、行业机构和商业公司的能源、工业和海关数据计算每月二氧化碳排放量。自 3 月以来,中国排放量一直在下降。这表明 2023 年中国的碳排放可能达到了峰值。驱动排放下降趋势的主要是清洁能源的增长。中国的排放此前发生过波动, 2013-2016 年减少煤炭使用推动了中国排放下降,但之后煤炭恢复增长后排放也恢复了增长。分析师表示可能需要一年的时间才能知道排放下降是短期还是长期现象。
CVE-2024-7737 | Dassault Systèmes 3DSwymer up to R2024x cross site scripting
1 year 5 months ago
A vulnerability, which was classified as problematic, was found in Dassault Systèmes 3DSwymer up to R2024x. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-7737. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
U.S. CISA adds Microsoft Windows, Apache HugeGraph-Server, Oracle JDeveloper, Oracle WebLogic Server, and Microsoft SQL Server bugs to its Known Exploited Vulnerabilities catalog
1 year 5 months ago
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Windows, Apache HugeGraph-Server, Oracle JDeveloper, Oracle WebLogic Server, and Microsoft SQL Server bugs to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SonicWall SonicOS, ImageMagick and Linux Kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. Below are the descriptions for these […]
Pierluigi Paganini
CVE-2024-7736 | Dassault Systèmes ENOVIA Collaborative Industry Innovator up to R2024x cross site scripting
1 year 5 months ago
A vulnerability, which was classified as problematic, has been found in Dassault Systèmes ENOVIA Collaborative Industry Innovator up to R2024x. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-7736. The attack may be launched remotely. There is no exploit available.
vuldb.com