Aggregator
SEAMFUZZ:灰盒模糊测试的学习种子自适应突变策略
4 months ago
CVE-2024-13316 | akashmalik Scratch and Win Plugin up to 2.8.0 on WordPress authorization
4 months ago
A vulnerability classified as problematic was found in akashmalik Scratch and Win Plugin up to 2.8.0 on WordPress. This vulnerability affects unknown code. The manipulation leads to missing authorization.
This vulnerability was named CVE-2024-13316. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-12860 | scriptsbundle CarSpot Plugin up to 2.4.3 on WordPress unverified password change
4 months ago
A vulnerability classified as very critical has been found in scriptsbundle CarSpot Plugin up to 2.4.3 on WordPress. This affects an unknown part. The manipulation leads to unverified password change.
This vulnerability is uniquely identified as CVE-2024-12860. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
解锁安全研究新姿势:DeepSeek 本地部署指南
4 months ago
DeepSeek本地部署指南,助你轻松开启大模型赋能的安全研究之旅!
解锁安全研究新姿势:DeepSeek 本地部署指南
4 months ago
DeepSeek本地部署指南,助你轻松开启大模型赋能的安全研究之旅!
CVE-2024-13718 | wpdesk Flexible Wishlist for WooCommerce Plugin up to 1.2.26 on WordPress cross-site request forgery
4 months ago
A vulnerability was found in wpdesk Flexible Wishlist for WooCommerce Plugin up to 1.2.26 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2024-13718. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-13395 | kerryoco Threepress Plugin up to 1.7.1 on WordPress Shortcode cross site scripting
4 months ago
A vulnerability was found in kerryoco Threepress Plugin up to 1.7.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-13395. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-0422 | Cordaware bestinformed Web up to 6.2.2.4 code injection
4 months ago
A vulnerability was found in Cordaware bestinformed Web up to 6.2.2.4. It has been classified as problematic. Affected is an unknown function. The manipulation leads to code injection.
This vulnerability is traded as CVE-2025-0422. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-13316 | akashmalik Scratch and Win Plugin up to 2.8.0 on WordPress authorization
4 months ago
A vulnerability classified as problematic was found in akashmalik Scratch and Win Plugin up to 2.8.0 on WordPress. This vulnerability affects unknown code. The manipulation leads to missing authorization.
This vulnerability was named CVE-2024-13316. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-12860 | scriptsbundle CarSpot Plugin up to 2.4.3 on WordPress unverified password change
4 months ago
A vulnerability classified as very critical has been found in scriptsbundle CarSpot Plugin up to 2.4.3 on WordPress. This affects an unknown part. The manipulation leads to unverified password change.
This vulnerability is uniquely identified as CVE-2024-12860. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-13718 | wpdesk Flexible Wishlist for WooCommerce Plugin up to 1.2.26 on WordPress cross-site request forgery
4 months ago
A vulnerability was found in wpdesk Flexible Wishlist for WooCommerce Plugin up to 1.2.26 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2024-13718. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-13395 | kerryoco Threepress Plugin up to 1.7.1 on WordPress Shortcode cross site scripting
4 months ago
A vulnerability was found in kerryoco Threepress Plugin up to 1.7.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-13395. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-0422 | Cordaware bestinformed Web up to 6.2.2.4 code injection
4 months ago
A vulnerability was found in Cordaware bestinformed Web up to 6.2.2.4. It has been classified as problematic. Affected is an unknown function. The manipulation leads to code injection.
This vulnerability is traded as CVE-2025-0422. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Хакеры усилили NFCGate: каждая успешная атака приносит до 200 тысяч рублей
4 months ago
Мошенники запустили волну атак на банковские карты.
Прочность, помноженная на 40: исследователи создали отца всех алмазов
4 months ago
Лонсдейлит впервые удалось приручить в лаборатории. Что это значит для науки?
【2025春节】解题领红包之番外篇writeup
4 months ago
一年一度,我又来了。
CVE-2025-0423 | Cordaware bestinformed Web up to 6.2.2.4 cross site scripting
4 months ago
A vulnerability was found in Cordaware bestinformed Web up to 6.2.2.4 and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-0423. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-0425 | Cordaware bestinformed Infoclient up to 6.3.6.x on Windows external control of system or configuration setting
4 months ago
A vulnerability has been found in Cordaware bestinformed Infoclient up to 6.3.6.x on Windows and classified as critical. This vulnerability affects unknown code. The manipulation leads to external control of system or configuration setting.
This vulnerability was named CVE-2025-0425. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-0424 | Cordaware bestinformed Web up to 6.2.2.4 cross site scripting
4 months ago
A vulnerability, which was classified as problematic, was found in Cordaware bestinformed Web up to 6.2.2.4. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-0424. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com