Aggregator
一种针对微服务云架构的同步毫秒瓶颈攻击
4 months 3 weeks ago
本文介绍了一种新型低容量应用层 DDoS 攻击,称为同步毫瓶颈攻击SyncM,专门针对微服务。实验表明SyncM可以实现各种性能损害,同时不被最先进的DDoS防御工具检测到。
Сложная жизнь на Земле могла возникнуть на 1,5 млрд лет раньше
4 months 3 weeks ago
Древние фоссилии в Габоне переписывают историю Земли.
CVE-2024-7303 | itsourcecode Online Blood Bank Management System 1.0 Send Blood Request Page /request.php Address/bloodgroup cross site scripting
4 months 3 weeks ago
A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /request.php of the component Send Blood Request Page. The manipulation of the argument Address/bloodgroup leads to cross site scripting.
The identification of this vulnerability is CVE-2024-7303. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Live Webinar | Modernize Identity and Security to Adopt a Zero Trust Strategy
4 months 3 weeks ago
CVE-2024-6770 | Lifetime Free Drag & Drop Contact Form Builder for VForm Plugin cross site scripting
4 months 3 weeks ago
A vulnerability was found in Lifetime Free Drag & Drop Contact Form Builder for VForm Plugin up to 2.1.5 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-6770. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-7208 | HostGator Hosted Services authentication spoofing
4 months 3 weeks ago
A vulnerability was found in HostGator. It has been classified as critical. This affects an unknown part of the component Hosted Services. The manipulation leads to authentication bypass by spoofing.
This vulnerability is uniquely identified as CVE-2024-7208. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-41944 | xibosignage xibo-cms up to 3.3.11/4.0.13 proofofplayReport sortBy sql injection (GHSA-v6q4-h869-gm3r)
4 months 3 weeks ago
A vulnerability was found in xibosignage xibo-cms up to 3.3.11/4.0.13 and classified as critical. Affected by this issue is some unknown functionality of the file report/data/proofofplayReport. The manipulation of the argument sortBy leads to sql injection.
This vulnerability is handled as CVE-2024-41944. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41804 | xibosignage xibo-cms up to 3.3.11/4.0.13 sql injection (GHSA-4pp3-4mw7-qfwr)
4 months 3 weeks ago
A vulnerability has been found in xibosignage xibo-cms up to 3.3.11/4.0.13 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection.
This vulnerability is known as CVE-2024-41804. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41803 | xibosignage xibo-cms up to 3.3.11/4.0.13 sql injection (GHSA-hpc5-mxfq-44hv)
4 months 3 weeks ago
A vulnerability, which was classified as critical, was found in xibosignage xibo-cms up to 3.3.11/4.0.13. Affected is an unknown function. The manipulation leads to sql injection.
This vulnerability is traded as CVE-2024-41803. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41802 | xibosignage xibo-cms up to 3.3.11/4.0.13 API Route sql injection (GHSA-x4qm-vvhp-g7c2)
4 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in xibosignage xibo-cms up to 3.3.11/4.0.13. This issue affects some unknown processing of the component API Route. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2024-41802. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-5486 | HPE ClearPass Policy Manager up to 6.11.8/6.12.1 information disclosure
4 months 3 weeks ago
A vulnerability classified as problematic was found in HPE ClearPass Policy Manager up to 6.11.8/6.12.1. This vulnerability affects unknown code. The manipulation leads to information disclosure.
This vulnerability was named CVE-2024-5486. The attack can be initiated remotely. There is no exploit available.
vuldb.com
HPE security advisory (AV24-429)
4 months 3 weeks ago
Canadian Centre for Cyber Security
CVE-2024-41916 | HPE ClearPass Policy Manager up to 6.11.8/6.12.1 information disclosure
4 months 3 weeks ago
A vulnerability classified as problematic has been found in HPE ClearPass Policy Manager up to 6.11.8/6.12.1. This affects an unknown part. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-41916. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-7209 | NetWin/Bird Fastmail SPF Record authentication spoofing
4 months 3 weeks ago
A vulnerability was found in NetWin and Bird Fastmail. It has been rated as critical. Affected by this issue is some unknown functionality of the component SPF Record Handler. The manipulation leads to authentication bypass by spoofing.
This vulnerability is handled as CVE-2024-7209. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-41943 | mkucej i-librarian-free up to 5.11.0 Item Summary Page cross site scripting
4 months 3 weeks ago
A vulnerability was found in mkucej i-librarian-free up to 5.11.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Item Summary Page. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-41943. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41915 | HPE ClearPass Policy Manager up to 6.11.8/6.12.1 Web-based Management Interface sql injection
4 months 3 weeks ago
A vulnerability was found in HPE ClearPass Policy Manager up to 6.11.8/6.12.1. It has been classified as critical. Affected is an unknown function of the component Web-based Management Interface. The manipulation leads to sql injection.
This vulnerability is traded as CVE-2024-41915. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-7297 | Langflow up to 1.0.12 /api/v1/users dynamically-managed code resources
4 months 3 weeks ago
A vulnerability was found in Langflow up to 1.0.12 and classified as very critical. This issue affects some unknown processing of the file /api/v1/users. The manipulation leads to dynamically-managed code resources.
The identification of this vulnerability is CVE-2024-7297. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-26289 | IBM Aspera Orchestrator 4.0.1 http headers for scripting syntax (XFDB-248478)
4 months 3 weeks ago
A vulnerability has been found in IBM Aspera Orchestrator 4.0.1 and classified as critical. This vulnerability affects unknown code. The manipulation leads to improper neutralization of http headers for scripting syntax.
This vulnerability was named CVE-2023-26289. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-38001 | IBM Aspera Orchestrator 4.0.1 cross-site request forgery (XFDB-260206)
4 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in IBM Aspera Orchestrator 4.0.1. This affects an unknown part. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2023-38001. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com