Aggregator
CVE-2024-56087 | Logpoint up to 7.4.x Search Template Dashboard injection
4 months ago
A vulnerability was found in Logpoint up to 7.4.x. It has been classified as critical. Affected is an unknown function of the component Search Template Dashboard. The manipulation leads to injection.
This vulnerability is traded as CVE-2024-56087. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-56085 | Logpoint up to 7.4.x Search Template Dashboard injection
4 months ago
A vulnerability was found in Logpoint up to 7.4.x and classified as critical. This issue affects some unknown processing of the component Search Template Dashboard. The manipulation leads to injection.
The identification of this vulnerability is CVE-2024-56085. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-56086 | Logpoint up to 7.4.x Report Template Privilege Escalation
4 months ago
A vulnerability has been found in Logpoint up to 7.4.x and classified as critical. This vulnerability affects unknown code of the component Report Template Handler. The manipulation leads to Privilege Escalation.
This vulnerability was named CVE-2024-56086. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-56084 | Logpoint UniversalNormalizer up to 5.6.x Remote Code Execution
4 months ago
A vulnerability, which was classified as critical, was found in Logpoint UniversalNormalizer up to 5.6.x. This affects an unknown part. The manipulation leads to Remote Code Execution.
This vulnerability is uniquely identified as CVE-2024-56084. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
先知先行——灯塔系列城市沙龙 · 上海站成功举办!
4 months ago
议题PPT可在先知社区官网查看~
先知先行——灯塔系列城市沙龙 · 上海站成功举办!
4 months ago
12月14日,阿里云「先知」灯塔系列城市沙龙第七站在上海圆满落地,本次沙龙由阿里云先知、阿里安全响应中心、华东师范大学软件工程学院联合举办。现场汇聚了来自华东师范大学、复旦大学、同济大学、上海交通大学
MUT-1244 против своих: как хакеры убирают конкурентов через GitHub
4 months ago
Популярная площадка стала ареной битвы за данные.
CVE-2024-56112 | CyberPanel phpmyadminsignin.php token/username cross site scripting
4 months ago
A vulnerability, which was classified as problematic, has been found in CyberPanel. Affected by this issue is some unknown functionality of the file plogical/phpmyadminsignin.php. The manipulation of the argument token/username leads to cross site scripting.
This vulnerability is handled as CVE-2024-56112. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-8798 | zephyrproject-rtos Zephyr up to 3.7 ots_client.c olcp_ind_handler heap-based overflow (GHSA-r7pm-f93f-f7fp)
4 months ago
A vulnerability classified as critical was found in zephyrproject-rtos Zephyr up to 3.7. Affected by this vulnerability is the function olcp_ind_handler of the file zephyr/subsys/bluetooth/services/ots/ots_client.c. The manipulation leads to heap-based buffer overflow.
This vulnerability is known as CVE-2024-8798. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-5333 | theeventscalendar The Events Calendar Plugin up to 6.8.2.0 on WordPress REST API information disclosure
4 months ago
A vulnerability classified as problematic has been found in theeventscalendar The Events Calendar Plugin up to 6.8.2.0 on WordPress. Affected is an unknown function of the component REST API. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-5333. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-11841 | Giving Tithe.ly Giving Button Plugin up to 1.1 on WordPress Shortcode cross site scripting
4 months ago
A vulnerability was found in Giving Tithe.ly Giving Button Plugin up to 1.1 on WordPress. It has been rated as problematic. This issue affects some unknown processing of the component Shortcode Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-11841. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-8650 | GitLab Community Edition/Enterprise Edition up to 17.4.5/17.5.3/17.6.1 Public Project authorization (Issue 486300 / Nessus ID 213032)
4 months ago
A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 17.4.5/17.5.3/17.6.1. It has been declared as problematic. This vulnerability affects unknown code of the component Public Project Handler. The manipulation leads to incorrect authorization.
This vulnerability was named CVE-2024-8650. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8116 | GitLab Community Edition/Enterprise Edition up to 17.4.5/17.5.3/17.6.1 GraphQL Query authorization (Issue 480509 / Nessus ID 213030)
4 months ago
A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 17.4.5/17.5.3/17.6.1. It has been classified as problematic. This affects an unknown part of the component GraphQL Query Handler. The manipulation leads to incorrect authorization.
This vulnerability is uniquely identified as CVE-2024-8116. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-56083 | Cognition Devin prior 2024-12-12 VSCode Live Share URL random values
4 months ago
A vulnerability was found in Cognition Devin and classified as problematic. Affected by this issue is some unknown functionality of the component VSCode Live Share URL Handler. The manipulation leads to insufficiently random values.
This vulnerability is handled as CVE-2024-56083. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-53376 | CyberPanel up to 2.3.7 submitWebsiteCreation phpSelection os command injection
4 months ago
A vulnerability has been found in CyberPanel up to 2.3.7 and classified as critical. Affected by this vulnerability is an unknown functionality of the file websites/submitWebsiteCreation. The manipulation of the argument phpSelection leads to os command injection.
This vulnerability is known as CVE-2024-53376. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2008-1510 | Alkacon OpenCMS 7.0.3 listSearchFilter cross site scripting (EDB-31475 / XFDB-41390)
4 months ago
A vulnerability, which was classified as problematic, was found in Alkacon OpenCMS 7.0.3. Affected is an unknown function. The manipulation of the argument listSearchFilter leads to cross site scripting.
This vulnerability is traded as CVE-2008-1510. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
The Qualcomm DSP Driver - Unexpectedly Excavating an Exploit
4 months ago
Posted by Seth Jenkins, Google Project ZeroThis blog post provides a technical analysis of exploit
CVE-2019-11269 | Oracle FLEXCUBE Universal Banking 14.4.0 Infrastructure redirect (EDB-47000)
4 months ago
A vulnerability was found in Oracle FLEXCUBE Universal Banking 14.4.0. It has been rated as critical. Affected by this issue is some unknown functionality of the component Infrastructure. The manipulation leads to open redirect.
This vulnerability is handled as CVE-2019-11269. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Parker 探测器将成为距离太阳最近的人造探测器
4 months ago
NASA Parker 太阳探测器即将成为距离太阳最近的人造探测器。格林尼治标准时间 12 月 24 日上午 11 点 40 分左右,Parker 太阳探测器将到达距离太阳最近的位置。自