Aggregator
.NET 安全攻防知识交流社区
4 months 2 weeks ago
.NET内网实战:通过提取NTDS文件获取Windows域环境资产信息
4 months 2 weeks ago
CVE-2024-28126 | Zerochannel 0ch BBS Script 4.00 cross site scripting
4 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in Zerochannel 0ch BBS Script 4.00. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-28126. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-30232 | Exclusive Addons Elementor Plugin up to 2.6.9 on WordPress cross site scripting
4 months 2 weeks ago
A vulnerability was found in Exclusive Addons Elementor Plugin up to 2.6.9 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-30232. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-28034 | Flash CGI Mini Thread 3.33βi cross site scripting
4 months 2 weeks ago
A vulnerability was found in Flash CGI Mini Thread 3.33βi. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-28034. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-26018 | TvRock 0.9t8a cross site scripting
4 months 2 weeks ago
A vulnerability was found in TvRock 0.9t8a and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-26018. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-2904 | Extend Themes Calliope Plugin up to 1.0.33 on WordPress cross-site request forgery
4 months 2 weeks ago
A vulnerability was found in Extend Themes Calliope Plugin up to 1.0.33 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2024-2904. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-29203 | TinyMCE up to 6.8.0 iFrame cross site scripting
4 months 2 weeks ago
A vulnerability was found in TinyMCE up to 6.8.0. It has been rated as problematic. This issue affects some unknown processing of the component iFrame Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-29203. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-44088 | Artica Pandora FMS up to 774 sql injection (EDB-52157)
4 months 2 weeks ago
A vulnerability classified as critical has been found in Artica Pandora FMS up to 774. This affects an unknown part. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2023-44088. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2023-30258 | MagnusSolution magnusbilling 6.x/7.x HTTP Request command injection (EDB-52170)
4 months 2 weeks ago
A vulnerability classified as critical has been found in MagnusSolution magnusbilling 6.x/7.x. Affected is an unknown function of the component HTTP Request Handler. The manipulation leads to command injection.
This vulnerability is traded as CVE-2023-30258. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
LeakedData
4 months 2 weeks ago
cohenido
LeakedData
4 months 2 weeks ago
cohenido
LeakedData
4 months 2 weeks ago
cohenido
LeakedData
4 months 2 weeks ago
cohenido
CVE-2021-28976 | GetSimpleCMS up to 3.3.15 phar File admin/upload.php unrestricted upload (EDB-52168)
4 months 2 weeks ago
A vulnerability was found in GetSimpleCMS up to 3.3.15. It has been declared as critical. This vulnerability affects unknown code of the file admin/upload.php of the component phar File Handler. The manipulation leads to unrestricted upload.
This vulnerability was named CVE-2021-28976. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-29684 | DedeCMS 5.7 makehtml_homepage.php cross-site request forgery
4 months 2 weeks ago
A vulnerability classified as problematic has been found in DedeCMS 5.7. Affected is an unknown function of the file /src/dede/makehtml_homepage.php. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2024-29684. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-2911 | Tianjin PubliCMS 4.0.202302.e cross-site request forgery
4 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in Tianjin PubliCMS 4.0.202302.e. This affects an unknown part. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2024-2911. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2024-29881 | TinyMCE up to 6.8.0 SVG Image cross site scripting
4 months 2 weeks ago
A vulnerability was found in TinyMCE up to 6.8.0 and classified as problematic. This issue affects some unknown processing of the component SVG Image Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-29881. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-2139 | Master Addons for Elementor Plugin up to 2.0.5.6 on WordPress Pricing Table Widget cross site scripting (ID 3050636)
4 months 2 weeks ago
A vulnerability was found in Master Addons for Elementor Plugin up to 2.0.5.6 on WordPress and classified as problematic. Affected by this issue is some unknown functionality of the component Pricing Table Widget. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-2139. The attack may be launched remotely. There is no exploit available.
vuldb.com