Aggregator
雷神众测漏洞周报2024.11.18-2024.11.24
9 months 2 weeks ago
雷神众测拥有该文章的修改和解释权。如欲转载或传播此文章,必须保证此文章的副本,包括版权声明等全部内容。声明雷神众测允许,不得任意修改或增减此文章内容,不得以任何方式将其用于商业目的。
CVE-2024-6538 | Red Hat OpenShift Container Platform 4 internet server-side request forgery
9 months 2 weeks ago
A vulnerability classified as critical was found in Red Hat OpenShift Container Platform 4. Affected by this vulnerability is an unknown functionality of the file /api/dev-console/proxy/internet. The manipulation leads to server-side request forgery.
This vulnerability is known as CVE-2024-6538. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-53930 | WikiDocs up to 1.0.64 KaTeX Parser cross site scripting (ID 211)
9 months 2 weeks ago
A vulnerability classified as problematic has been found in WikiDocs up to 1.0.64. Affected is an unknown function of the component KaTeX Parser. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-53930. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-53916 | OpenStack Neutron up to 25.0.0 Policy Enforcement tagging.py Privilege Escalation
9 months 2 weeks ago
A vulnerability was found in OpenStack Neutron up to 25.0.0. It has been rated as critical. This issue affects some unknown processing of the file neutron/extensions/tagging.py of the component Policy Enforcement Handler. The manipulation leads to Privilege Escalation.
The identification of this vulnerability is CVE-2024-53916. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
COP29 提出每年向发展中国家提供 3000 亿美元援助
9 months 2 weeks ago
在阿塞拜疆举行的《联合国气候变化框架公约》第 29 次缔约方会议(COP29)24 日就发展中国家全球变暖对策的援助目标达成共识后闭幕。内容为到 2035 年为止,发达国家公共资金和民间资金合计每年至少提供 3000 亿美元的援助。这是目前每年 1000 亿美元援助规模的三倍。此外还要求包括发展中国家等在内的全世界的资金官民合计扩大到每年 1.3 万亿美元。为了抑制发展中国家债务增加,将设置在利用无偿提供资金等手段的同时扩大资金的机制,并敦促中国及产油国等有经济实力的发展中国家也要作出贡献。
CVE-2024-7056 | WPForms Plugin up to 1.9.1.5 on WordPress Setting cross site scripting
9 months 2 weeks ago
A vulnerability was found in WPForms Plugin up to 1.9.1.5 on WordPress. It has been declared as problematic. This vulnerability affects unknown code of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-7056. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6393 | Photo Gallery, Sliders, Proofing Plugin up to 3.59.4 on WordPress Setting cross site scripting
9 months 2 weeks ago
A vulnerability was found in Photo Gallery, Sliders, Proofing Plugin up to 3.59.4 on WordPress. It has been classified as problematic. This affects an unknown part of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-6393. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-10709 | YaDisk Files Plugin up to 1.2.5 on WordPress Shortcode Attribute cross site scripting
9 months 2 weeks ago
A vulnerability was found in YaDisk Files Plugin up to 1.2.5 on WordPress and classified as problematic. Affected by this issue is some unknown functionality of the component Shortcode Attribute Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-10709. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-11665 | hardy-barth cph2_echarge_firmware up to 2.0.4 command injection
9 months 2 weeks ago
A vulnerability has been found in hardy-barth cph2_echarge_firmware up to 2.0.4 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to command injection.
This vulnerability is known as CVE-2024-11665. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2024-53901 | Imager Package up to 1.024 on Perl trim heap-based overflow (Issue 167)
9 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Imager Package up to 1.024 on Perl. Affected is the function trim. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2024-53901. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-10710 | YaDisk Files Plugin up to 1.2.5 on WordPress Setting cross site scripting
9 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in YaDisk Files Plugin up to 1.2.5 on WordPress. This issue affects some unknown processing of the component Setting Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-10710. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-11666 | hardy-barth cph2_echarge_firmware up to 2.0.4 data authenticity
9 months 2 weeks ago
A vulnerability classified as critical was found in hardy-barth cph2_echarge_firmware up to 2.0.4. This vulnerability affects unknown code. The manipulation leads to insufficient verification of data authenticity.
This vulnerability was named CVE-2024-11666. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-53915 | Veritas Enterprise Vault up to 15.1 .NET Remoting TCP Port deserialization (ZDI-CAN-24405)
9 months 2 weeks ago
A vulnerability classified as very critical has been found in Veritas Enterprise Vault up to 15.1. This affects an unknown part of the component .NET Remoting TCP Port. The manipulation leads to deserialization.
This vulnerability is uniquely identified as CVE-2024-53915. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-53914 | Veritas Enterprise Vault up to 15.1 .NET Remoting TCP Port deserialization (ZDI-CAN-24344)
9 months 2 weeks ago
A vulnerability was found in Veritas Enterprise Vault up to 15.1. It has been rated as very critical. Affected by this issue is some unknown functionality of the component .NET Remoting TCP Port. The manipulation leads to deserialization.
This vulnerability is handled as CVE-2024-53914. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-53913 | Veritas Enterprise Vault up to 15.1 .NET Remoting TCP Port deserialization (ZDI-CAN-24343)
9 months 2 weeks ago
A vulnerability was found in Veritas Enterprise Vault up to 15.1. It has been declared as very critical. Affected by this vulnerability is an unknown functionality of the component .NET Remoting TCP Port. The manipulation leads to deserialization.
This vulnerability is known as CVE-2024-53913. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-53912 | Veritas Enterprise Vault up to 15.1 .NET Remoting TCP Port deserialization (ZDI-CAN-24341)
9 months 2 weeks ago
A vulnerability was found in Veritas Enterprise Vault up to 15.1. It has been classified as very critical. Affected is an unknown function of the component .NET Remoting TCP Port. The manipulation leads to deserialization.
This vulnerability is traded as CVE-2024-53912. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-53910 | Veritas Enterprise Vault up to 15.1 .NET Remoting TCP Port deserialization (ZDI-CAN-24336)
9 months 2 weeks ago
A vulnerability was found in Veritas Enterprise Vault up to 15.1 and classified as very critical. This issue affects some unknown processing of the component .NET Remoting TCP Port. The manipulation leads to deserialization.
The identification of this vulnerability is CVE-2024-53910. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-53911 | Veritas Enterprise Vault up to 15.1 .NET Remoting TCP Port deserialization (ZDI-CAN-24339)
9 months 2 weeks ago
A vulnerability has been found in Veritas Enterprise Vault up to 15.1 and classified as very critical. This vulnerability affects unknown code of the component .NET Remoting TCP Port. The manipulation leads to deserialization.
This vulnerability was named CVE-2024-53911. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
网络安全信息与动态周报2024年第46期(11月11日-11月17日)
9 months 2 weeks ago
本周,互联网网络安全态势整体评价为良。