Aggregator
【安全圈】涨幅约 200%:美国流媒体 Plex 终身版将涨价至 749.99 美元
4 weeks ago
AI 漏洞挖掘开始交付"工程化结果"
从音频解码到工业 CAD,从车端 CAN 帧到企业 Java 中间件——这一次,AI 红队没有靠"灵感"。
【安全圈】消息称微软内部示警:GitHub 面临生存级风险,AI 编程工具削弱托管必要性
4 weeks ago
AI 漏洞挖掘开始交付"工程化结果"
从音频解码到工业 CAD,从车端 CAN 帧到企业 Java 中间件——这一次,AI 红队没有靠"灵感"。
【安全圈】撞库黑产牟利倒卖十万条账号密码,男子获刑三年六个月
4 weeks ago
AI 漏洞挖掘开始交付"工程化结果"
从音频解码到工业 CAD,从车端 CAN 帧到企业 Java 中间件——这一次,AI 红队没有靠"灵感"。
Microsoft issues YellowKey mitigation, no patch yet
4 weeks ago
Microsoft acknowledged the YellowKey BitLocker bypass flaw and released mitigations, urging admins to disable autofstx.exe and enable TPM+PIN. A week after Chaotic Eclipse publicly dropped the YellowKey vulnerability, Microsoft acknowledged it and published a mitigation. Not a patch, a mitigation. The distinction matters, and we will get to why. The flaw, tracked as CVE-2026-45585 (CVSS […]
Pierluigi Paganini
CVE-2023-5807 | TRtek Education Portal prior 3.2023.29 sql injection
4 weeks ago
A vulnerability described as critical has been identified in TRtek Education Portal. This affects an unknown function. Executing a manipulation can lead to sql injection.
The identification of this vulnerability is CVE-2023-5807. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2023-5921 | DECE Geodi prior 8.0.0.27396 behavioral workflow
4 weeks ago
A vulnerability has been found in DECE Geodi and classified as problematic. This impacts an unknown function. The manipulation leads to enforcement of behavioral workflow.
This vulnerability is traded as CVE-2023-5921. An attack has to be approached locally. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2023-6011 | DECE Geodi prior 8.0.0.27396 cross site scripting
4 weeks ago
A vulnerability was found in DECE Geodi and classified as problematic. Affected is an unknown function. The manipulation results in cross site scripting.
This vulnerability is known as CVE-2023-6011. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2023-5983 | Botanik Pharmacy Automation prior 2.1.133.0 Embedded Sensitive Data information disclosure
4 weeks ago
A vulnerability identified as problematic has been detected in Botanik Pharmacy Automation. This issue affects some unknown processing of the component Embedded Sensitive Data Handler. The manipulation leads to information disclosure.
This vulnerability is referenced as CVE-2023-5983. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2023-6118 | Neutron IP Camera prior b1130.1.0.1 path traversal
4 weeks ago
A vulnerability was found in Neutron IP Camera. It has been rated as problematic. This issue affects some unknown processing. This manipulation causes path traversal: '/../filedir'.
This vulnerability is registered as CVE-2023-6118. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2023-6150 | ESKOM Computer e-municipality module up to 104 privileges management
4 weeks ago
A vulnerability, which was classified as critical, was found in ESKOM Computer e-municipality module up to 104. Affected by this vulnerability is an unknown functionality. Such manipulation leads to improper privilege management.
This vulnerability is referenced as CVE-2023-6150. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2023-6151 | ESKOM Computer e-municipality module up to 104 privileges management
4 weeks ago
A vulnerability has been found in ESKOM Computer e-municipality module up to 104 and classified as critical. Affected by this issue is some unknown functionality. Performing a manipulation results in improper privilege management.
This vulnerability is identified as CVE-2023-6151. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2023-5989 | Uyumsoft LioXERP up to 145 cross site scripting
4 weeks ago
A vulnerability, which was classified as problematic, was found in Uyumsoft LioXERP up to 145. Affected is an unknown function. Executing a manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2023-5989. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2023-5988 | Uyumsoft LioXERP up to 145 cross site scripting
4 weeks ago
A vulnerability has been found in Uyumsoft LioXERP up to 145 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2023-5988. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2023-6122 | Softomi Gelişmiş C2C Pazaryeri Yazılımı prior 12122023 cross site scripting
4 weeks ago
A vulnerability described as problematic has been identified in İstanbul Soft Informatics and Consultancy Limited Company Softomi Gelişmiş C2C Pazaryeri Yazılımı. This impacts an unknown function. Such manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2023-6122. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2023-6145 | Softomi Advanced C2C Marketplace Software prior 12122023 sql injection
4 weeks ago
A vulnerability classified as critical was found in İstanbul Soft Informatics and Consultancy Limited Company Softomi Advanced C2C Marketplace Software. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to sql injection.
This vulnerability is registered as CVE-2023-6145. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2023-6675 | National Keep Cyber Security Services CyberMath 1.4 unrestricted upload
4 weeks ago
A vulnerability marked as critical has been reported in National Keep Cyber Security Services CyberMath 1.4. This affects an unknown function. Performing a manipulation results in unrestricted upload.
This vulnerability is identified as CVE-2023-6675. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
260 символов, 126 уровней и 8,5 × 10³⁷ путей: GhostTree запутывает EDR и антивирусы в Windows
4 weeks ago
Новая техника обхода антивирусов прячет вирусы через штатные ссылки NTFS
Mini Shai-Hulud Hits Hundreds of npm Packages in AntV Ecosystem
4 weeks ago
Mini Shai-Hulud worm hits Alibaba AntV ecosystem in largest npm supply chain wave to date
Understanding Trend Structure: Higher Highs and Lower Lows Explained
4 weeks ago
Before indicators, before oscillators, before anything that requires a formula – the market communicates through price structure. Peaks…
Owais Sultan