Aggregator
BianLian
11 months 2 weeks ago
cohenido
CVE-2025-30203 | Enalean Tuleap Community Edition/Tuleap Enterprise Edition RSS Widget cross site scripting
11 months 2 weeks ago
A vulnerability was found in Enalean Tuleap Community Edition and Tuleap Enterprise Edition and classified as problematic. Affected by this issue is some unknown functionality of the component RSS Widget. The manipulation leads to improper neutralization of encoded uri schemes in a web page.
This vulnerability is handled as CVE-2025-30203. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-29929 | Enalean Tuleap Community Edition/Tuleap Enterprise Edition cross-site request forgery
11 months 2 weeks ago
A vulnerability has been found in Enalean Tuleap Community Edition and Tuleap Enterprise Edition and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2025-29929. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Qilin
11 months 2 weeks ago
cohenido
CVE-2025-29766 | Enalean Tuleap Community Edition/Tuleap Enterprise Edition cross-site request forgery
11 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in Enalean Tuleap Community Edition and Tuleap Enterprise Edition. Affected is an unknown function. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2025-29766. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-30209 | Enalean Tuleap Community Edition/Tuleap Enterprise Edition FRS REST Endpoint authorization
11 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Enalean Tuleap Community Edition and Tuleap Enterprise Edition. This issue affects some unknown processing of the component FRS REST Endpoint. The manipulation leads to incorrect authorization.
The identification of this vulnerability is CVE-2025-30209. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-3048 | Amazon AWS Serverless Application Model Command Line Interface SAM CLI path traversal (AWS-2025-008)
11 months 2 weeks ago
A vulnerability classified as critical was found in Amazon AWS Serverless Application Model Command Line Interface up to 1.133.x. This vulnerability affects unknown code of the component SAM CLI. The manipulation leads to path traversal.
This vulnerability was named CVE-2025-3048. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-3047 | Amazon AWS Serverless Application Model Command Line Interface SAM CLI path traversal (AWS-2025-008)
11 months 2 weeks ago
A vulnerability classified as critical has been found in Amazon AWS Serverless Application Model Command Line Interface up to 1.132.x. This affects an unknown part of the component SAM CLI. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2025-3047. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-27149 | Zulip up to 9.x exposure of sensitive system information to an unauthorized control sphere
11 months 2 weeks ago
A vulnerability was found in Zulip up to 9.x. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to exposure of sensitive system information to an unauthorized control sphere.
This vulnerability is handled as CVE-2025-27149. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-27095 | JumpServer up to 3.10.17/4.7.x Kubernetes Session privileges assignment
11 months 2 weeks ago
A vulnerability was found in JumpServer up to 3.10.17/4.7.x. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Kubernetes Session Handler. The manipulation leads to incorrect privilege assignment.
This vulnerability is known as CVE-2025-27095. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Akira
11 months 2 weeks ago
cohenido
Akira
11 months 2 weeks ago
cohenido
白领工人的工作可能开始减少
11 months 2 weeks ago
过去几年美国白领工人的失业率高于其他群体,且同时其薪水增长也在放缓。这一趋势部分被归因于 AI。经济学家认为白领的工作方式发生了巨变。纽约联邦储备银行的数据显示,大学毕业生的失业率从 2% 升至 2.6%,而所有工人的失业率约为从 3.4% 升至 4%。失业率在拥有学士学位或上过大学但没有学位的人群中最高,学历最高或没有高中文凭的人群中失业率则维持平稳或下降。需要大学学历的职位招聘招聘率下降更快。AI 通过提高白领工作的自动化程度进一步减少了此类职位的需求。
CVE-2025-22937 | Adtran 411 ONT L80.00.0011.M2 privilege escalation
11 months 2 weeks ago
A vulnerability was found in Adtran 411 ONT L80.00.0011.M2. It has been classified as critical. Affected is an unknown function. The manipulation leads to privilege escalation.
This vulnerability is traded as CVE-2025-22937. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2025-22940 | Adtran 411 ONT L80.00.0011.M2 Admin Password access control
11 months 2 weeks ago
A vulnerability was found in Adtran 411 ONT L80.00.0011.M2 and classified as problematic. This issue affects some unknown processing of the component Admin Password Handler. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2025-22940. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2025-22938 | Adtran 411 ONT L80.00.0011.M2 default password
11 months 2 weeks ago
A vulnerability has been found in Adtran 411 ONT L80.00.0011.M2 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to use of default password.
This vulnerability was named CVE-2025-22938. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2025-22941 | Adtran 411 ONT L80.00.0011.M2 Web Interface command injection
11 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Adtran 411 ONT L80.00.0011.M2. This affects an unknown part of the component Web Interface. The manipulation leads to command injection.
This vulnerability is uniquely identified as CVE-2025-22941. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-22939 | Adtran 411 ONT L80.00.0011.M2 Telnet Service command injection
11 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in Adtran 411 ONT L80.00.0011.M2. Affected by this issue is some unknown functionality of the component Telnet Service. The manipulation leads to command injection.
This vulnerability is handled as CVE-2025-22939. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-33302 | Fortinet FortiNDR/FortiMail Webmail buffer overflow (FG-IR-21-023)
11 months 2 weeks ago
A vulnerability classified as critical was found in Fortinet FortiNDR and FortiMail. Affected by this vulnerability is an unknown functionality of the component Webmail. The manipulation leads to buffer overflow.
This vulnerability is known as CVE-2023-33302. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com