Aggregator
CVE-2024-34158 | Google Go up to 1.22.6/1.23.0 go-build-constraint resource consumption
10 months 1 week ago
A vulnerability classified as problematic has been found in Google Go up to 1.22.6/1.23.0. Affected is an unknown function of the component go-build-constraint. The manipulation leads to resource consumption.
This vulnerability is traded as CVE-2024-34158. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45034 | Apache Airflow up to 2.10.0 DAG Folder unnecessary privileges
10 months 1 week ago
A vulnerability was found in Apache Airflow up to 2.10.0 and classified as critical. Affected by this issue is some unknown functionality of the component DAG Folder Handler. The manipulation leads to execution with unnecessary privileges.
This vulnerability is handled as CVE-2024-45034. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-7652 | Mozilla Thunderbird ECMA-262 type confusion
10 months 1 week ago
A vulnerability was found in Mozilla Thunderbird. It has been declared as critical. This vulnerability affects unknown code of the component ECMA-262 Handler. The manipulation leads to type confusion.
This vulnerability was named CVE-2024-7652. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8538 | Big File Uploads Plugin up to 2.1.2 on WordPress information disclosure
10 months 1 week ago
A vulnerability has been found in Big File Uploads Plugin up to 2.1.2 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to information disclosure.
This vulnerability was named CVE-2024-8538. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-6849 | Preloader Plus Plugin up to 2.2.1 on WordPress SVG File Upload cross site scripting
10 months 1 week ago
A vulnerability was found in Preloader Plus Plugin up to 2.2.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component SVG File Upload Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-6849. The attack can be launched remotely. There is no exploit available.
vuldb.com
idekCTF 2024 Writeup - Advanced iframe Magic
10 months 1 week ago
In idekCTF 2024, there was an interesting problem called srcdoc-memos from @icesfont,
idekCTF 2024 筆記之 iframe 高級魔法
10 months 1 week ago
在 idekCTF 2024 中,由 icesfont 所出的一道題目 srcdoc-memos 十分有趣,牽涉到了許多 iframe 的相關知識。我沒有實際參加比賽,但賽
CVE-2024-8427 | Frontend Post Submission Manager Lite Plugin up to 1.2.2 on WordPress Setting authorization
10 months 1 week ago
A vulnerability was found in Frontend Post Submission Manager Lite Plugin up to 1.2.2 on WordPress. It has been classified as problematic. This affects an unknown part of the component Setting Handler. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2024-8427. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-7493 | WPCOM Member Plugin up to 1.5.2.1 on WordPress User Meta privileges management
10 months 1 week ago
A vulnerability, which was classified as critical, has been found in WPCOM Member Plugin up to 1.5.2.1 on WordPress. This issue affects some unknown processing of the component User Meta Handler. The manipulation leads to improper privilege management.
The identification of this vulnerability is CVE-2024-7493. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2024-44739 | SourceCodester Simple Forum Website 1.0 id sql injection
10 months 1 week ago
A vulnerability has been found in SourceCodester Simple Forum Website 1.0 and classified as critical. This vulnerability affects unknown code of the file /php-sqlite-forum/?page=manage_user. The manipulation of the argument id leads to sql injection.
This vulnerability was named CVE-2024-44739. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-44401 | D-Link DI-8100G 17.12.20A1 upgrade_filter.asp sub47A60C command injection
10 months 1 week ago
A vulnerability classified as critical was found in D-Link DI-8100G 17.12.20A1. Affected by this vulnerability is the function sub47A60C of the file upgrade_filter.asp. The manipulation leads to command injection.
This vulnerability is known as CVE-2024-44401. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-44408 | D-Link DIR-823G 1.0.2B05_20181207 Configuration File information disclosure
10 months 1 week ago
A vulnerability, which was classified as problematic, was found in D-Link DIR-823G 1.0.2B05_20181207. Affected is an unknown function of the component Configuration File Handler. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-44408. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2024-44402 | D-Link DI-8100G 17.12.20A1 msp_info.htm command injection
10 months 1 week ago
A vulnerability, which was classified as critical, was found in D-Link DI-8100G 17.12.20A1. Affected is an unknown function of the file msp_info.htm. The manipulation leads to command injection.
This vulnerability is traded as CVE-2024-44402. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
Meow
10 months 1 week ago
cohenido
AT&T因VMware授权改成订阅制起诉博通 后者拒绝为现有买断产品提供支持
10 months 1 week ago
CVE-2012-2316 | OpenKM 5.1.7/5.1.8 script cross-site request forgery (EDB-18888 / SA47420)
10 months 1 week ago
A vulnerability was found in OpenKM 5.1.7/5.1.8 and classified as problematic. This issue affects some unknown processing. The manipulation of the argument script leads to cross-site request forgery.
The identification of this vulnerability is CVE-2012-2316. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-13006 | tcpdump up to 4.9.1 L2TP Parser print-l2tp.c memory corruption (Nessus ID 103257 / ID 370625)
10 months 1 week ago
A vulnerability was found in tcpdump up to 4.9.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file print-l2tp.c of the component L2TP Parser. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2017-13006. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-7415 | Remember Me Controls Plugin up to 2.0.1 on WordPress information disclosure
10 months 1 week ago
A vulnerability was found in Remember Me Controls Plugin up to 2.0.1 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2024-7415. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-8480 | Image Optimizer, Resizer and CDN Plugin up to 7.2.7 on WordPress sirv_save_prevented_sizes authorization
10 months 1 week ago
A vulnerability classified as critical was found in Image Optimizer, Resizer and CDN Plugin up to 7.2.7 on WordPress. Affected by this vulnerability is the function sirv_save_prevented_sizes. The manipulation leads to missing authorization.
This vulnerability is known as CVE-2024-8480. The attack can be launched remotely. There is no exploit available.
vuldb.com