侧载是 Android 生态系统相比 iOS 更自由的地方,用户可通过下载 APK 文件安装一个应用的旧版本或修改版本。但现在 Google Play Integrity API 将给予应用开发商选择去屏蔽侧载,强行通过 Google Play 下载。Play Integrity API 将通过检查交互和服务器请求寻找应用是否被修改,软件运行环境是否可信,设备是否启用 Google Play Protect 等的证据,然后应用开发商可以决定是否警告用户设备已经 root、或者拒绝应用运行,建议用户切换到 Google Play 版本——此举将会删除设备上该应用的所有数据替换为 Google Play 版本。如果有愈来愈多的应用使用该功能,那么 root 设备的价值将会越来越小。
A vulnerability classified as problematic was found in Mentiss Acgv ACGVannu 1.3. This vulnerability affects unknown code of the file theme/acgv.php. The manipulation of the argument rubrik leads to path traversal.
This vulnerability was named CVE-2007-2560. The attack can be initiated remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as critical, was found in DynamicPAD 1.02. This affects an unknown part of the file dp_logs.php. The manipulation of the argument HomeDir leads to file inclusion.
This vulnerability is uniquely identified as CVE-2007-2527. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in Redsys 3DSecure 2.0. Affected is an unknown function. The manipulation of the argument threeDSMethodNotificationURL leads to cross site scripting.
This vulnerability is traded as CVE-2024-25285. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
A vulnerability was found in Redsys 3DSecure 2.0. It has been rated as problematic. This issue affects some unknown processing of the component 3DSMethod Authentication. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-25282. The attack may be initiated remotely. Furthermore, there is an exploit available.
A vulnerability was found in amCharts Plugin up to 1.4.4 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2024-8622. The attack can be initiated remotely. There is no exploit available.
A vulnerability was found in LearnPress Plugin up to 4.2.7 on WordPress. It has been classified as critical. This affects an unknown part. The manipulation of the argument c_fields leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-8529. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in LearnPress Plugin up to 4.2.7 on WordPress and classified as critical. Affected by this issue is some unknown functionality. The manipulation of the argument c_only_fields leads to sql injection.
This vulnerability is handled as CVE-2024-8522. The attack may be launched remotely. There is no exploit available.
A vulnerability has been found in Citrix Workspace App on Windows and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to Local Privilege Escalation.
This vulnerability is known as CVE-2024-7889. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Citrix Workspace App on Windows. Affected is an unknown function. The manipulation leads to Local Privilege Escalation.
This vulnerability is traded as CVE-2024-7890. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in evilnapsis Inventio Lite up to 4. This issue affects some unknown processing of the file /?action=processlogin. The manipulation of the argument username leads to sql injection.
The identification of this vulnerability is CVE-2024-44541. The attack may be initiated remotely. There is no exploit available.
A vulnerability classified as problematic was found in Hitachi Vantara Pentaho Data Integration & Analytics up to 9.3.0.7/10.0.x. This vulnerability affects unknown code of the component Search. The manipulation leads to insufficiently protected credentials.
This vulnerability was named CVE-2024-28981. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Mozilla Thunderbird up to 128.1. It has been rated as critical. This issue affects some unknown processing of the component OTR Chat Session Handler. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2024-8394. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in DrayTek Vigor3900 1.5.1.6. It has been declared as critical. Affected by this vulnerability is the function run_command. The manipulation of the argument name leads to command injection.
This vulnerability is known as CVE-2024-44844. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in DrayTek Vigor3900 1.5.1.6. It has been rated as critical. Affected by this issue is the function filter_string. The manipulation of the argument value leads to command injection.
This vulnerability is handled as CVE-2024-44845. The attack may be launched remotely. There is no exploit available.