Aggregator
Play
10 months 2 weeks ago
cohenido
Play
10 months 2 weeks ago
cohenido
CVE-2016-4148 | Adobe Flash Player up to 21.0.0.242 privileges management (MS16-083 / Nessus ID 91671)
10 months 2 weeks ago
A vulnerability has been found in Adobe Flash Player up to 21.0.0.242 and classified as critical. This vulnerability affects unknown code. The manipulation leads to improper privilege management.
This vulnerability was named CVE-2016-4148. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Apple iOS 18.0.1 and iPadOS 18.0.1 fix media session and passwords bugs
10 months 2 weeks ago
Apple iOS 18.0.1 and iPadOS 18.0.1 fix media session and passwords bugsApple released iOS 18.0
CVE-2014-7405 | Appbasedtechnologies Belaire Family Orthodontics 1.304 X.509 Certificate cryptographic issues (VU#582497)
10 months 2 weeks ago
A vulnerability classified as critical was found in Appbasedtechnologies Belaire Family Orthodontics 1.304. This vulnerability affects unknown code of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability was named CVE-2014-7405. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
WordPress LiteSpeed Cache plugin flaw could allow site takeover
10 months 2 weeks ago
A high-severity flaw in the WordPress LiteSpeed Cache plugin could allow attackers to execute arbitrary JavaScript code under certain conditions. A high-severity security flaw, tracked as CVE-2024-47374 (CVSS score 7.2), in the LiteSpeed Cache plugin for WordPress could allow attackers to execute arbitrary JavaScript. The vulnerability is a stored cross-site scripting (XSS) issue impacting versions […]
Pierluigi Paganini
CVE-2006-3147 | Hosting Controller up to 6.0 privileges management (EDB-1987 / Nessus ID 21736)
10 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in Hosting Controller up to 6.0. This issue affects some unknown processing. The manipulation leads to improper privilege management.
The identification of this vulnerability is CVE-2006-3147. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to add further authentication.
vuldb.com
一日一技 | 用 iOS 快捷指令和 AI,DIY 一个更好用的「闪念笔记」
10 months 2 weeks ago
一日一技 | 用 iOS 快捷指令和 AI,DIY 一个更好用的「闪念笔记」 Matrix 首页推荐 Matrix 是少数派的写作社区,我们主张分享真实的产品体验,有实用价值的经验与思考。我们会不定
CVE-2020-7209 | LinuxKI up to 6.0-1 code injection (ID 157739 / EDB-48483)
10 months 2 weeks ago
A vulnerability was found in LinuxKI up to 6.0-1 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to code injection.
This vulnerability is handled as CVE-2020-7209. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Apple Releases Critical iOS and iPadOS Updates to Fix VoiceOver Password Vulnerability
10 months 2 weeks ago
Data Privacy / Mobile SecurityApple has released iOS and iPadOS updates to address two security is
CVE-2024-9306 | WP Booking Calendar Plugin up to 10.6 on WordPress cross site scripting
10 months 2 weeks ago
A vulnerability was found in WP Booking Calendar Plugin up to 10.6 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-9306. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-9435 | ShiftController Employee Shift Scheduling Plugin up to 4.9.66 on WordPress cross site scripting
10 months 2 weeks ago
A vulnerability classified as problematic has been found in ShiftController Employee Shift Scheduling Plugin up to 4.9.66 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-9435. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-9271 | Re WP Plugin up to 1.0.1 on WordPress SVG File Upload cross site scripting
10 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Re WP Plugin up to 1.0.1 on WordPress. This issue affects some unknown processing of the component SVG File Upload Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-9271. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-9071 | Easy Demo Importer Plugin up to 1.1.2 on WordPress SVG File Upload cross site scripting
10 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in Easy Demo Importer Plugin up to 1.1.2 on WordPress. Affected is an unknown function of the component SVG File Upload Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-9071. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-8743 | Bit File Manager Plugin up to 6.5.7 on WordPress JavaScript File unrestricted upload
10 months 2 weeks ago
A vulnerability classified as critical has been found in Bit File Manager Plugin up to 6.5.7 on WordPress. Affected is an unknown function of the component JavaScript File Handler. The manipulation leads to unrestricted upload.
This vulnerability is traded as CVE-2024-8743. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-9417 | Hash Form Plugin up to 1.1.9 on WordPress unrestricted upload
10 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Hash Form Plugin up to 1.1.9 on WordPress. This affects an unknown part. The manipulation leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2024-9417. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-8486 | Shortcodes and Extra Features for Phlox Theme up to 2.16.3 on WordPress Modern Heading Widget/Icon Picker Widget cross site scripting
10 months 2 weeks ago
A vulnerability has been found in Shortcodes and Extra Features for Phlox Theme up to 2.16.3 on WordPress and classified as problematic. This vulnerability affects unknown code of the component Modern Heading Widget/Icon Picker Widget. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-8486. The attack can be initiated remotely. There is no exploit available.
vuldb.com
R3CTF2024 WP - 渗透测试中心
10 months 2 weeks ago
一、PWN1.Nullullullllu在直接给 libc_base 的情况下,一次任意地址写 \x00 。直接修改 IO_2_1_stdin 的 _IO_buf_base 末尾为 \x00 ,那么
CVE-2007-4737 | SpeedTech PHP Library stphptextareawithcaption.php STPHPLIB_DIR code injection (EDB-4358 / XFDB-36417)
10 months 2 weeks ago
A vulnerability has been found in SpeedTech PHP Library and classified as critical. Affected by this vulnerability is an unknown functionality in the library STPHPLIB_DIR of the file stphptextareawithcaption.php. The manipulation of the argument STPHPLIB_DIR leads to code injection.
This vulnerability is known as CVE-2007-4737. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com