Aggregator
RSAC 2025创新沙盒 | EQTY Lab:构建可信AI生态的治理先锋与技术架构
1 year 1 month ago
EQTY Lab聚焦可信AI领域,面向高监管行业提供融合硬件加密、分布式账本与全生命周期治理的完整解决方案,重构AI系统的安全性、透明度与合规性,助力人工智能技术在金融、医疗、政务等关键场景的可信落地...
3个理由,告诉你为什么浏览器是阻止钓鱼攻击的最佳选择?
1 year 1 month ago
钓鱼攻击在 2025 年仍然是组织面临的一大挑战。事实上,随着攻击者越来越多地利用基于身份的技术而不是软件漏洞,钓鱼可以说比以往任何时候都更具威胁。
CVE-2018-19752 | DomainMod up to 4.11.01 Registrar assets/add/registrar.php notes cross site scripting (Issue 84 / EDB-45949)
1 year 1 month ago
A vulnerability has been found in DomainMod up to 4.11.01 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file assets/add/registrar.php of the component Registrar Handler. The manipulation of the argument notes leads to cross site scripting.
This vulnerability is known as CVE-2018-19752. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2021-4293 | gnuboard youngcart5 up to 5.4.5.1 adm/menu_list_update.php me_link cross site scripting
1 year 1 month ago
A vulnerability classified as problematic has been found in gnuboard youngcart5 up to 5.4.5.1. Affected is an unknown function of the file adm/menu_list_update.php. The manipulation of the argument me_link leads to cross site scripting. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is traded as CVE-2021-4293. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-30519 | Reprise RLM License Administration 14.2BL4 Password cross site scripting (EDB-51188)
1 year 1 month ago
A vulnerability was found in Reprise RLM License Administration 14.2BL4. It has been classified as problematic. This affects an unknown part. The manipulation of the argument Password leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2022-30519. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2020-36637 | Chris92de AdminServ adminserv.php text cross site scripting
1 year 1 month ago
A vulnerability was found in Chris92de AdminServ. It has been declared as problematic. This vulnerability affects unknown code of the file resources/core/adminserv.php. The manipulation of the argument text leads to cross site scripting. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability was named CVE-2020-36637. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2020-36638 | Chris92de AdminServ adminserv.php Error cross site scripting
1 year 1 month ago
A vulnerability was found in Chris92de AdminServ. It has been rated as problematic. This issue affects some unknown processing of the file resources/core/adminserv.php. The manipulation of the argument Error leads to cross site scripting. This vulnerability only affects products that are no longer supported by the maintainer.
The identification of this vulnerability is CVE-2020-36638. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-4861 | M-Files Server up to 22.3.11237.1 Token incorrect implementation of authentication algorithm
1 year 1 month ago
A vulnerability has been found in M-Files Server up to 22.3.11237.1 and classified as problematic. This vulnerability affects unknown code of the component Token Handler. The manipulation leads to incorrect implementation of authentication algorithm.
This vulnerability was named CVE-2022-4861. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-8128 | LibTIFF up to 4.0.3 TIFF Image out-of-bounds write (Nessus ID 83499 / ID 123680)
1 year 1 month ago
A vulnerability, which was classified as critical, was found in LibTIFF up to 4.0.3. This affects an unknown part of the component TIFF Image Handler. The manipulation leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2014-8128. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
Бреши в Rack: точка + слэш = все секреты с сервера Ruby
1 year 1 month ago
Хочешь читать чужие файлы — Rack уже готов помочь.
Obfuscation Techniques: A Key Weapon in the Ongoing War Between Hackers and Defenders
1 year 1 month ago
Obfuscation stands as a powerful weapon for attackers seeking to shield their malicious code from defenders. This technique, which deliberately makes code hard to understand while preserving its functionality, is a cornerstone of the ongoing struggle between black hats and white hats. From penetration testers to antivirus developers, reverse engineers face an uphill battle against […]
The post Obfuscation Techniques: A Key Weapon in the Ongoing War Between Hackers and Defenders appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Aman Mishra
通用第二期,万元奖励金,更有拍立得/冰块键盘!
1 year 1 month ago
本次活动涵盖通用2.0、通用1.0
通用第二期,万元奖励金,更有拍立得/冰块键盘!
1 year 1 month ago
本次活动涵盖通用2.0、通用1.0
CVE-2025-4005 | PHPGurukul COVID19 Testing Management System 1.0 /patient-report.php searchdata sql injection
1 year 1 month ago
A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /patient-report.php. The manipulation of the argument searchdata leads to sql injection.
The identification of this vulnerability is CVE-2025-4005. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-4006 | youyiio BeyongCms 1.6.0 Document Management Page /admin/theme/Upload.html File unrestricted upload
1 year 1 month ago
A vulnerability classified as critical has been found in youyiio BeyongCms 1.6.0. Affected is an unknown function of the file /admin/theme/Upload.html of the component Document Management Page. The manipulation of the argument File leads to unrestricted upload.
This vulnerability is traded as CVE-2025-4006. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2017-20158 | vova07 Yii2 FileAPI Widget up to 0.1.8 actions/UploadAction.php run File cross site scripting
1 year 1 month ago
A vulnerability was found in vova07 Yii2 FileAPI Widget up to 0.1.8. It has been declared as problematic. Affected by this vulnerability is the function run of the file actions/UploadAction.php. The manipulation of the argument File leads to cross site scripting. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is known as CVE-2017-20158. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-10007 | 82Flex WEIPDCRM cross site scripting
1 year 1 month ago
A vulnerability was found in 82Flex WEIPDCRM and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is handled as CVE-2015-10007. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2021-30558 | Google Chrome up to 90.0.4430.212 HTML Page ui layer
1 year 1 month ago
A vulnerability, which was classified as critical, has been found in Google Chrome. This issue affects some unknown processing of the component HTML Page. The manipulation leads to improper restriction of rendered ui layers.
The identification of this vulnerability is CVE-2021-30558. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-48197 | YUI2 up to 2800 TreeView cross site scripting (EDB-51198)
1 year 1 month ago
A vulnerability was found in YUI2 up to 2800. It has been classified as problematic. Affected is an unknown function of the component TreeView. The manipulation leads to cross site scripting. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is traded as CVE-2022-48197. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com