Aggregator
CVE-2023-34657 | EyouCMS 1.6.2 web_recordnum cross site scripting (Issue 43)
1 year 1 month ago
A vulnerability was found in EyouCMS 1.6.2. It has been classified as problematic. Affected is an unknown function. The manipulation of the argument web_recordnum leads to cross site scripting.
This vulnerability is traded as CVE-2023-34657. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2023-2654 | Conditional Menus Plugin up to 1.2.0 on WordPress Attribute cross site scripting
1 year 1 month ago
A vulnerability was found in Conditional Menus Plugin up to 1.2.0 on WordPress. It has been rated as problematic. This issue affects some unknown processing of the component Attribute Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2023-2654. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-2684 | File Renaming on Upload Plugin up to 2.5.1 on WordPress Setting cross site scripting
1 year 1 month ago
A vulnerability classified as problematic has been found in File Renaming on Upload Plugin up to 2.5.1 on WordPress. Affected is an unknown function of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2023-2684. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-2779 | Social Share, Social Login and Social Comments Plugin cross site scripting (ID 173053 / EDB-51534)
1 year 1 month ago
A vulnerability, which was classified as problematic, has been found in Social Share, Social Login and Social Comments Plugin 7.13.30 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2023-2779. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-2399 | QuBot Plugin up to 1.1.5 on WordPress Chat cross site scripting
1 year 1 month ago
A vulnerability has been found in QuBot Plugin up to 1.1.5 on WordPress and classified as problematic. This vulnerability affects unknown code of the component Chat Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2023-2399. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Why NHIs Are Security's Most Dangerous Blind Spot
1 year 1 month ago
When we talk about identity in cybersecurity, most people think of usernames, passwords, and the occasional MFA prompt. But lurking beneath the surface is a growing threat that does not involve human credentials at all, as we witness the exponential growth of Non-Human Identities (NHIs).
At the top of mind when NHIs are mentioned, most security teams immediately think of Service Accounts.
The Hacker News
Google считает, что пара вопросов к ИИ стоит сотни миллиардов: кто ещё хочет попробовать?
1 year 1 month ago
Экономика целой страны — в голове секретаря, который боится ИИ.
观点 | 切实筑牢网络意识形态安全防线
1 year 1 month ago
互联网作为意识形态传播的重要载体,其强大的传播能力和广泛的覆盖面,成为意识形态斗争的主战场、主阵地、最前沿。各种思想观念、价值取向在网络空间汇聚、交锋、碰撞,网络舆论环境复杂多变,给我国意识形态安全带来了严峻挑战。
行业 | IIFAA推出业内首个智能体可信互连技术ASL并宣布开源
1 year 1 month ago
24日消息,业内首个智能体可信互连技术ASL发布,该技术可以在MCP等协议的基础之上,保障各个智能体协作中在权限等方面的安全,为Agent互连提供安全、可信的协作保障。
专家观点 | 合力筑牢个人信息保护屏障
1 year 1 month ago
个人信息保护是数字时代的重要议题,是社会治理的底线。只有强化协同治理,构建全方位、多层次的保护体系,才能有效遏制个人信息违法犯罪活动,推动数字社会长远健康发展。
前沿 | 如何规避人工智能带来的政务服务风险
1 year 1 month ago
我们应该看到人工智能技术下的政务应用在提升效能的同时,其所带来的政务员工失业风险、政务算法黑箱、政务数据安全泄露风险等也亟待防范。如何在拥抱技术红利的同时规避潜在政务服务风险,是数字政府建设面临的关键课题。
预警 | 远程控制、窃密、挖矿!我国境内捕获“银狐”木马病毒变种
1 year 1 month ago
近日,国家计算机病毒应急处理中心和计算机病毒防治技术国家工程实验室依托国家计算机病毒协同分析平台在我国境内连续捕获一系列针对我国网络用户,特别是财务和税务工作人员用户的木马病毒。
专题·数据安全流通 | 推动数据要素安全流通的机制与技术
1 year 1 month ago
数据作为新质生产力的优质生产要素,已快速融入各个环节,通过其独特的价值增值方式促进科技革命和产业变革。在数据要素价值释放的过程中,流通环节起着至关重要的作用。数据安全流通在数据要素市场化配置中占据重要地位,是推动数字经济发展的关键动力。
Marineschepen Luymes en Schiedam terug uit Oostzee
1 year 1 month ago
Hydrografisch opnemingsvaartuig Zr.Ms. Luymes en mijnenjager Zr.Ms. Schiedam zijn vandaag teruggekeerd in Den Helder. Beide opereerden op de Oostzee. Daar maakten de schepen afgelopen maanden deel uit van de Standing NATO Mine Countermeasures Group 1 (SNMCMG1). Beveiliging van onderzeese infrastructuur stond binnen dit NAVO-vlootverband centraal.
Citrix NetScaler 漏洞引发权限危机,企业安全防线告急
1 year 1 month ago
安全客
CVE-2023-2811 | AI ChatBot Plugin up to 4.5.5 on WordPress Setting cross site scripting
1 year 1 month ago
A vulnerability was found in AI ChatBot Plugin up to 4.5.5 on WordPress and classified as problematic. This issue affects some unknown processing of the component Setting Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2023-2811. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-3320 | WP Sticky Social Plugin up to 1.0.1 on WordPress cross-site request forgery (ID 173048 / EDB-51533)
1 year 1 month ago
A vulnerability was found in WP Sticky Social Plugin up to 1.0.1 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2023-3320. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2020-20725 | taogogo taoCMS 2.5 beta5.1 admin.php Name cross site scripting
1 year 1 month ago
A vulnerability was found in taogogo taoCMS 2.5 beta5.1 and classified as problematic. This issue affects some unknown processing of the file admin.php. The manipulation of the argument Name leads to cross site scripting.
The identification of this vulnerability is CVE-2020-20725. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2020-20070 | wkeyuan DWSurvey 1.0 qu-multi-fillblank!answers.action thequltemld cross site scripting (Issue 48)
1 year 1 month ago
A vulnerability was found in wkeyuan DWSurvey 1.0. It has been classified as problematic. Affected is an unknown function of the file qu-multi-fillblank!answers.action. The manipulation of the argument thequltemld leads to cross site scripting.
This vulnerability is traded as CVE-2020-20070. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com