Aggregator
报名学习 | 国内最专业、最全面的 [ .NET 代码审计 ] 体系化视频学习课程
2 months ago
.NET 2025年第 76 期工具库和资源汇总
2 months ago
01阅读须知此文所提供的信息只为网络安全人员对自己所负责的网站、服务器等(包括但不限于)进行检测或维护参考,未
CVE-2015-1679 | Microsoft Windows Server 2003 SP2 up to Server 2012 R2 Kernel-Mode Driver information disclosure (MS15-051 / EDB-37049)
2 months ago
A vulnerability, which was classified as problematic, was found in Microsoft Windows. This affects an unknown part of the component Kernel-Mode Driver. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2015-1679. Attacking locally is a requirement. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Google генерирует фальшивые подкасты из поисковых запросов. Абсурд или новая реальность?
2 months ago
2025-06-13: Traffic analysis exercise: It's a trap!
2 months ago
CVE-2025-6059 | Seraphinite Solutions Seraphinite Accelerator Plugin up to 2.27.21 on WordPress OnAdminApi_CacheOpBegin cross-site request forgery (EUVD-2025-18319)
2 months ago
A vulnerability was found in Seraphinite Solutions Seraphinite Accelerator Plugin up to 2.27.21 on WordPress. It has been declared as problematic. This vulnerability affects the function OnAdminApi_CacheOpBegin. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2025-6059. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2011-2960 | Sunwayland ForceControl 6.1 httpsvr.exe memory corruption (EDB-35864 / SBV-31859)
2 months ago
A vulnerability was found in Sunwayland ForceControl 6.1. It has been declared as very critical. Affected by this vulnerability is an unknown functionality of the file httpsvr.exe. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2011-2960. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2000-0835 | Sambar Server 4.3/4.4 ISAPI Search Utility search.dll Query privileges management (EDB-20223 / Nessus ID 10514)
2 months ago
A vulnerability classified as critical has been found in Sambar Server 4.3/4.4. Affected is an unknown function in the library search.dll of the component ISAPI Search Utility. The manipulation of the argument Query leads to improper privilege management.
This vulnerability is traded as CVE-2000-0835. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2004-1735 | Sympa 4.0/4.1/4.1.1/4.1.2 Description cross site scripting (EDB-24389 / Nessus ID 14323)
2 months ago
A vulnerability classified as problematic was found in Sympa 4.0/4.1/4.1.1/4.1.2. Affected by this vulnerability is an unknown functionality. The manipulation of the argument Description leads to basic cross site scripting.
This vulnerability is known as CVE-2004-1735. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-4232 | Palo Alto GlobalProtect App up to 6.0.0/6.1.0/6.2.8-h1/6.3.2 Log Collection wildcards or matching symbols (Nessus ID 238432)
2 months ago
A vulnerability, which was classified as critical, has been found in Palo Alto GlobalProtect App up to 6.0.0/6.1.0/6.2.8-h1/6.3.2. Affected by this issue is some unknown functionality of the component Log Collection. The manipulation leads to improper neutralization of wildcards or matching symbols.
This vulnerability is handled as CVE-2025-4232. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-36633 | Tenable Agent up to 10.8.4 on Windows privileges management (EUVD-2025-18279 / Nessus ID 238433)
2 months ago
A vulnerability classified as critical was found in Tenable Agent up to 10.8.4 on Windows. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper privilege management.
This vulnerability is known as CVE-2025-36633. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-36631 | Tenable Agent up to 10.8.4 on Windows privileges management (EUVD-2025-18277 / Nessus ID 238433)
2 months ago
A vulnerability, which was classified as critical, has been found in Tenable Agent up to 10.8.4 on Windows. Affected by this issue is some unknown functionality. The manipulation leads to improper privilege management.
This vulnerability is handled as CVE-2025-36631. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2002-0189 | Microsoft Internet Explorer 6.0 Local HTML HTML injection (MS02-023 / EDB-21750)
2 months ago
A vulnerability was found in Microsoft Internet Explorer 6.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Local HTML Handler. The manipulation leads to HTML injection.
This vulnerability is known as CVE-2002-0189. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2017-2531 | Apple tvOS up to 10.2.0 WebKit memory corruption (HT207801 / EDB-42104)
2 months ago
A vulnerability was found in Apple tvOS up to 10.2.0. It has been rated as critical. Affected by this issue is the function emitPutDerivedConstructorToArrowFunctionContextScope of the component WebKit. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2017-2531. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2006-0418 | Topcmm Computing 123 Flash Chat Server 5.0 memory corruption (EDB-27121 / BID-16360)
2 months ago
A vulnerability was found in Topcmm Computing 123 Flash Chat Server 5.0. It has been classified as critical. This affects an unknown part. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2006-0418. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2004-2702 | Swsoft Plesk 7.0/7.1 login_up.php3 login_name cross site scripting (EDB-24405 / Nessus ID 14369)
2 months ago
A vulnerability was found in Swsoft Plesk 7.0/7.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the file login_up.php3. The manipulation of the argument login_name leads to cross site scripting.
This vulnerability is handled as CVE-2004-2702. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2011-4800 | Serv-U up to 7.1.0.2 path traversal (EDB-18182 / SA47021)
2 months ago
A vulnerability was found in Serv-U. It has been classified as critical. This affects an unknown part. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2011-4800. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2011-2950 | RealNetworks RealPlayer up to 14.0.5 qcpfformat.dll memory corruption (EDB-17849 / Nessus ID 55908)
2 months ago
A vulnerability was found in RealNetworks RealPlayer. It has been declared as very critical. Affected by this vulnerability is an unknown functionality in the library qcpfformat.dll. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2011-2950. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2019-19208 | Codiad Web IDE up to 2.8.4 code injection (ID 162753 / EDB-49902)
2 months ago
A vulnerability was found in Codiad Web IDE up to 2.8.4. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to code injection.
This vulnerability was named CVE-2019-19208. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com