Aggregator
.NET 内网实战:通过 EnumSystemCodePagesA 函数执行 ShellCode
2 months 1 week ago
基于 ViewState 反序列化漏洞,通过 Sharp4ViewStateShell 执行命令实现权限维持
2 months 1 week ago
metlo: open-source API security platform
2 months 1 week ago
Metlo Metlo is an open-source API security platform Create an Inventory of all your API Endpoints. Proactively test your APIs before they go into production. Detect API attacks in real-time. Features Endpoint Discovery –...
The post metlo: open-source API security platform appeared first on Penetration Testing Tools.
ddos
Driving Success on the Track or in the Boardroom
2 months 1 week ago
Discover how the Trend Micro and the NEOM McLaren Formula E Team partnership is powered by a common vision for winning, on the track and in the boardroom.
Dhanya Thakkar
《政务数据共享条例》公布!开启数字政府法治新纪元
2 months 1 week ago
五大制度创新破解数据共享顽疾!
CVE-2023-49739 | PowerPack Pro for Elementor Plugin up to 2.9.23 on WordPress cross site scripting (EUVD-2023-53662)
2 months 1 week ago
A vulnerability was found in PowerPack Pro for Elementor Plugin up to 2.9.23 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2023-49739. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2023-50342 | HCL DRYiCE MyXalytics 5.9/6.0/6.1 resource injection (KB0109608 / EUVD-2023-55143)
2 months 1 week ago
A vulnerability, which was classified as critical, was found in HCL DRYiCE MyXalytics 5.9/6.0/6.1. Affected is an unknown function. The manipulation leads to improper control of resource identifiers.
This vulnerability is traded as CVE-2023-50342. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2023-51812 | Tenda AX3 16.03.12.11 Parameter SetNetControlList list privilege escalation (EUVD-2023-56496)
2 months 1 week ago
A vulnerability was found in Tenda AX3 16.03.12.11 and classified as critical. Affected by this issue is some unknown functionality of the file /goform/SetNetControlList of the component Parameter Handler. The manipulation of the argument list leads to privilege escalation.
This vulnerability is handled as CVE-2023-51812. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-20971 | Oracle MySQL Server 8.0.35 and prior/8.2.0 and prior Optimizer denial of service (EUVD-2024-18685 / Nessus ID 235542)
2 months 1 week ago
A vulnerability classified as critical was found in Oracle MySQL Server 8.0.35 and prior/8.2.0 and prior. Affected by this vulnerability is an unknown functionality of the component Optimizer. The manipulation leads to denial of service.
This vulnerability is known as CVE-2024-20971. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-45718 | HCL Sametime up to 12.0.1 FP1 session expiration (KB0109082 / EUVD-2023-50007)
2 months 1 week ago
A vulnerability was found in HCL Sametime up to 12.0.1 FP1 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to session expiration.
This vulnerability is handled as CVE-2023-45718. The attack may be launched remotely. There is no exploit available.
vuldb.com
Daily Dose of Dark Web Informer - 3rd of June 2025
2 months 1 week ago
This daily article is intended to make it easier for those who want to stay updated with my regular Dark Web Informer and X/Twitter posts.
Dark Web Informer - Cyber Threat Intelligence
栈溢出从复现到挖掘-CVE-2018-16333漏洞复现详解
2 months 1 week ago
分析栈溢出,观察栈变化
CVE-2013-6128 | WellinTech KingView 6.52 ActiveX Control KChartXY.ocx pathname access control (EDB-28085 / ID 121440)
2 months 1 week ago
A vulnerability, which was classified as problematic, was found in WellinTech KingView 6.52. Affected is an unknown function in the library KCHARTXYLib.KChartXY of the file KChartXY.ocx of the component ActiveX Control. The manipulation of the argument pathname leads to improper access controls.
This vulnerability is traded as CVE-2013-6128. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
主权云研究报告:定义、技术架构、国家战略与AI能力提升路径
2 months 1 week ago
AI时代的基础设施
Threat Attack Daily - 3rd of June 2025
2 months 1 week ago
Threat Attack Daily - 3rd of June 2025
Dark Web Informer - Cyber Threat Intelligence
CVE-2023-6158 | EventON Plugin up to 2.2.7/4.5.4 on WordPress evo_eventpost_update_meta authorization (ID 3017578)
2 months 1 week ago
A vulnerability, which was classified as problematic, has been found in EventON Plugin up to 2.2.7/4.5.4 on WordPress. Affected by this issue is the function evo_eventpost_update_meta. The manipulation leads to missing authorization.
This vulnerability is handled as CVE-2023-6158. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-47994 | FreeImage 3.18.0 PluginBMP.cpp LoadPixelDataRLE4 integer overflow
2 months 1 week ago
A vulnerability was found in FreeImage 3.18.0. It has been declared as critical. This vulnerability affects the function LoadPixelDataRLE4 of the file PluginBMP.cpp. The manipulation leads to integer overflow.
This vulnerability was named CVE-2023-47994. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2023-47997 | FreeImage 3.18.0 BitmapAccess.cpp FreeImage_AllocateBitmap denial of service
2 months 1 week ago
A vulnerability classified as problematic was found in FreeImage 3.18.0. Affected by this vulnerability is the function FreeImage_AllocateBitmap of the file BitmapAccess.cpp. The manipulation leads to denial of service.
This vulnerability is known as CVE-2023-47997. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-50136 | JFinalcms 5.0.0 New Custom Table Creation Name cross site scripting
2 months 1 week ago
A vulnerability was found in JFinalcms 5.0.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component New Custom Table Creation. The manipulation of the argument Name leads to cross site scripting.
This vulnerability is known as CVE-2023-50136. The attack can be launched remotely. There is no exploit available.
vuldb.com