Aggregator
$9000 赏金的漏洞
2 months 2 weeks ago
诚邀渠道合作伙伴共启新征程
2 months 2 weeks ago
“易语言定制”助力黑产,溯源开发者多平台账号
2 months 2 weeks ago
近期,火绒安全情报中心监测到一款伪装成Clash(代理工具)的程序正在网络上传播。经溯源分析,这款恶意软件是由易语言编写的木马,其存在相关开发者提供私人定制易语言服务,为他人的黑灰产活动提供支持。目前,火绒安全产品可对上述病毒进行拦截查杀。
诚邀渠道合作伙伴共启新征程
2 months 2 weeks ago
“易语言定制”助力黑产,溯源开发者多平台账号
2 months 2 weeks ago
近期,火绒安全情报中心监测到一款伪装成Clash(代理工具)的程序正在网络上传播。经溯源分析,这款恶意软件是由易语言编写的木马,其存在相关开发者提供私人定制易语言服务,为他人的黑灰产活动提供支持。目前,火绒安全产品可对上述病毒进行拦截查杀。
CVE-2020-11023 | Oracle OSS Support Tools jQuery cross site scripting (EDB-49767 / Nessus ID 208606)
2 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in Oracle OSS Support Tools. Affected by this issue is some unknown functionality of the component jQuery. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2020-11023. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2018-0739 | Oracle Fujitsu M10-1 OpenSSL denial of service (ID 20088 / BID-103518)
2 months 2 weeks ago
A vulnerability classified as critical has been found in Oracle Fujitsu M10-1, Fujitsu M10-4, Fujitsu M10-4S, Fujitsu M12-1, Fujitsu M12-2 and Fujitsu M12-2S. This affects an unknown part of the component OpenSSL. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2018-0739. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-18113 | Atlassian JIRA Server/Data Center up to 8.18.0 DefaultOSWorkflowConfigurator code injection
2 months 2 weeks ago
A vulnerability was found in Atlassian JIRA Server and Data Center up to 8.18.0. It has been classified as critical. Affected is the function DefaultOSWorkflowConfigurator. The manipulation leads to code injection.
This vulnerability is traded as CVE-2017-18113. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-24444 | Create and Manage Taxonomies Plugin up to 3.7.0.1 on WordPress unfiltered_html cross site scripting (EDB-50442)
2 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in Create and Manage Taxonomies Plugin up to 3.7.0.1 on WordPress. Affected is the function unfiltered_html. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2021-24444. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-25791 | SourceCodester Doctor Appointment System 1.0 Update Profile cross site scripting (Exploit 49396 / EDB-49396)
2 months 2 weeks ago
A vulnerability has been found in SourceCodester Doctor Appointment System 1.0 and classified as problematic. This vulnerability affects unknown code of the component Update Profile. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2021-25791. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2015-2100 | WebGate eDVR Manager/Control Center TCPDiscover/TCPDiscover2 stack-based overflow (ID 123487)
2 months 2 weeks ago
A vulnerability was found in WebGate eDVR Manager and Control Center and classified as critical. Affected by this issue is the function TCPDiscover/TCPDiscover2. The manipulation leads to stack-based buffer overflow.
This vulnerability is handled as CVE-2015-2100. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-27365 | IBM MQ Operator up to 3.5.1 CD MQ Queue Manager use after free (Nessus ID 235088)
2 months 2 weeks ago
A vulnerability was found in IBM MQ Operator up to 3.5.1 CD. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component MQ Queue Manager. The manipulation leads to use after free.
This vulnerability is known as CVE-2025-27365. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-43903 | Freedesktop Poppler up to 25.03.x adbe.pkcs7.sha1 Signature NSSCryptoSignBackend.cc signature verification (Nessus ID 235095)
2 months 2 weeks ago
A vulnerability was found in Freedesktop Poppler up to 25.03.x. It has been classified as problematic. Affected is an unknown function of the file NSSCryptoSignBackend.cc of the component adbe.pkcs7.sha1 Signature Handler. The manipulation leads to improper verification of cryptographic signature.
This vulnerability is traded as CVE-2025-43903. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47829 | pnpm up to 9.x MD5 /node_modoules/ weak hash (GHSA-8cc4-rfj6-fhg4 / Nessus ID 235103)
2 months 2 weeks ago
A vulnerability was found in pnpm up to 9.x. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /node_modoules/ of the component MD5 Handler. The manipulation leads to use of weak hash.
This vulnerability is known as CVE-2024-47829. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-43859 | python-hyper h11 up to 0.15.x request smuggling (Nessus ID 235092)
2 months 2 weeks ago
A vulnerability was found in python-hyper h11 up to 0.15.x. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to http request smuggling.
This vulnerability is known as CVE-2025-43859. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2016-1585 | AppArmor Mount 7pk security (Nessus ID 235109)
2 months 2 weeks ago
A vulnerability classified as very critical was found in AppArmor. This vulnerability affects unknown code of the component Mount Handler. The manipulation leads to 7pk security features.
This vulnerability was named CVE-2016-1585. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-4250 | code-projects Nero Social Networking Site 1.0 /index.php sql injection
2 months 2 weeks ago
A vulnerability was found in code-projects Nero Social Networking Site 1.0. It has been classified as critical. This affects an unknown part of the file /index.php. The manipulation of the argument fname/lname/login/password2/cpassword/address/cnumber/email/gender/propic/month leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-4250. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-4249 | PHPGurukul e-Diary Management System 1.0 /manage-categories.php ID sql injection
2 months 2 weeks ago
A vulnerability was found in PHPGurukul e-Diary Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /manage-categories.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is handled as CVE-2025-4249. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #562906: code-projects Nero Social Networking Site In PHP v1.0 SQL Injection [Accepted]
2 months 2 weeks ago
Submit #562906 / VDB-307347
zzzxby