Aggregator
某微信小程序未授权漏洞挖掘(置空查询思路)
3 months 1 week ago
Submit #521506: code-projects.org Online Notice Board Using PHP With Source Code V1 SQL Injection [Duplicate]
3 months 1 week ago
Submit #521506 / VDB-249692
Xuezhi_Wang
VDB-300707 | Microsoft Azure iPaaS Services access control
3 months 1 week ago
A vulnerability was found in Microsoft Azure. It has been rated as problematic. This issue affects some unknown processing of the component iPaaS Services. The manipulation leads to improper access controls.
The attack may be initiated remotely. There is no exploit available.
This product is a managed service. It is not possible for users to maintain vulnerability countermeasures themselves. It is recommended to change the configuration settings.
vuldb.com
VDB-300706 | Microsoft Azure Key Vault permission
3 months 1 week ago
A vulnerability was found in Microsoft Azure Key Vault. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to permission issues.
The attack can be initiated remotely. Furthermore, there is an exploit available.
This product is available as a managed service. Users are not able to maintain vulnerability countermeasures themselves. It is recommended to change the configuration settings.
vuldb.com
Submit #521454: PHPGurukul eLearning System V1.0 Unrestricted Upload [Accepted]
3 months 1 week ago
Submit #521454 / VDB-300708
CVE-2025-1446 | Pods Plugin 3.2.7.1/3.2.8.1 on WordPress sql injection
3 months 1 week ago
A vulnerability was found in Pods Plugin 3.2.7.1/3.2.8.1 on WordPress. It has been classified as critical. This affects an unknown part. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-1446. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-0718 | Kyle Phillips Nested Pages Plugin up to 3.2.12 on WordPress cross site scripting
3 months 1 week ago
A vulnerability was found in Kyle Phillips Nested Pages Plugin up to 3.2.12 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-0718. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-2686 | mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 Backend /admin/ doFilter Request access control (IBTS25)
3 months 1 week ago
A vulnerability has been found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as critical. Affected by this vulnerability is the function doFilter of the file /admin/ of the component Backend. The manipulation of the argument Request leads to improper access controls.
This vulnerability is known as CVE-2025-2686. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #521449: 明月复苏 图书管理系统 null Broken Access Control [Accepted]
3 months 1 week ago
Submit #521449 / VDB-300703
enenen
CVE-2006-2661 | Freetype up to 2.1.10 ftutil.c denial of service (Bug 183676 / EDB-27993)
3 months 1 week ago
A vulnerability was found in Freetype up to 2.1.10 and classified as problematic. This issue affects some unknown processing of the file ftutil.c. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2006-2661. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-23141 | Autodesk AutoCAD MODEL File Parser out-of-bounds
3 months 1 week ago
A vulnerability was found in Autodesk AutoCAD. It has been rated as critical. Affected by this issue is some unknown functionality of the component MODEL File Parser. The manipulation leads to out-of-bounds read.
This vulnerability is handled as CVE-2024-23141. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-23140 | Autodesk AutoCAD 3DM File Parser out-of-bounds
3 months 1 week ago
A vulnerability classified as critical has been found in Autodesk AutoCAD. This affects an unknown part of the component 3DM File Parser. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2024-23140. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-23140 | Autodesk AutoCAD MODEL File Parser out-of-bounds
3 months 1 week ago
A vulnerability classified as critical was found in Autodesk AutoCAD. This vulnerability affects unknown code of the component MODEL File Parser. The manipulation leads to out-of-bounds read.
This vulnerability was named CVE-2024-23140. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-23145 | Autodesk AutoCAD PRT File Parser out-of-bounds
3 months 1 week ago
A vulnerability, which was classified as problematic, has been found in Autodesk AutoCAD. This issue affects some unknown processing of the component PRT File Parser. The manipulation leads to out-of-bounds read.
The identification of this vulnerability is CVE-2024-23145. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-23144 | Autodesk AutoCAD CATPART File Parser out-of-bounds
3 months 1 week ago
A vulnerability, which was classified as critical, was found in Autodesk AutoCAD. Affected is an unknown function of the component CATPART File Parser. The manipulation leads to out-of-bounds read.
This vulnerability is traded as CVE-2024-23144. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-37005 | Autodesk AutoCAD X_B File Parser out-of-bounds
3 months 1 week ago
A vulnerability has been found in Autodesk AutoCAD and classified as critical. Affected by this vulnerability is an unknown functionality of the component X_B File Parser. The manipulation leads to out-of-bounds read.
This vulnerability is known as CVE-2024-37005. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-37004 | Autodesk AutoCAD SLDPRT File Parser use after free
3 months 1 week ago
A vulnerability was found in Autodesk AutoCAD and classified as critical. Affected by this issue is some unknown functionality of the component SLDPRT File Parser. The manipulation leads to use after free.
This vulnerability is handled as CVE-2024-37004. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-4666 | Xceedium Xsuite 2.3.0/2.4.3 opm/read_sessionlog.php logFile path traversal (ID 132809 / EDB-37708)
3 months 1 week ago
A vulnerability classified as critical has been found in Xceedium Xsuite 2.3.0/2.4.3. This affects an unknown part of the file opm/read_sessionlog.php. The manipulation of the argument logFile with the input ....// leads to path traversal.
This vulnerability is uniquely identified as CVE-2015-4666. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Week in review: Veeam Backup & Replication RCE fixed, free file converter sites deliver malware
3 months 1 week ago
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Critical Veeam Backup & Replication RCE vulnerability fixed, patch ASAP! (CVE-2025-23120) Veeam has released fixes for a critical remote code execution vulnerability (CVE-2025-23120) affecting its enterprise Veeam Backup & Replication solution, and is urging customers to quickly upgrade to a fixed version. FBI: Free file converter sites and tools deliver malware Malware peddlers are increasingly targeting users who are searching … More →
The post Week in review: Veeam Backup & Replication RCE fixed, free file converter sites deliver malware appeared first on Help Net Security.
Help Net Security