Aggregator
SecWiki News 2025-07-02 Review
5 months 2 weeks ago
今日暂未更新资讯~
更多最新文章,请访问SecWiki
更多最新文章,请访问SecWiki
Google Chrome security advisory (AV25-385)
5 months 2 weeks ago
Canadian Centre for Cyber Security
Пока другие генерят котиков, Baidu запустила ИИ, способный оживлять любую фантазию
5 months 2 weeks ago
Пока корпорации получают лучшее, простых пользователей снова оставляют за дверью.
CVE-2023-24163 | Dromara HuTool 5.8.11 Aviator Template Engine sql injection (EUVD-2023-0359)
5 months 2 weeks ago
A vulnerability was found in Dromara HuTool 5.8.11. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Aviator Template Engine. The manipulation leads to sql injection.
This vulnerability is known as CVE-2023-24163. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2023-0312 | thorsten phpmyfaq up to 3.1.9 cross site scripting (EUVD-2023-0350)
5 months 2 weeks ago
A vulnerability was found in thorsten phpmyfaq up to 3.1.9 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2023-0312. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-47042 | Mingsoft MCMS up to 5.2.10 writeFileContent.do unrestricted upload (EUVD-2023-0354)
5 months 2 weeks ago
A vulnerability was found in Mingsoft MCMS up to 5.2.10. It has been rated as critical. This issue affects some unknown processing of the file ms/template/writeFileContent.do. The manipulation leads to unrestricted upload.
The identification of this vulnerability is CVE-2022-47042. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2023-24428 | Bitbucket OAuth Plugin up to 0.12 on Jenkins cross-site request forgery (EUVD-2023-0356)
5 months 2 weeks ago
A vulnerability was found in Bitbucket OAuth Plugin up to 0.12 on Jenkins. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2023-24428. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-24459 | Jenkins BearyChat Plugin up to 3.0.2 URL permission (EUVD-2023-0355)
5 months 2 weeks ago
A vulnerability was found in Jenkins BearyChat Plugin up to 3.0.2. It has been classified as critical. This affects an unknown part of the component URL Handler. The manipulation leads to permission issues.
This vulnerability is uniquely identified as CVE-2023-24459. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2023-24449 | PWauth Security Realm Plugin up to 0.4 on Jenkins Controller File System permission (EUVD-2023-0347)
5 months 2 weeks ago
A vulnerability has been found in PWauth Security Realm Plugin up to 0.4 on Jenkins and classified as critical. This vulnerability affects unknown code of the component Controller File System Handler. The manipulation leads to permission issues.
This vulnerability was named CVE-2023-24449. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2023-24458 | BearyChat Plugin up to 3.0.2 on Jenkins URL cross-site request forgery (EUVD-2023-0346)
5 months 2 weeks ago
A vulnerability classified as problematic was found in BearyChat Plugin up to 3.0.2 on Jenkins. This vulnerability affects unknown code of the component URL Handler. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2023-24458. The attack can be initiated remotely. There is no exploit available.
vuldb.com
Concentric AI Expands Data Security Ambitions With Swift Security, Acante Acquisitions
5 months 2 weeks ago
Data security governance provider Concentric AI announced its acquisition of Swift Security and Acante, two AI-driven security startups, in a move Concentric AI founder and CEO Karthik Krishnan hopes will reshape enterprise data protection.
The post Concentric AI Expands Data Security Ambitions With Swift Security, Acante Acquisitions appeared first on Security Boulevard.
George V. Hulme
Hacker with ‘political agenda’ stole data from Columbia, university says
5 months 2 weeks ago
Columbia University said the hacker stole data from a “limited portion" of its network but that it was still determining the size of the breach.
WorldLeaks
5 months 2 weeks ago
You must login to view this content
cohenido
Types of VPN
5 months 2 weeks ago
Types of VPN
Dark Web Informer - Cyber Threat Intelligence
Android SMS Stealer Infects 100,000 Devices in Uzbekistan
5 months 2 weeks ago
New Android malware Qwizzserial has infected 100,000 devices, primarily in Uzbekistan, stealing SMS data via Telegram distribution
CVE-2005-1346 | Symantec AntiVirus 4.3.7.27/2005 11.0.0 RAR Archive denial of service (ID 38427 / XFDB-20294)
5 months 2 weeks ago
A vulnerability has been found in Symantec AntiVirus 4.3.7.27/2005 11.0.0 and classified as critical. This vulnerability affects unknown code of the component RAR Archive Handler. The manipulation leads to denial of service.
This vulnerability was named CVE-2005-1346. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2005-1346 | Symantec Mail Security up to 4.1.4.30 RAR Archive denial of service (ID 38427 / SA15153)
5 months 2 weeks ago
A vulnerability was found in Symantec Mail Security up to 4.1.4.30 and classified as critical. This issue affects some unknown processing of the component RAR Archive Handler. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2005-1346. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2005-1381 | Oracle Application Server 10g Web Cache webcacheadmin cache_dump_file cross site scripting (EDB-25562 / Nessus ID 18175)
5 months 2 weeks ago
A vulnerability classified as critical has been found in Oracle Application Server 10g. Affected is an unknown function of the file webcacheadmin of the component Web Cache. The manipulation of the argument cache_dump_file leads to basic cross site scripting.
This vulnerability is traded as CVE-2005-1381. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2005-1381 | Oracle Application Server 9 Web Cache webcacheadmin cache_dump_file cross site scripting (EDB-25562 / Nessus ID 18175)
5 months 2 weeks ago
A vulnerability classified as critical was found in Oracle Application Server 9. Affected by this vulnerability is an unknown functionality of the file webcacheadmin of the component Web Cache. The manipulation of the argument cache_dump_file leads to basic cross site scripting.
This vulnerability is known as CVE-2005-1381. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com