Aggregator
为什么“建体系”无法阻挡勒索病毒?斗象CPS渗透脆弱性模拟演练来回答
5 months ago
CVE-2024-9044 | msg Suisse AG EasyTax up to 2021/2022 1.3/2023 1.2 xml external entity reference
5 months ago
A vulnerability was found in msg Suisse AG EasyTax up to 2021/2022 1.3/2023 1.2. It has been classified as critical. Affected is an unknown function. The manipulation leads to xml external entity reference.
This vulnerability is traded as CVE-2024-9044. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-11014 | NEC UNIVERGE IX up to 10.8.27/10.9.14/10.10.21 Management Interface cross-site request forgery
5 months ago
A vulnerability was found in NEC UNIVERGE IX up to 10.8.27/10.9.14/10.10.21 and classified as problematic. This issue affects some unknown processing of the component Management Interface. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2024-11014. The attack may be initiated remotely. There is no exploit available.
vuldb.com
第十二版《网络安全企业100强》发布
5 months ago
为了更加真实、全面、客观地展现国内网络安全厂商的现状,发现其中真正有能力、可落地、引领创新的安全品牌,同时也帮 […]
aqniu
CVE-2024-11981 | Billion Electric M100/M150/M120N/M500 prior 1.04.1.592.8/1.04.1.613.13/1.04.1.675 authentication bypass
5 months ago
A vulnerability has been found in Billion Electric M100, M150, M120N and M500 and classified as critical. This vulnerability affects unknown code. The manipulation leads to authentication bypass using alternate channel.
This vulnerability was named CVE-2024-11981. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-11482 | Trellix Enterprise Security Manager 11.6.12 Snowservice API os command injection
5 months ago
A vulnerability, which was classified as very critical, was found in Trellix Enterprise Security Manager 11.6.12. This affects an unknown part of the component Snowservice API. The manipulation leads to os command injection.
This vulnerability is uniquely identified as CVE-2024-11482. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-11013 | NEC UNIVERGE IX/UNIVERGE IX-R/IX-V Management Interface command injection
5 months ago
A vulnerability, which was classified as critical, has been found in NEC UNIVERGE IX, UNIVERGE IX-R and IX-V. Affected by this issue is some unknown functionality of the component Management Interface. The manipulation leads to command injection.
This vulnerability is handled as CVE-2024-11013. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-11481 | Trellix Enterprise Security Manager 11.6.12 Snowservice API path traversal
5 months ago
A vulnerability classified as critical was found in Trellix Enterprise Security Manager 11.6.12. Affected by this vulnerability is an unknown functionality of the component Snowservice API. The manipulation leads to path traversal.
This vulnerability is known as CVE-2024-11481. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-11983 | Billion Electric M100/M150/M120N/M500 prior 1.04.1.592.8/1.04.1.613.13/1.04.1.675 SSH os command injection
5 months ago
A vulnerability classified as critical has been found in Billion Electric M100, M150, M120N and M500. Affected is an unknown function of the component SSH. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2024-11983. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-11982 | Billion Electric M100/M150/M120N/M500 prior 1.04.1.592.8/1.04.1.613.13/1.04.1.675 Setting credentials storage
5 months ago
A vulnerability was found in Billion Electric M100, M150, M120N and M500. It has been rated as problematic. This issue affects some unknown processing of the component Setting Handler. The manipulation leads to unprotected storage of credentials.
The identification of this vulnerability is CVE-2024-11982. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-11980 | Billion Electric M100/M150/M120N/M500 prior 1.04.1.592.8/1.04.1.675/1.04.613.13 missing authentication
5 months ago
A vulnerability was found in Billion Electric M100, M150, M120N and M500. It has been declared as very critical. This vulnerability affects unknown code. The manipulation leads to missing authentication.
This vulnerability was named CVE-2024-11980. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Музыка в нашем ДНК: язык и ритм – близкие родственники?
5 months ago
Ученые нашли неожиданную связь между мелодией и человеческой речью.
太极股份发布可信数据空间产品,推动数据要素安全有序流通
5 months ago
11 月 28 日,太极计算机股份有限公司(简称“太极股份”)在中国电科太极信息产业园召开发布会,面向市场发布 […]
aqniu
Цензура в арабском мире: как кибербезопасность стала инструментом репрессий
5 months ago
Правозащитники рассказали, как власти используют законы в своих интересах.
Возрождение Вояджер-1: как легендарный зонд спасали от гибели с расстояния 25 млрд км
5 months ago
В этом году аппарат прошел очередную проверку на прочность.
Zello urges users to reset passwords following a cyber attack
5 months ago
Zello urges users to reset passwords following a cyber attack P
CVE-2009-1652 | 2daybiz Business Community Script adminaddeditdetails.php access control (EDB-8689 / BID-34976)
5 months ago
A vulnerability classified as critical has been found in 2daybiz Business Community Script. Affected is an unknown function of the file admin/adminaddeditdetails.php. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2009-1652. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-1654 | Easy-scripts Answer/Question Script questiondetail.php questionid cross site scripting (EDB-8690 / BID-34975)
5 months ago
A vulnerability, which was classified as problematic, has been found in Easy-scripts Answer and Question Script. Affected by this issue is some unknown functionality of the file questiondetail.php. The manipulation of the argument questionid leads to cross site scripting.
This vulnerability is handled as CVE-2009-1654. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-1655 | Easy-scripts Answer/Question Script myaccount.php sql injection (EDB-8690 / BID-34975)
5 months ago
A vulnerability, which was classified as critical, was found in Easy-scripts Answer and Question Script. This affects an unknown part of the file myaccount.php. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2009-1655. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to add further authentication.
vuldb.com