Aggregator
没有眼花,没有看错!额外抽奖机会来了!
6 months 2 weeks ago
Google Researchers Claim First Vulnerability Found Using AI
6 months 2 weeks ago
The flaw, an exploitable stack buffer underflow in SQLite, was found by Google’s Big Sleep team using a large language model (LLM)
CVE-2024-51683 | Michael Gangolf Custom Post Type Templates for Elementor Plugin up to 1.10.1 on WordPress cross site scripting
6 months 2 weeks ago
A vulnerability was found in Michael Gangolf Custom Post Type Templates for Elementor Plugin up to 1.10.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-51683. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-51681 | CodeRevolution WP Pocket URLs Plugin up to 1.0.3 on WordPress cross site scripting
6 months 2 weeks ago
A vulnerability was found in CodeRevolution WP Pocket URLs Plugin up to 1.0.3 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-51681. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-51680 | CrestaProject Cresta Addons for Elementor Plugin up to 1.0.9 on WordPress cross site scripting
6 months 2 weeks ago
A vulnerability was found in CrestaProject Cresta Addons for Elementor Plugin up to 1.0.9 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-51680. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-51677 | WebberZone Knowledge Base Plugin up to 2.2.0 on WordPress cross site scripting
6 months 2 weeks ago
A vulnerability has been found in WebberZone Knowledge Base Plugin up to 2.2.0 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-51677. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-51251 | Draytek Vigor 3900 1.5.1.3 mainfunction.cgi backup command injection
6 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Draytek Vigor 3900 1.5.1.3. This affects the function backup of the file mainfunction.cgi. The manipulation leads to command injection.
This vulnerability is uniquely identified as CVE-2024-51251. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-51249 | Draytek Vigor 3900 1.5.1.3 mainfunction.cgi reboot command injection
6 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in Draytek Vigor 3900 1.5.1.3. Affected by this issue is the function reboot of the file mainfunction.cgi. The manipulation leads to command injection.
This vulnerability is handled as CVE-2024-51249. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-51246 | Draytek Vigor 3900 1.5.1.3 mainfunction.cgi doPPTP command injection
6 months 2 weeks ago
A vulnerability classified as critical was found in Draytek Vigor 3900 1.5.1.3. Affected by this vulnerability is the function doPPTP of the file mainfunction.cgi. The manipulation leads to command injection.
This vulnerability is known as CVE-2024-51246. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-51253 | Draytek Vigor 3900 1.5.1.3 mainfunction.cgi doL2TP command injection
6 months 2 weeks ago
A vulnerability classified as critical has been found in Draytek Vigor 3900 1.5.1.3. Affected is the function doL2TP of the file mainfunction.cgi. The manipulation leads to command injection.
This vulnerability is traded as CVE-2024-51253. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-51678 | Marcel Pol Elo Rating Shortcode Plugin up to 1.0.3 on WordPress cross site scripting
6 months 2 weeks ago
A vulnerability was found in Marcel Pol Elo Rating Shortcode Plugin up to 1.0.3 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-51678. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-51408 | AppSmith Community up to 1.8.2 JSON Request server-side request forgery
6 months 2 weeks ago
A vulnerability was found in AppSmith Community up to 1.8.2. It has been declared as critical. This vulnerability affects unknown code of the component JSON Request Handler. The manipulation leads to server-side request forgery.
This vulnerability was named CVE-2024-51408. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-51665 | Noor Alam Magical Addons For Elementor Plugin up to 1.2.1 on WordPress server-side request forgery
6 months 2 weeks ago
A vulnerability was found in Noor Alam Magical Addons For Elementor Plugin up to 1.2.1 on WordPress. It has been classified as critical. This affects an unknown part. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2024-51665. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-50528 | Stacks Mobile App Builder Plugin up to 5.2.3 on WordPress exposure of sensitive system information to an unauthorized control sphere
6 months 2 weeks ago
A vulnerability was found in Stacks Mobile App Builder Plugin up to 5.2.3 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to exposure of sensitive system information to an unauthorized control sphere.
This vulnerability is handled as CVE-2024-50528. The attack may be launched remotely. There is no exploit available.
vuldb.com
IntelBroker and EnergyWeaponUser Are Allegedly Selling the Data of Nokia
6 months 2 weeks ago
IntelBroker and EnergyWeaponUser Are Allegedly Selling the Data of Nokia
Dark Web Informer
CVE-2024-50527 | Stacks Mobile App Builder Plugin up to 5.2.3 on WordPress unrestricted upload
6 months 2 weeks ago
A vulnerability has been found in Stacks Mobile App Builder Plugin up to 5.2.3 on WordPress and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to unrestricted upload.
This vulnerability is known as CVE-2024-50527. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-9147 | Bna Informatics PosPratik up to 3.2.0 cross site scripting
6 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in Bna Informatics PosPratik up to 3.2.0. Affected is an unknown function. The manipulation leads to basic cross site scripting.
This vulnerability is traded as CVE-2024-9147. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-51582 | ThimPress WP Hotel Booking Plugin up to 2.1.4 on WordPress path traversal
6 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in ThimPress WP Hotel Booking Plugin up to 2.1.4 on WordPress. This issue affects some unknown processing. The manipulation leads to path traversal: '.../...//'.
The identification of this vulnerability is CVE-2024-51582. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-45891 | DrayTek Vigor 3900 1.5.1.3 cgi-bin/mainfunction.cgi delete_wlan_profile action command injection
6 months 2 weeks ago
A vulnerability classified as critical was found in DrayTek Vigor 3900 1.5.1.3. This vulnerability affects the function delete_wlan_profile of the file cgi-bin/mainfunction.cgi. The manipulation of the argument action leads to command injection.
This vulnerability was named CVE-2024-45891. The attack can be initiated remotely. There is no exploit available.
vuldb.com