Aggregator
CVE-2021-29447 | WordPress up to 5.7.0 Media Library Parser xml external entity reference (EDB-50304)
8 months 2 weeks ago
A vulnerability was found in WordPress up to 5.7.0. It has been rated as critical. This issue affects some unknown processing of the component Media Library Parser. The manipulation leads to xml external entity reference.
The identification of this vulnerability is CVE-2021-29447. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-43481 | webTareas up to 2.4p3 POST Parameter editapprovalstage.php uq sql injection (EDB-50893)
8 months 2 weeks ago
A vulnerability has been found in webTareas up to 2.4p3 and classified as critical. Affected by this vulnerability is an unknown functionality of the file editapprovalstage.php of the component POST Parameter Handler. The manipulation of the argument uq leads to sql injection.
This vulnerability is known as CVE-2021-43481. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2011-4713 | osCSS 1.0/1.1/1.2.2/2.10 _ID path traversal (EDB-18099 / SA46741)
8 months 2 weeks ago
A vulnerability has been found in osCSS 1.0/1.1/1.2.2/2.10 and classified as problematic. This vulnerability affects unknown code. The manipulation of the argument _ID leads to path traversal.
This vulnerability was named CVE-2011-4713. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2003-1536 | DCP-Portal 5.3.1 search.php/calendar.php q/year cross site scripting (EDB-22387 / Nessus ID 11446)
8 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in DCP-Portal 5.3.1. Affected by this issue is some unknown functionality of the file search.php/calendar.php. The manipulation of the argument q/year leads to cross site scripting.
This vulnerability is handled as CVE-2003-1536. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2001-1370 | PHPLib 7.2/7.2.1/7.2b/7.2c prepend.php3 $_PHPLIB[libdir] privileges management (EDB-21022 / Nessus ID 14910)
8 months 2 weeks ago
A vulnerability was found in PHPLib 7.2/7.2.1/7.2b/7.2c. It has been classified as critical. This affects an unknown part of the file prepend.php3. The manipulation of the argument $_PHPLIB[libdir] leads to improper privilege management.
This vulnerability is uniquely identified as CVE-2001-1370. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
尼康新镜头能同时捕捉长焦和广角图像
8 months 2 weeks ago
登录 注册
尼康新镜头能同时捕捉长焦和广角图像
8 months 2 weeks ago
尼康与三菱扶桑卡客车株式会合作了研发了一款车载摄像头系统,摄像头配备一个可同时捕捉长焦和广角图像的光学镜头,允许司机同时查看远处物体和周围环境。新相机将在下个月的 CES 展上首次公开展示。用作车载摄像头时,同时集成远摄和广角的镜头系统允许汽车使用更少的摄像头就能实现 360 度环绕,有助于降低成本和降低故障率。
CVE-2014-7280 | Tenable Nessus 2.3.3 HTTP Header Host cross site scripting (File 128579 / EDB-34929)
8 months 2 weeks ago
A vulnerability was found in Tenable Nessus 2.3.3 and classified as problematic. This issue affects some unknown processing of the component HTTP Header Handler. The manipulation of the argument Host with the input <script>alert(1)</script>foo leads to cross site scripting.
The identification of this vulnerability is CVE-2014-7280. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-5300 | Adaptivecomputing Moab 7.2.8/8.0 improper authentication (ID 128483 / EDB-34865)
8 months 2 weeks ago
A vulnerability classified as problematic has been found in Adaptivecomputing Moab 7.2.8/8.0. This affects an unknown part. The manipulation leads to improper authentication.
This vulnerability is uniquely identified as CVE-2014-5300. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
现代产业学院又添一所!360携手校企再创产教融合新佳绩
8 months 2 weeks ago
安全客
Changes in SSL and TLS support in 2024, (Mon, Dec 30th)
8 months 2 weeks ago
With the end of the year quickly approaching, it is undoubtedly a good time to take a look at what
CVE-2024-45497 | Red Hat OpenShift API permission assignment
8 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Red Hat OpenShift. This affects an unknown part of the component API. The manipulation leads to incorrect permission assignment.
This vulnerability is uniquely identified as CVE-2024-45497. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2024-12993 | Infinix Mobile com.rlk.weathers 7.0.0.037 on Android exposure of sensitive system information to an unauthorized control sphere
8 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Infinix Mobile com.rlk.weathers 7.0.0.037 on Android. Affected by this issue is some unknown functionality. The manipulation leads to exposure of sensitive system information to an unauthorized control sphere.
This vulnerability is handled as CVE-2024-12993. It is possible to launch the attack on the local host. There is no exploit available.
vuldb.com
小米限制 HyperOS Bootloader 解锁每个帐户一台设备
8 months 2 weeks ago
安全客
CVE-2000-0676 | Netscape Communicator up to 4.74 Java Applet privileges management (EDB-20140 / BID-1546)
8 months 2 weeks ago
A vulnerability was found in Netscape Communicator up to 4.74 and classified as critical. Affected by this issue is some unknown functionality of the component Java Applet Handler. The manipulation leads to improper privilege management.
This vulnerability is handled as CVE-2000-0676. The attack may be launched remotely. Furthermore, there is an exploit available. This vulnerability has a historic impact due to its background and reception.
It is recommended to upgrade the affected component.
vuldb.com
勒索软件组织攻击药物滥用治疗服务机构
8 months 2 weeks ago
安全客
警惕 | 收到这类短信,别信!
8 months 2 weeks ago
扫码订阅《中国信息安全》邮发代号 2-786征订热线:010-82341063岁末年关不少人可能会收到“积分清零、可兑换商品并附带商城链接”的提醒短信此时要千万警惕短信里可能暗藏危机小心清空的不是积
发布 | 中国信通院发布《数字消费者权益保护蓝皮书(2024年)》(附下载)
8 months 2 weeks ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
《网络数据安全管理条例》解读一:条例出台的必要性与重要性
8 months 2 weeks ago
扫码订阅《中国信息安全》邮发代号 2-786征订热线:010-823410632024年9月24日,《网络数据安全管理条例》正式出台,自2025年1月1日起施行。作为《网络安全法》《数据安全法》《个