Aggregator
火绒安全终端防护数据月报(2025-01)
10 months 1 week ago
1月,火绒安全产品拦截恶意攻击总数151,214,109次,其中病毒拦截9688.3万次、系统高危动作拦截2716.0万次、网络高危风险拦截2717.1万次。
解析Next.js中的SSRF漏洞:深入探讨盲目的SSRF攻击及其防范策略
10 months 1 week ago
本文将深入探讨Next.js中的图像优化组件以及与其相关的SSRF漏洞,并解释如何将其转化为易于理解的内容。
一周网安优质PDF资源推荐丨FreeBuf知识大陆
10 months 1 week ago
我们精选了本周知识大陆公开发布的10条优质资源,让我们一起看看吧。
CVE-2024-39556 | Juniper Networks Junos OS/Junos OS Evolved stack-based overflow (JSA83016)
10 months 1 week ago
A vulnerability was found in Juniper Networks Junos OS and Junos OS Evolved. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to stack-based buffer overflow.
This vulnerability is handled as CVE-2024-39556. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-53807 | brandtoss WP Mailster Plugin up to 1.8.16.0 on WordPress sql injection
10 months 1 week ago
A vulnerability, which was classified as critical, has been found in brandtoss WP Mailster Plugin up to 1.8.16.0 on WordPress. This issue affects some unknown processing. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2024-53807. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-52480 | Astoundify Jobify Plugin up to 4.2.3 on WordPress authorization
10 months 1 week ago
A vulnerability classified as problematic was found in Astoundify Jobify Plugin up to 4.2.3 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to missing authorization.
This vulnerability is known as CVE-2024-52480. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2020-8094 | Bitdefender Antivirus Free 2020 1.0.15.119 DLL testinitsigs.exe untrusted search path
10 months 1 week ago
A vulnerability classified as critical was found in Bitdefender Antivirus Free 2020 1.0.15.119. This vulnerability affects unknown code of the file testinitsigs.exe of the component DLL Handler. The manipulation leads to untrusted search path.
This vulnerability was named CVE-2020-8094. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21185 | Microsoft Edge up to 131.0.2903.86 access control
10 months 1 week ago
A vulnerability was found in Microsoft Edge. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to improper access controls.
This vulnerability was named CVE-2025-21185. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-46400 | KWHotel 0.47 Add Guest csv injection
10 months 1 week ago
A vulnerability has been found in KWHotel 0.47 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Add Guest. The manipulation leads to csv injection.
This vulnerability is known as CVE-2023-46400. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2025-23374 | Dell Enterprise SONiC OS up to 4.2.2/4.4.0 log file (dsa-2025-057)
10 months 1 week ago
A vulnerability classified as problematic was found in Dell Enterprise SONiC OS up to 4.2.2/4.4.0. This vulnerability affects unknown code. The manipulation leads to sensitive information in log files.
This vulnerability was named CVE-2025-23374. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21107 | Dell NetWorker up to 19.9/19.10.0.6/19.11.0.2 unquoted search path (dsa-2025-064)
10 months 1 week ago
A vulnerability was found in Dell NetWorker up to 19.9/19.10.0.6/19.11.0.2. It has been classified as critical. This affects an unknown part. The manipulation leads to unquoted search path.
This vulnerability is uniquely identified as CVE-2025-21107. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-13698 | Astoundify Jobify Plugin up to 4.2.7 on WordPress download_image_via_ai authorization
10 months 1 week ago
A vulnerability was found in Astoundify Jobify Plugin up to 4.2.7 on WordPress and classified as critical. This issue affects the function download_image_via_ai. The manipulation leads to missing authorization.
The identification of this vulnerability is CVE-2024-13698. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-55215 | trojan up to 2.15.3 Initialization Interface /auth/register initialization
10 months 1 week ago
A vulnerability classified as critical was found in trojan up to 2.15.3. Affected by this vulnerability is an unknown functionality of the file /auth/register of the component Initialization Interface. The manipulation leads to improper initialization.
This vulnerability is known as CVE-2024-55215. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-55272 | Brainasoft Braina 2.8 Chat Window information disclosure
10 months 1 week ago
A vulnerability classified as problematic has been found in Brainasoft Braina 2.8. Affected is an unknown function of the component Chat Window. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-55272. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-57606 | JeecgBoot 3.7.2 TotalData Component sql injection (Issue 7665)
10 months 1 week ago
A vulnerability was found in JeecgBoot 3.7.2. It has been rated as critical. This issue affects some unknown processing of the component TotalData Component. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2024-57606. The attack may be initiated remotely. There is no exploit available.
vuldb.com
加拿大政府推出新的国家网络安全战略
10 months 1 week ago
加拿大最新国家网络安全战略聚焦两大原则和三大支柱
破解DeepSeek大模型,揭秘内部运行参数
10 months 1 week ago
并总结了五种最常用的大模型攻击方法
CVE-2025-24028 | laurent22 joplin up to 3.2.11 cross site scripting (GHSA-5w3c-wph9-hq92)
10 months 1 week ago
A vulnerability was found in laurent22 joplin up to 3.2.11. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-24028. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-24366 | drakkan sftpgo up to 2.6.4 os command injection (GHSA-vj7w-3m8c-6vpx)
10 months 1 week ago
A vulnerability was found in drakkan sftpgo up to 2.6.4. It has been classified as critical. This affects an unknown part. The manipulation leads to os command injection.
This vulnerability is uniquely identified as CVE-2025-24366. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com