Aggregator
WordPress 主题“Houzez”和相关插件漏洞暴露了数千个网站
9 months 3 weeks ago
安全客
开挂神器能让企业管理有多轻松?这才是真正的职场爽文
9 months 3 weeks ago
安全客
CVE-2024-36399 | Kanboard up to 1.2.36 URL Parameter ProjectPermissionController.php addUser project_id access control (GHSA-x8v7-3ghx-65cv)
9 months 3 weeks ago
A vulnerability has been found in Kanboard up to 1.2.36 and classified as critical. This vulnerability affects the function addUser of the file app/Controller/ProjectPermissionController.php of the component URL Parameter Handler. The manipulation of the argument project_id leads to improper access controls.
This vulnerability was named CVE-2024-36399. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-3404 | gaizhenbiao chuanhuchatgpt History File access control
9 months 3 weeks ago
A vulnerability classified as critical was found in gaizhenbiao chuanhuchatgpt. Affected by this vulnerability is an unknown functionality of the component History File Handler. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2024-3404. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-3234 | gaizhenbiao chuanhuchatgpt prior 20240305 web_assets path traversal
9 months 3 weeks ago
A vulnerability classified as critical was found in gaizhenbiao chuanhuchatgpt. Affected by this vulnerability is an unknown functionality of the file web_assets. The manipulation leads to path traversal.
This vulnerability is known as CVE-2024-3234. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-3402 | gaizhenbiao chuanhuchatgpt up to 20240121 cross site scripting
9 months 3 weeks ago
A vulnerability classified as problematic was found in gaizhenbiao chuanhuchatgpt up to 20240121. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-3402. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-5186 | imartinez privategpt up to 0.5.0 Requests path server-side request forgery
9 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in imartinez privategpt up to 0.5.0. Affected by this issue is some unknown functionality of the component Requests Handler. The manipulation of the argument path leads to server-side request forgery.
This vulnerability is handled as CVE-2024-5186. The attack may be launched remotely. There is no exploit available.
vuldb.com
盛邦安全入选IDC《中国WAAP厂商技术能力评估,2024》报告,获满分评价!
9 months 3 weeks ago
盛邦安全
盛邦安全权小文:多源异构数据融合技术在威胁情报实战化趋势下将“大有可为”
9 months 3 weeks ago
盛邦安全
CVE-2008-6644 | DotNetNuke up to 4.8.3 Default.aspx cross site scripting (EDB-31865 / XFDB-42752)
9 months 3 weeks ago
A vulnerability classified as problematic has been found in DotNetNuke. Affected is an unknown function of the file Default.aspx. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2008-6644. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Generative AI Security: Getting ready for Salesforce Einstein Copilot
9 months 3 weeks ago
Salesforce's Einstein Copilot can provide insights and perform tasks help streamline daily processes. However, it also comes with risks that you should takes steps to mitigate. Learn more from Varonis on how to prepare for Salesforce Einstein Copilot, [...]
Sponsored by Varonis
CVE-2024-30368 | A10 Thunder ADC CsrRequestView command injection
9 months 3 weeks ago
A vulnerability has been found in A10 Thunder ADC and classified as critical. This vulnerability affects the function CsrRequestView. The manipulation leads to command injection.
This vulnerability was named CVE-2024-30368. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-30369 | A10 Thunder ADC permission
9 months 3 weeks ago
A vulnerability was found in A10 Thunder ADC. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to permission issues.
This vulnerability is known as CVE-2024-30369. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-1879 | significant-gravitas AutoGPT up to 5.0 cross-site request forgery
9 months 3 weeks ago
A vulnerability has been found in significant-gravitas AutoGPT up to 5.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2024-1879. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
KELA Identity Guard detects and intercepts compromised assets
9 months 3 weeks ago
KELA launched Identity Guard, the first line of defense to help combat the #1 cause of data breaches – compromised corporate assets and identities. Identity Guard is a critical module of KELA’s threat intelligence platform, already in use by hundreds of customers, including government agencies, law enforcement and enterprises. As threat actors look for new ways to circumvent advanced Firewalls, EDRs, and other security controls, they increasingly turn to using valid corporate account credentials — … More →
The post KELA Identity Guard detects and intercepts compromised assets appeared first on Help Net Security.
Industry News
Startup Torq Secures $70M to Advance Hyperautomation with AI
9 months 3 weeks ago
Series C Funding to Fuel Generative AI Integration and AI-Powered Threat Detection
The funding will enhance generative AI technologies that streamline security operations and provide autonomous threat investigation, alongside plans for broader U.S. and European market penetration.
The funding will enhance generative AI technologies that streamline security operations and provide autonomous threat investigation, alongside plans for broader U.S. and European market penetration.
Managing Cyber-Risk Is No Different Than Managing Any Business Risk
9 months 3 weeks ago
A sound cyber-risk management strategy analyzes all the business impacts that may stem from an attack and estimates the related costs of mitigation versus the costs of not taking action.
Dave Gerry
CVE-2007-4109 | Codewidgets Online Event Registration Template sign_in.aspx Password sql injection (EDB-30425 / XFDB-35669)
9 months 3 weeks ago
A vulnerability classified as critical has been found in Codewidgets Online Event Registration Template. This affects an unknown part of the file sign_in.aspx. The manipulation of the argument Password leads to sql injection.
This vulnerability is uniquely identified as CVE-2007-4109. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
2024 CCF中国软件大会筹办工作推进系列【二十二】:并行论坛巡礼之软件定义汽车:基础软件与开发实践“
9 months 3 weeks ago
2024 CCF中国软件大会筹办工作推进系列【二十二】:并行论坛巡礼之软件定义汽车:基础软件与开发实践“