Aggregator
看看产业里 AI 应用的进展吧,它治愈了我的 AI 价值焦虑
6 months 4 weeks ago
不用怀疑,AI 就是未来的新阶梯。文 | 张鹏编辑 | 宛辰你会发现,当把目光放在消费级应用时,无论是软件还是硬件,面对的问题其实很复杂。除了 AI 技术本身的能力够不够,还有产品和工程上的可实现性,
看看产业里 AI 应用的进展吧,它治愈了我的 AI 价值焦虑
6 months 4 weeks ago
不用怀疑,AI 就是未来的新阶梯。
强网杯S8决赛Reverse
6 months 4 weeks ago
看雪论坛作者ID:xi@0ji233
欢迎报名!“系统0day安全”系列课程:掌握漏洞挖掘重要技能
6 months 4 weeks ago
全是干货
强网杯S8决赛Reverse
6 months 4 weeks ago
复盘一下强网决赛的Reverse题。一S1mpleVM附件下载:https://xia0ji233.pro/2024/12/11/qwb2024_final_reverse/S1mpLeVM_6d42
欢迎报名!“系统0day安全”系列课程:掌握漏洞挖掘重要技能
6 months 4 weeks ago
数字化时代,系统漏洞如同隐形的威胁,潜伏在企业网络的每个角落。0day漏洞的发现与利用,已成为黑客攻击的主要手段,给企业安全带来巨大的威胁和挑战。我们特别推出了“系统0day安全”系列课程,本系列课程
CVE-2012-4997 | AneCMS 2e2c583 path traversal (EDB-18559 / XFDB-73682)
6 months 4 weeks ago
A vulnerability was found in AneCMS 2e2c583. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to path traversal.
The identification of this vulnerability is CVE-2012-4997. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2017-6074 | Oracle Communications ECz7.x/ECz8.x Session Border Controller double free (EDB-41457 / Nessus ID 97347)
6 months 4 weeks ago
A vulnerability, which was classified as critical, was found in Oracle Communications ECz7.x/ECz8.x. This affects an unknown part of the component Session Border Controller. The manipulation leads to double free.
This vulnerability is uniquely identified as CVE-2017-6074. The attack needs to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-13629 | Espressif UART Download Mode uninitialized pointer (AR2020-001)
6 months 4 weeks ago
A vulnerability has been found in Espressif and classified as problematic. This vulnerability affects unknown code of the component UART Download Mode. The manipulation leads to uninitialized pointer.
This vulnerability was named CVE-2020-13629. It is possible to launch the attack on the physical device. There is no exploit available.
vuldb.com
CVE-2020-15048 | Espressif Flash injection (AR2020-001)
6 months 4 weeks ago
A vulnerability, which was classified as problematic, was found in Espressif. This affects an unknown part of the component Flash Handler. The manipulation leads to injection.
This vulnerability is uniquely identified as CVE-2020-15048. It is possible to launch the attack on the physical device. There is no exploit available.
vuldb.com
CVE-2024-10797 | Full Screen Menu for Elementor Plugin up to 1.0.7 on WordPress Post information disclosure
6 months 4 weeks ago
A vulnerability classified as problematic was found in Full Screen Menu for Elementor Plugin up to 1.0.7 on WordPress. This vulnerability affects unknown code of the component Post Handler. The manipulation leads to information disclosure.
This vulnerability was named CVE-2024-10797. The attack can be initiated remotely. There is no exploit available.
vuldb.com
LockBit Developer Rostislav Panev Charged for Billions in Global Ransomware Damages
6 months 4 weeks ago
A dual Russian and Israeli national has been charged in the United States for allegedly being the developer of the now-defunct LockBit ransomware-as-a-service (RaaS) operation since its inception in or around 2019 through at least February 2024.
Rostislav Panev, 51, was arrested in Israel earlier this August and is currently awaiting extradition, the U.S. Department of Justice (DoJ) said in a
The Hacker News
LockBit Developer Rostislav Panev Charged for Billions in Global Ransomware Damages
6 months 4 weeks ago
A dual Russian and Israeli national has been charged in the United States for allegedly being the d
CVE-2024-12893 | Portabilis i-Educar up to 2.9 Tipo de Usuário Page /usuarios/tipos/2 name cross site scripting
6 months 4 weeks ago
A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar up to 2.9. Affected by this issue is some unknown functionality of the file /usuarios/tipos/2 of the component Tipo de Usuário Page. The manipulation of the argument name leads to cross site scripting.
This vulnerability is handled as CVE-2024-12893. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
This product is a managed service. It is not possible for users to maintain vulnerability countermeasures themselves.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
Submit #459903: Portábilis i-Educar 2.9 Cross Site Scripting [Accepted]
6 months 4 weeks ago
Submit #459903 / VDB-289154
regularus3r
CVE-2024-12892 | code-projects Online Exam Mastering System 1.0 /sign.php?q=account.php name/gender/college cross site scripting
6 months 4 weeks ago
A vulnerability classified as problematic was found in code-projects Online Exam Mastering System 1.0. Affected by this vulnerability is an unknown functionality of the file /sign.php?q=account.php. The manipulation of the argument name/gender/college leads to cross site scripting.
This vulnerability is known as CVE-2024-12892. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-12891 | code-projects Online Exam Mastering System 1.0 account.php?q=quiz&step=2 eid sql injection
6 months 4 weeks ago
A vulnerability classified as critical has been found in code-projects Online Exam Mastering System 1.0. Affected is an unknown function of the file /account.php?q=quiz&step=2. The manipulation of the argument eid leads to sql injection.
This vulnerability is traded as CVE-2024-12891. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-12890 | code-projects Online Exam Mastering System 1.0 update.php?q=quiz&step=2 eid sql injection
6 months 4 weeks ago
A vulnerability was found in code-projects Online Exam Mastering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /update.php?q=quiz&step=2. The manipulation of the argument eid leads to sql injection.
The identification of this vulnerability is CVE-2024-12890. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-1999-0068 | PHP 1.0/2.0/2.0b10 mylog privileges management (EDB-19553 / Nessus ID 15708)
6 months 4 weeks ago
A vulnerability classified as critical has been found in PHP 1.0/2.0/2.0b10. Affected is an unknown function of the file mylog. The manipulation leads to improper privilege management.
This vulnerability is traded as CVE-1999-0068. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com