Aggregator
cs免杀(lodaer1,过国内御三家,微步云查杀)
8 months 2 weeks ago
go语言 使用rc4加密+利用Active Directory服务API(AllocADsMem)实现非标准内存分配,结合RtlCopyMemory完成内存写入操作
大道至简,druid弱口令+接口测试组合拳轻松拿下30w+敏感信息
8 months 2 weeks ago
本文详细记录了一次针对某NFT商城的渗透测试全过程,展示了如何从简单的业务逻辑漏洞入手,逐步深入挖掘,最终实现大规模数据泄露的完整攻击链。
航空公司向国土安全局出售乘客数据
8 months 2 weeks ago
安全客
Alleged Data Sale of Agencia Nacional de Hidrocarburos
8 months 2 weeks ago
Alleged Data Sale of Agencia Nacional de Hidrocarburos
Dark Web Informer - Cyber Threat Intelligence
美国政府疫苗网站被人工智能生成的内容污损
8 months 2 weeks ago
安全客
CVE-2023-3909 | GitLab Community Edition/Enterprise Edition prior 16.3.6/16.4.2/16.5.1 Regular Expression resource consumption (Issue 41876 / EUVD-2023-44535)
8 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in GitLab Community Edition and Enterprise Edition. This affects an unknown part of the component Regular Expression Handler. The manipulation leads to resource consumption.
This vulnerability is uniquely identified as CVE-2023-3909. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-4430 | Ortus Solutions ColdBox Elixir 3.1.6 ENV Variable src/defaultConfig.js information disclosure (EUVD-2021-34257)
8 months 2 weeks ago
A vulnerability classified as problematic has been found in Ortus Solutions ColdBox Elixir 3.1.6. This affects an unknown part of the file src/defaultConfig.js of the component ENV Variable Handler. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2021-4430. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-5088 | QEMU Disk Offset hw/ide/core.c ide_dma_cb memory corruption (EUVD-2023-57428 / Nessus ID 209571)
8 months 2 weeks ago
A vulnerability, which was classified as critical, was found in QEMU. This affects the function ide_dma_cb of the file hw/ide/core.c of the component Disk Offset Handler. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2023-5088. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
中科固源Wisdom发现NASA嵌入式飞行控制系统—F prime通信协议漏洞!
8 months 2 weeks ago
中科固源
CVE-2022-31860 | OpenRemote up to 1.0.4 Groovy Rule privilege escalation
8 months 2 weeks ago
A vulnerability classified as critical was found in OpenRemote up to 1.0.4. Affected by this vulnerability is an unknown functionality of the component Groovy Rule Handler. The manipulation leads to privilege escalation.
This vulnerability is known as CVE-2022-31860. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2022-26461 | MediaTek MT8797 vow Local Privilege Escalation (ALPS07032604)
8 months 2 weeks ago
A vulnerability was found in MediaTek MT6833, MT6853, MT6855, MT6873, MT6877, MT6879, MT6883, MT6885, MT6889, MT6893, MT6895, MT6983, MT8791 and MT8797 and classified as critical. Affected by this issue is some unknown functionality of the component vow. The manipulation leads to Local Privilege Escalation.
This vulnerability is handled as CVE-2022-26461. An attack has to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-10677 | BTEV Plugin up to 2.0.2 on WordPress Setting cross-site request forgery
8 months 2 weeks ago
A vulnerability was found in BTEV Plugin up to 2.0.2 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Setting Handler. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2024-10677. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-11190 | jwp-a11y Plugin up to 4.1.7 on WordPress Setting cross site scripting
8 months 2 weeks ago
A vulnerability classified as problematic was found in jwp-a11y Plugin up to 4.1.7 on WordPress. Affected by this vulnerability is an unknown functionality of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-11190. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-11221 | Full Screen Page Background Image Slideshow Plugin Setting cross site scripting
8 months 2 weeks ago
A vulnerability classified as problematic has been found in Full Screen Page Background Image Slideshow Plugin up to 1.1 on WordPress. This affects an unknown part of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-11221. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-10143 | MB Custom Post Types & Custom Taxonomies Plugin up to 2.7.6 on WordPress Setting cross site scripting
8 months 2 weeks ago
A vulnerability was found in MB Custom Post Types & Custom Taxonomies Plugin up to 2.7.6 on WordPress. It has been declared as problematic. This vulnerability affects unknown code of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-10143. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-10818 | JSFiddle Shortcode Plugin up to 1.1.2 on WordPress cross site scripting
8 months 2 weeks ago
A vulnerability was found in JSFiddle Shortcode Plugin up to 1.1.2 on WordPress. It has been classified as problematic. Affected is an unknown function of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-10818. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-5959 | Google Chrome up to 137.0.7151.68 V8 type confusion (ID 422313 / EUVD-2025-18071)
8 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in Google Chrome. This issue affects some unknown processing of the component V8. The manipulation leads to type confusion.
The identification of this vulnerability is CVE-2025-5959. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-10639 | Ramon Fincken Auto Prune Posts Plugin up to 2.x on WordPress Setting cross site scripting (EUVD-2025-15347)
8 months 2 weeks ago
A vulnerability was found in Ramon Fincken Auto Prune Posts Plugin up to 2.x on WordPress and classified as problematic. This issue affects some unknown processing of the component Setting Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-10639. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-11141 | Sailthru Triggermail Plugin up to 1.1 on WordPress Setting cross site scripting (EUVD-2025-15355)
8 months 2 weeks ago
A vulnerability classified as problematic was found in Sailthru Triggermail Plugin up to 1.1 on WordPress. This vulnerability affects unknown code of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-11141. The attack can be initiated remotely. There is no exploit available.
vuldb.com