Aggregator
【二十四节气】谷雨 | 甘雨应时落,新苗到处滋。
9 months 3 weeks ago
【二十四节气】谷雨 | 甘雨应时落,新苗到处滋。
9 months 3 weeks ago
CVE-2023-46344 | Solar-Log Base 15 6.0.1 Build 161 Web Portal #ilang=DE&b=c_smartenergy_swgroups cross site scripting
9 months 3 weeks ago
A vulnerability was found in Solar-Log Base 15 6.0.1 Build 161. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /#ilang=DE&b=c_smartenergy_swgroups of the component Web Portal. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2023-46344. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-1196 | SourceCodester Testimonial Page Manager 1.0 HTTP POST Request add-testimonial.php name/description/testimony cross site scripting
9 months 3 weeks ago
A vulnerability classified as problematic was found in SourceCodester Testimonial Page Manager 1.0. This vulnerability affects unknown code of the file add-testimonial.php of the component HTTP POST Request Handler. The manipulation of the argument name/description/testimony leads to cross site scripting.
This vulnerability was named CVE-2024-1196. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-23635 | nahsra AntiSamy up to 1.7.4 cross site scripting (GHSA-2mrq-w8pv-5pvq / Nessus ID 214580)
9 months 3 weeks ago
A vulnerability has been found in nahsra AntiSamy up to 1.7.4 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-23635. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-22936 | Campcodes AIMS Student Information Systems 3053 Parents / Student Portal Message cross site scripting
9 months 3 weeks ago
A vulnerability was found in Campcodes AIMS Student Information Systems 3053. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Parents / Student Portal. The manipulation of the argument Message leads to cross site scripting.
This vulnerability is handled as CVE-2024-22936. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-22939 | FlyCMS 1.0 category_edit cross-site request forgery
9 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in FlyCMS 1.0. This issue affects some unknown processing of the file system/article/category_edit. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2024-22939. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2023-37531 | HCL BigFix Platform up to 9.5.23/10.0.10 Web Reports cross site scripting (KB0110209)
9 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in HCL BigFix Platform up to 9.5.23/10.0.10. Affected is an unknown function of the component Web Reports. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2023-37531. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-24857 | Linux Kernel up to 6.8-rc1 Bluetooth conn_info_min_age_set/conn_info_max_age_set race condition (Nessus ID 210359)
9 months 3 weeks ago
A vulnerability classified as problematic was found in Linux Kernel up to 6.8-rc1. This vulnerability affects the function conn_info_min_age_set/conn_info_max_age_set of the component Bluetooth. The manipulation leads to race condition.
This vulnerability was named CVE-2024-24857. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
APT29组织通过品酒会诱饵在欧洲外交官中部署GRAPELOADER恶意软件
9 months 3 weeks ago
俄黑客APT29以品酒会诱饵攻击欧洲外交官,部署新型恶意软件GRAPELOADER。
RSAC 2025创新沙盒 | Command Zero:重构安全调查流程的人机协作引擎
9 months 3 weeks ago
通过LLM构建的、基于问题的安全事件标准化调查方案
RSAC 2025创新沙盒 | Command Zero:重构安全调查流程的人机协作引擎
9 months 3 weeks ago
通过LLM构建的、基于问题的安全事件标准化调查方案
CVE-2024-0012&CVE-2025-0108 PAN-OS 从配置文件中寻找认证绕过漏洞
9 months 3 weeks ago
Palo Alto Networks PAN-OS 近期爆出的多个漏洞,其中包含 2 个认证绕过漏洞。漏洞原理比较类似,都是因为在多级配置转发的过程中存在逻辑缺陷,导致可通过构造特殊请求数据包实现认证绕过,从而越权访问 Web 管理界面。
CVE-2024-0012&CVE-2025-0108 PAN-OS 从配置文件中寻找认证绕过漏洞
9 months 3 weeks ago
Palo Alto Networks PAN-OS 近期爆出的多个漏洞,其中包含 2 个认证绕过漏洞。漏洞原理比较类似,都是因为在多级配置转发的过程中存在逻辑缺陷,导致可通过构造特殊请求数据包实现认证绕过,从而越权访问 Web 管理界面。
CVE-2015-7848 | ntpd 4.2.8 Private Mode integer overflow (cisco-sa-20151021-ntp / Nessus ID 91248)
9 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in ntpd 4.2.8. This issue affects some unknown processing of the component Private Mode. The manipulation leads to integer overflow.
The identification of this vulnerability is CVE-2015-7848. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2016-1547 | ntp 4.2.8 Crypto NAK input validation (RHSA-2016:1141 / VU#718152)
9 months 3 weeks ago
A vulnerability classified as critical was found in ntp 4.2.8. Affected by this vulnerability is an unknown functionality of the component Crypto NAK Handler. The manipulation leads to improper input validation.
This vulnerability is known as CVE-2016-1547. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2016-1548 | ntp 4.2.8 ntpd Client data processing (FEDORA-2016-777d838c1b / VU#718152)
9 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in ntp 4.2.8. Affected by this issue is some unknown functionality of the component ntpd Client. The manipulation leads to data processing error.
This vulnerability is handled as CVE-2016-1548. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2016-1549 | ntp 4.2.8 Ephemeral Association data processing (SA_18_13 / VU#718152)
9 months 3 weeks ago
A vulnerability, which was classified as critical, was found in ntp 4.2.8. This affects an unknown part of the component Ephemeral Association Handler. The manipulation leads to data processing error.
This vulnerability is uniquely identified as CVE-2016-1549. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2016-1550 | ntp 4.2.8 constant-time Memory Comparison information disclosure (RHSA-2016:1141 / VU#718152)
9 months 3 weeks ago
A vulnerability has been found in ntp 4.2.8 and classified as critical. This vulnerability affects unknown code of the component constant-time Memory Comparison. The manipulation leads to information disclosure.
This vulnerability was named CVE-2016-1550. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com