Aggregator
ASUS Confirms Critical Flaw in AiCloud Routers; Users Urged to Update Firmware
9 months 3 weeks ago
ASUS has disclosed a critical security flaw impacting routers with AiCloud enabled that could permit remote attackers to perform unauthorized execution of functions on susceptible devices.
The vulnerability, tracked as CVE-2025-2492, has a CVSS score of 9.2 out of a maximum of 10.0.
"An improper authentication control vulnerability exists in certain ASUS router firmware series,"
The Hacker News
CVE-2024-1171 | wpdevteam Essential Addons for Elementor Plugin up to 5.9.8 on WordPress Filterable Gallery Widget cross site scripting (ID 3034127)
9 months 3 weeks ago
A vulnerability was found in wpdevteam Essential Addons for Elementor Plugin up to 5.9.8 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Filterable Gallery Widget. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-1171. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-1172 | wpdevteam Essential Addons for Elementor Plugin up to 5.9.8 on WordPress Accordion Widget cross site scripting
9 months 3 weeks ago
A vulnerability was found in wpdevteam Essential Addons for Elementor Plugin up to 5.9.8 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Accordion Widget. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-1172. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-1236 | wpdevteam Essential Addons for Elementor Plugin up to 5.9.8 on WordPress cross site scripting (ID 3034127)
9 months 3 weeks ago
A vulnerability classified as problematic was found in wpdevteam Essential Addons for Elementor Plugin up to 5.9.8 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-1236. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-26135 | Ylianst MeshCentral up to 1.1.20 CSWSH control.ashx origin validation (GHSA-cp68-qrhr-g9h8)
9 months 3 weeks ago
A vulnerability was found in Ylianst MeshCentral up to 1.1.20 and classified as problematic. This issue affects some unknown processing of the file control.ashx of the component CSWSH. The manipulation leads to origin validation error.
The identification of this vulnerability is CVE-2024-26135. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-1276 | wpdevteam Essential Addons for Elementor Plugin up to 5.9.8 on WordPress Content Ticker arrow cross site scripting
9 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in wpdevteam Essential Addons for Elementor Plugin up to 5.9.8 on WordPress. Affected by this issue is some unknown functionality of the component Content Ticker. The manipulation of the argument arrow leads to cross site scripting.
This vulnerability is handled as CVE-2024-1276. The attack may be launched remotely. There is no exploit available.
vuldb.com
今晚直播聊聊我的安全创业故事
9 months 3 weeks ago
聊聊安全创业的心得、踩过的坑和关键决策及思考
今晚直播聊聊我的安全创业故事
9 months 3 weeks ago
聊聊安全创业的心得、踩过的坑和关键决策及思考
RALord
9 months 3 weeks ago
cohenido
1996年《财富》杂志封面到底是怎么说格林斯潘的
9 months 3 weeks ago
特朗普要开除美联储主席鲍威尔,这可是动摇国本的大事。自 1913 年美联储成立以来,还从未有过美联储主席被罢免的先例。
1996年《财富》杂志封面到底是怎么说格林斯潘的
9 months 3 weeks ago
特朗普要开除美联储主席鲍威尔,这可是动摇国本的大事。自 1913 年美联储成立以来,还从未有过美联储主席被罢免的先例。
.NET 免杀新思路,基于 Emit 技术实现的 WebShell
9 months 3 weeks ago
.NET 内网攻防实战电子报刊
9 months 3 weeks ago
01.NET内网安全攻防报刊小报童电子报刊【.NET内网安全攻防】也正式上线了,引入小报童也是为了弥补知识星球
.NET 总第 68 期红队武器库和资源汇总
9 months 3 weeks ago
Вчера это была фантастика, сегодня — суббота в Пекине: роботы пробежали полумарафон и даже не вспотели
9 months 3 weeks ago
Один рухнул на старте, другой врезался в забор, третий победил — роботозабег, как он есть.
Учёные впервые сконцентрировали свет на наноразмерах для широкого спектра волн
9 months 3 weeks ago
Физики открыли способ концентрировать энергию в самых малых масштабах.
CVE-2025-3763 | SourceCodester Phone Management System 1.0 Password main s buffer overflow
9 months 3 weeks ago
A vulnerability classified as critical has been found in SourceCodester Phone Management System 1.0. This affects the function main of the component Password Handler. The manipulation of the argument s leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2025-3763. Local access is required to approach this attack. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-3795 | DaiCuo 1.3.13 SEO Optimization Settings Section cross site scripting
9 months 3 weeks ago
A vulnerability was found in DaiCuo 1.3.13. It has been rated as problematic. Affected by this issue is some unknown functionality of the component SEO Optimization Settings Section. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-3795. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2003-0413 | Sun One Application Server 7.0 on Windows Error Message cross site scripting (EDB-22665 / XFDB-12095)
9 months 3 weeks ago
A vulnerability was found in Sun One Application Server 7.0 on Windows. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Error Message Handler. The manipulation leads to basic cross site scripting.
This vulnerability is known as CVE-2003-0413. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com