Aggregator
VNCTF-2025-赛后复现
9 months 1 week ago
看雪论坛作者ID:周bosh
CVE-2023-6361 | Winhex 16.1 SR-1/20.4 Structured Exception filename memory corruption
9 months 1 week ago
A vulnerability was found in Winhex 16.1 SR-1/20.4. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Structured Exception Handler. The manipulation of the argument filename leads to memory corruption.
This vulnerability is known as CVE-2023-6361. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-6362 | Winhex 16.1 SR-1/20.4 Structured Exception filename memory corruption
9 months 1 week ago
A vulnerability was found in Winhex 16.1 SR-1/20.4. It has been rated as critical. Affected by this issue is some unknown functionality of the component Structured Exception Handler. The manipulation of the argument filename leads to memory corruption.
This vulnerability is handled as CVE-2023-6362. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-28710 | LimeSurvey up to 6.4.x Alert Widget cross site scripting
9 months 1 week ago
A vulnerability, which was classified as problematic, has been found in LimeSurvey up to 6.4.x. This issue affects some unknown processing of the component Alert Widget. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-28710. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-28709 | LimeSurvey up to 6.5.11 comment cross site scripting
9 months 1 week ago
A vulnerability, which was classified as problematic, was found in LimeSurvey up to 6.5.11. Affected is an unknown function. The manipulation of the argument comment leads to cross site scripting.
This vulnerability is traded as CVE-2024-28709. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45933 | OnlineNewsSite 1.0 /admin/post/edit/ Title/summary cross site scripting
9 months 1 week ago
A vulnerability has been found in OnlineNewsSite 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/post/edit/. The manipulation of the argument Title/summary leads to cross site scripting.
This vulnerability is known as CVE-2024-45933. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-45932 | Krayin CRM 1.3.0 2 organization name cross site scripting
9 months 1 week ago
A vulnerability was found in Krayin CRM 1.3.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/contacts/organizations/edit/2. The manipulation of the argument organization name leads to cross site scripting.
This vulnerability is handled as CVE-2024-45932. The attack may be launched remotely. There is no exploit available.
vuldb.com
堆栈欺骗(ThreadStackSpoofer分析)
9 months 1 week ago
最重要的点在于要修改MySleep的返回地址,让工具无法栈回溯,并且要在结束之后还原被Hook函数的各种信息
Как математика звёздных взрывов спасла будущее смартфонов и закон Мура
9 months 1 week ago
Почему суперновы стали ключом к новым технологиям?
CVE-2025-2093 | PHPGurukul Online Library Management System 3.0 /change-password.php email/phone number password recovery
9 months 1 week ago
A vulnerability was found in PHPGurukul Online Library Management System 3.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /change-password.php. The manipulation of the argument email/phone number leads to weak password recovery.
This vulnerability is known as CVE-2025-2093. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-2094 | TOTOLINK EX1800T 9.1.0cu.2112_B20220316 /cgi-bin/cstecgi.cgi setWiFiExtenderConfig apcliKey/key os command injection
9 months 1 week ago
A vulnerability was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. It has been rated as critical. Affected by this issue is the function setWiFiExtenderConfig of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument apcliKey/key leads to os command injection.
This vulnerability is handled as CVE-2025-2094. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-2095 | TOTOLINK EX1800T 9.1.0cu.2112_B20220316 /cgi-bin/cstecgi.cgi setDmzCfg ip os command injection
9 months 1 week ago
A vulnerability classified as critical has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This affects the function setDmzCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip leads to os command injection.
This vulnerability is uniquely identified as CVE-2025-2095. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-2096 | TOTOLINK EX1800T 9.1.0cu.2112_B20220316 /cgi-bin/cstecgi.cgi setRebootScheCfg mode/week/minute/recHour os command injection
9 months 1 week ago
A vulnerability classified as critical was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affects the function setRebootScheCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument mode/week/minute/recHour leads to os command injection.
This vulnerability was named CVE-2025-2096. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-2097 | TOTOLINK EX1800T 9.1.0cu.2112_B20220316 /cgi-bin/cstecgi.cgi setRptWizardCfg loginpass stack-based overflow
9 months 1 week ago
A vulnerability, which was classified as critical, has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This issue affects the function setRptWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument loginpass leads to stack-based buffer overflow.
The identification of this vulnerability is CVE-2025-2097. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
[Meachines] [Hard] Jarmis API+Gopher-SSRF+OMI权限提升
9 months 1 week ago
#Jarmis API #Gopher-SSRF #OMI权限提升 #jarmis-omi
日本电信巨头NTT遭遇数据泄露,波及1.8万家企业
9 months 1 week ago
日本电信巨头NTT遭遇数据泄露,波及1.8万家企业,客户信息可能外泄。
Russian DDoS Groups Frothing After Europe Backs Ukraine
9 months 1 week ago
Self-Described Hacktivists Appear to Remain Moscow Foreign Policy Extension
Russia's use of high-profile online nuisance attacks as a psychology ploy designed to amplify Moscow's geopolitical agenda continues. As Europe has rallied to support Ukraine, self-proclaimed Russian hacktivists have trumpeted their targeting of the U.K. and EU member states, instead of the U.S.
Russia's use of high-profile online nuisance attacks as a psychology ploy designed to amplify Moscow's geopolitical agenda continues. As Europe has rallied to support Ukraine, self-proclaimed Russian hacktivists have trumpeted their targeting of the U.K. and EU member states, instead of the U.S.
Are Efforts to Help Secure Rural Hospitals Doing Any Good?
9 months 1 week ago
Biden-Era Cyber Aid Programs Are Still Available, but the Future Is Uncertain
Even though rural hospitals and other small healthcare providers don't have deep pockets, cybercriminals continue to target them with ransomware, often causing serious disruption and affecting large swaths of patients. What can be done to help them strengthen cybersecurity?
Even though rural hospitals and other small healthcare providers don't have deep pockets, cybercriminals continue to target them with ransomware, often causing serious disruption and affecting large swaths of patients. What can be done to help them strengthen cybersecurity?
Trump Executive Order Aims to Make US a 'Bitcoin Superpower'
9 months 1 week ago
White House Order Centralizes Crypto Seized Through Civil, Criminal Forfeitures
The Trump administration pledged to not spend taxpayer dollars on cryptocurrencies deposited into a federal "Strategic Bitcoin Reserve" created by a Thursday evening executive order. The government has collected an estimated 200,000 digital coins through criminal and civil forfeiture.
The Trump administration pledged to not spend taxpayer dollars on cryptocurrencies deposited into a federal "Strategic Bitcoin Reserve" created by a Thursday evening executive order. The government has collected an estimated 200,000 digital coins through criminal and civil forfeiture.