Aggregator
CVE-2023-51454 | DJI Mavic 3 Pro Service Port 10000 libv2_sdk.so my_tcp_receive out-of-bounds write
10 months ago
A vulnerability was found in DJI Mavic 3 Pro, Mavic 3, Mavic 3 Classic, Mavic 3 Enterprise, Matrice 300, Matrice M30 and Mini 3 Pro. It has been classified as critical. This affects the function my_tcp_receive of the file libv2_sdk.so of the component Service Port 10000. The manipulation leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2023-51454. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-51455 | DJI Mavic 3 Pro Service Port 10000 libv2_sdk.so on_receive_session_packet_ack array index
10 months ago
A vulnerability was found in DJI Mavic 3 Pro, Mavic 3, Mavic 3 Classic, Mavic 3 Enterprise, Matrice 300, Matrice M30 and Mini 3 Pro. It has been declared as critical. This vulnerability affects the function on_receive_session_packet_ack of the file libv2_sdk.so of the component Service Port 10000. The manipulation leads to improper validation of array index.
This vulnerability was named CVE-2023-51455. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-30965 | DedeCMS 5.7 member_scores.php cross-site request forgery
10 months ago
A vulnerability has been found in DedeCMS 5.7 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /src/dede/member_scores.php. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2024-30965. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-51456 | DJI Mavic 3 Pro Service Port 10000 v2_pack_array_to_msg memory corruption
10 months ago
A vulnerability was found in DJI Mavic 3 Pro, Mavic 3, Mavic 3 Classic, Mavic 3 Enterprise, Matrice 300, Matrice M30 and Mini 3 Pro. It has been rated as critical. This issue affects the function v2_pack_array_to_msg of the component Service Port 10000. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2023-51456. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-6951 | DJI Mavic 3 Pro Wi-Fi Network weak credentials
10 months ago
A vulnerability classified as problematic has been found in DJI Mavic 3 Pro, Mavic 3, Mavic 3 Classic, Mavic 3 Enterprise, Matrice 300, Matrice M30 and Mini 3 Pro. Affected is an unknown function of the component Wi-Fi Network Handler. The manipulation leads to use of weak credentials.
This vulnerability is traded as CVE-2023-6951. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-51452 | DJI Mavic 3 Pro Service Port 10000 libv2_sdk.so pull_file_v2_proc denial of service
10 months ago
A vulnerability classified as problematic was found in DJI Mavic 3 Pro, Mavic 3, Mavic 3 Classic, Mavic 3 Enterprise, Matrice 300, Matrice M30 and Mini 3 Pro. Affected by this vulnerability is the function pull_file_v2_proc of the file libv2_sdk.so of the component Service Port 10000. The manipulation leads to denial of service.
This vulnerability is known as CVE-2023-51452. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-30946 | DedeCMS 5.7 /src/dede/co_do.php cross-site request forgery
10 months ago
A vulnerability was found in DedeCMS 5.7 and classified as problematic. Affected by this issue is some unknown functionality of the file /src/dede/co_do.php. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2024-30946. The attack may be launched remotely. There is no exploit available.
vuldb.com
Человечество беззащитно перед космосом? Спросите у тихоходок, как это исправить
10 months ago
Эти малыши выживут даже после ядерной зимы... Да ещё и спляшут на руинах цивилизации.
CVE-2024-22780 | CA17 TeamsACS 1.0.1 errmsg cross site scripting
10 months ago
A vulnerability classified as problematic was found in CA17 TeamsACS 1.0.1. Affected by this vulnerability is an unknown functionality. The manipulation of the argument errmsg leads to cross site scripting.
This vulnerability is known as CVE-2024-22780. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-0598 | Kadence Gutenberg Blocks Plugin up to 3.2.17 on WordPress Contact Form Message Settings cross site scripting
10 months ago
A vulnerability was found in Kadence Gutenberg Blocks Plugin up to 3.2.17 on WordPress. It has been rated as problematic. This issue affects some unknown processing of the component Contact Form Message Settings. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-0598. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-3162 | Jeg Elementor Kit Plugin up to 2.6.3 on WordPress Testimonial cross site scripting (ID 3062484)
10 months ago
A vulnerability classified as problematic has been found in Jeg Elementor Kit Plugin up to 2.6.3 on WordPress. Affected is an unknown function of the component Testimonial. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-3162. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-1327 | Jeg Elementor Kit Plugin up to 2.6.3 on WordPress Image Box cross site scripting
10 months ago
A vulnerability, which was classified as problematic, has been found in Jeg Elementor Kit Plugin up to 2.6.3 on WordPress. Affected by this issue is some unknown functionality of the component Image Box. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-1327. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-2435 | Temporal OSS ui-server up to 2.24.x cross site scripting
10 months ago
A vulnerability classified as problematic has been found in Temporal OSS ui-server up to 2.24.x. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-2435. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-22248 | Vmware SD-WAN Orchestrator 5.0.0 redirect (VMSA-2024-0008)
10 months ago
A vulnerability was found in Vmware SD-WAN Orchestrator 5.0.0 and classified as problematic. This issue affects some unknown processing. The manipulation leads to open redirect.
The identification of this vulnerability is CVE-2024-22248. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
科学家分离出候选最苦物质
10 months ago
德国科学家团队从一种暗褐网褶菌中分离出 3 种新型苦味化合物,其中寡孢菌素D展现出惊人的苦味强度,或成为目前已知的最苦物质。现有的苦味物质数据库收录了 2400 余种苦味分子,其中约 800 种已明确关联特定受体。暗褐网褶菌无毒,但味道极苦。团队此次分离出 3 种此前未知的化合物,并揭示了它们的结构。随后团队利用细胞测试系统发现,这些化合物至少激活了大约 25 种人类苦味受体类型中的一种。特别值得注意的是新发现的苦味化合物寡孢菌素D,它即使在最低浓度(约63微克/升)下,仍能激活苦味受体 TAS2R46。该浓度相当于将 1 克寡孢菌素D溶解在约106个浴缸的水量中。团队认为,苦味受体是为了“警示”人们避免摄入潜在有害物质进化而成的,但也存在毒鹅膏菌毒素等反例,表明苦味与毒性并非绝对相关,其具体机制仍需进一步探索。
扣子全新升级,用 Agent 重塑生产力
10 months ago
CVE-2008-5126 | BoutikOne CMS search.php search_query cross site scripting (EDB-32588 / XFDB-46621)
10 months ago
A vulnerability was found in BoutikOne CMS and classified as problematic. This issue affects some unknown processing of the file search.php. The manipulation of the argument search_query leads to cross site scripting.
The identification of this vulnerability is CVE-2008-5126. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
三月漏洞信息简报
10 months ago
3月新公开漏洞367个,其中高危漏洞176个。
三月漏洞信息简报
10 months ago
3月新公开漏洞367个,其中高危漏洞176个。