Aggregator
CVE-2025-1548 | iteachyou Dreamer CMS 4.1.3 /admin/archives/edit editorValue/answer/content cross site scripting
9 months 3 weeks ago
A vulnerability was found in iteachyou Dreamer CMS 4.1.3. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/archives/edit. The manipulation of the argument editorValue/answer/content leads to cross site scripting.
This vulnerability was named CVE-2025-1548. The attack can be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
U.S. CISA adds Craft CMS and Palo Alto Networks PAN-OS flaws to its Known Exploited Vulnerabilities catalog
9 months 3 weeks ago
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Craft CMS and Palo Alto Networks PAN-OS vulnerabilities to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SonicWall SonicOS and Palo Alto PAN-OS vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. The two vulnerabilities are: Craft is a flexible, user-friendly CMS, affected […]
Pierluigi Paganini
CVE-2025-1471 | Eclipse OMR 0.2.x/0.3.x out-of-bounds write (ID 55)
9 months 3 weeks ago
A vulnerability was found in Eclipse OMR 0.2.x/0.3.x. It has been classified as critical. This affects an unknown part. The manipulation leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2025-1471. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-1470 | Eclipse OMR up to 0.4.0 null pointer dereference (ID 54)
9 months 3 weeks ago
A vulnerability was found in Eclipse OMR up to 0.4.0 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2025-1470. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Submit #497604: iteachyou Dreamer CMS 4.1.3 Stored Cross Site Scripting (XSS) [Duplicate]
9 months 3 weeks ago
Submit #497604 / VDB-296494
vastzero
Submit #497603: iteachyou Dreamer CMS 4.1.3 Server-Side Request Forgery [Duplicate]
9 months 3 weeks ago
Submit #497603 / VDB-296494
vastzero
Submit #497602: iteachyou Dreamer CMS 4.1.3 Remote File Inclusion [Accepted]
9 months 3 weeks ago
Submit #497602 / VDB-296494
vastzero
CVE-2024-50030 | Linux Kernel up to 6.11.3 send_recv use after free (8ed7dd4c55e4/db7f92af6261 / Nessus ID 216493)
9 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.11.3 and classified as critical. Affected by this issue is the function send_recv. The manipulation leads to use after free.
This vulnerability is handled as CVE-2024-50030. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47717 | Linux Kernel up to 6.10.12/6.11.1 RISC-V kvm_vcpu_write_guest null pointer dereference (81aa95fd5bd1/6d0a5dcfc78b/47d40d93292d / Nessus ID 216493)
9 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.10.12/6.11.1. It has been rated as critical. Affected by this issue is the function kvm_vcpu_write_guest of the component RISC-V. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2024-47717. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-22044 | Oracle Java SE up to 8u371-perf/17.0.7/20.0.1 Hotspot information disclosure (Nessus ID 216569)
9 months 3 weeks ago
A vulnerability was found in Oracle Java SE up to 8u371-perf/17.0.7/20.0.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Hotspot. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2023-22044. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-22025 | Oracle Java SE 8u381-perf/17.0.8/20.0.2 Hotspot (Nessus ID 216569)
9 months 3 weeks ago
A vulnerability was found in Oracle Java SE 8u381-perf/17.0.8/20.0.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Hotspot. The manipulation leads to an unknown weakness.
This vulnerability is known as CVE-2023-22025. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2021-43519 | Lua up to 5.4.4 Script File ldo.c lua_resume stack-based overflow (Nessus ID 216572)
9 months 3 weeks ago
A vulnerability was found in Lua up to 5.4.4 and classified as critical. Affected by this issue is the function lua_resume of the file ldo.c of the component Script File Handler. The manipulation leads to stack-based buffer overflow.
This vulnerability is handled as CVE-2021-43519. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-22025 | OpenJDK on x64 Ideal memory corruption (Nessus ID 216569)
9 months 3 weeks ago
A vulnerability, which was classified as critical, was found in OpenJDK on x64. This affects the function LoadVectorMaskedNode::Ideal. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2023-22025. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-20932 | Oracle Java SE Security (Nessus ID 216569)
9 months 3 weeks ago
A vulnerability has been found in Oracle Java SE and classified as critical. This vulnerability affects unknown code of the component Security. The manipulation leads to an unknown weakness.
This vulnerability was named CVE-2024-20932. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2021-44647 | Lua 5.4.2/5.4.4 ldebug.c funcnamefromcode denial of service (Nessus ID 216573)
9 months 3 weeks ago
A vulnerability was found in Lua 5.4.2/5.4.4. It has been declared as problematic. Affected by this vulnerability is the function funcnamefromcode of the file ldebug.c. The manipulation leads to denial of service.
This vulnerability is known as CVE-2021-44647. The attack can be launched remotely. There is no exploit available.
vuldb.com
隐匿黑手:基于 JavaScript 的恶意软件借隐写术暗偷数据
9 months 3 weeks ago
安全客
Atlassian 修复Confluence 和 Crowd 中的多个严重漏洞
9 months 3 weeks ago
已修复
微软修复已遭利用的 Power Pages 0day
9 months 3 weeks ago
速修复
Банки или мошенники? Виртуальные АТС получат специальную маркировку
9 months 3 weeks ago
Звонки через интернет станут прозрачными.