Aggregator
澳洲航空遭黑客攻击,瑞士政府服务商敏感数据泄露|一周特辑
9 months 2 weeks ago
点击查看更多本周网络安全大事件。
CVE-2007-0663 | Eclectic Designs CascadianFAQ 4.0/4.1 index.php qid sql injection (EDB-3227 / ADV-2007-0424)
9 months 2 weeks ago
A vulnerability has been found in Eclectic Designs CascadianFAQ 4.0/4.1 and classified as critical. This vulnerability affects unknown code of the file index.php. The manipulation of the argument qid leads to sql injection.
This vulnerability was named CVE-2007-0663. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2023-0299 | publify up to 9.2.9 input validation (EUVD-2023-0526)
9 months 2 weeks ago
A vulnerability was found in publify up to 9.2.9 and classified as problematic. This issue affects some unknown processing. The manipulation leads to improper input validation.
The identification of this vulnerability is CVE-2023-0299. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-24452 | TestQuality Updater Plugin up to 1.3 on Jenkins cross-site request forgery (EUVD-2023-0524)
9 months 2 weeks ago
A vulnerability has been found in TestQuality Updater Plugin up to 1.3 on Jenkins and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2023-24452. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2022-46648 | git Gem up to 1.12.0 on Ruby deserialization (EUVD-2023-0518)
9 months 2 weeks ago
A vulnerability has been found in git Gem up to 1.12.0 on Ruby and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to deserialization.
This vulnerability is known as CVE-2022-46648. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-22452 | phpMyAdmin up to 5.1.x sql injection (Issue 15898 / EUVD-2023-0523)
9 months 2 weeks ago
A vulnerability, which was classified as critical, was found in phpMyAdmin up to 5.1.x. Affected is an unknown function. The manipulation leads to sql injection.
This vulnerability is traded as CVE-2020-22452. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-0564 | froxlor up to 2.0.9 weak password (EUVD-2023-0521)
9 months 2 weeks ago
A vulnerability classified as critical was found in froxlor up to 2.0.9. Affected by this vulnerability is an unknown functionality. The manipulation leads to weak password requirements.
This vulnerability is known as CVE-2023-0564. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-47318 | ruby-git up to 1.12.x Filename privilege escalation (DLA 3303-1 / EUVD-2023-0522)
9 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in ruby-git up to 1.12.x. This issue affects some unknown processing of the component Filename Handler. The manipulation leads to privilege escalation.
The identification of this vulnerability is CVE-2022-47318. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-0107 | usememos up to 0.9.x cross site scripting (EUVD-2023-0516)
9 months 2 weeks ago
A vulnerability was found in usememos memos up to 0.9.x. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2023-0107. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2010-4937 | Robitbt Com Amblog 1.0 index.php catid sql injection (EDB-14596 / SA40932)
9 months 2 weeks ago
A vulnerability has been found in Robitbt Com Amblog 1.0 and classified as critical. This vulnerability affects unknown code of the file index.php. The manipulation of the argument catid leads to sql injection.
This vulnerability was named CVE-2010-4937. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2019-11358 | Oracle Hospitality Materials Control 18.1 jQuery cross site scripting (EDB-52141 / Nessus ID 208606)
9 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in Oracle Hospitality Materials Control 18.1. Affected by this issue is some unknown functionality of the component jQuery. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2019-11358. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-7068 | HDF5 1.14.6 src/H5FL.c H5FL__malloc memory leak (Issue 5578 / EUVD-2025-20091)
9 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5FL__malloc of the file src/H5FL.c. The manipulation leads to memory leak.
The identification of this vulnerability is CVE-2025-7068. Attacking locally is a requirement. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-7069 | HDF5 1.14.6 src/H5FSsection.c H5FS__sect_link_size heap-based overflow (Issue 5550 / EUVD-2025-20089)
9 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FS__sect_link_size of the file src/H5FSsection.c. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2025-7069. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-3359 | Datetopia Match Agency BiZ 1.0 edit_profile.php pid cross site scripting (EDB-34600 / XFDB-53173)
9 months 2 weeks ago
A vulnerability was found in Datetopia Match Agency BiZ 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file edit_profile.php. The manipulation of the argument pid leads to cross site scripting.
This vulnerability is handled as CVE-2009-3359. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Google's AI video maker Veo 3 is now available via $20 Gemini
9 months 2 weeks ago
Google says Veo 3, which is the company's state-of-the-art video generator, is now shipping to everyone using the Gemini app with a $20 subscription. [...]
Mayank Parmar
Interlock
9 months 2 weeks ago
You must login to view this content
cohenido
ChatGPT Deep Research tests new connectors for more context
9 months 2 weeks ago
ChatGPT Deep Research, which is an AI research tool to automate research, is getting support for new connectors (integrations), including Slack. [...]
Mayank Parmar
CVE-2012-6048 | Guitar-pro Guitar Pro 6.1.1 memory corruption (EDB-18851 / OSVDB-81828)
9 months 2 weeks ago
A vulnerability was found in Guitar-pro Guitar Pro 6.1.1. It has been classified as problematic. This affects an unknown part. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2012-6048. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-1620 | Mata MataChat input.php cross site scripting (EDB-32958 / BID-34722)
9 months 2 weeks ago
A vulnerability was found in Mata MataChat. It has been classified as problematic. Affected is an unknown function of the file input.php. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2009-1620. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com