Aggregator
CVE-2007-2187 | eXtremail 2.1/2.1.1 stack-based overflow (EDB-3769 / BID-23577)
5 months ago
A vulnerability, which was classified as very critical, was found in eXtremail 2.1/2.1.1. This affects an unknown part. The manipulation leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2007-2187. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Telegram轻博客和图床平台Telegraph将限制发布新图片 主要存在违规内容
5 months ago
CVE-2017-13006 | Apple macOS up to 10.13.1 tcpdump memory corruption (HT208221 / Nessus ID 100472)
5 months ago
A vulnerability classified as very critical has been found in Apple macOS up to 10.13.1. This affects an unknown part of the component tcpdump. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2017-13006. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
加入 AI 混战,蚂蚁全面加速「卷应用」
5 months ago
发布三个 AI 管家的蚂蚁,要从生活场景全面切入 AI 应用。
微软发布Windows Server 2025新预览版调整时间炸弹 请用户尽快更新
5 months ago
A flaw in WordPress LiteSpeed Cache Plugin allows account takeover
5 months ago
A critical flaw in the LiteSpeed Cache plugin for WordPress could allow unauthenticated users to take control of arbitrary accounts. The LiteSpeed Cache plugin is a popular caching plugin for WordPress that accounts for over 5 million active installations. The plugin offers site acceleration through server-level caching and various optimization features. The LiteSpeed Cache plugin […]
Pierluigi Paganini
CVE-2007-2180 | NullSoft WinAmp 5.3 memory corruption (EDB-3768 / XFDB-33764)
5 months ago
A vulnerability was found in NullSoft WinAmp 5.3 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2007-2180. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
《黑神话:悟空》欢乐圆桌:聊聊游戏内外的趣事儿
5 months ago
《黑神话:悟空》欢乐圆桌:聊聊游戏内外的趣事儿 少数派播客 等 4 位作者 11:00 《黑神话:悟空》是近期突破了各个次元壁的现象级话题,也是每个游戏玩家都不得不聊的佳作。在本期节目中,《少数派播
微软将在Microsoft Office 2024中默认关闭ActiveX控件提高整体安全性
5 months ago
CVE-2024-34158 | Google Go up to 1.22.6/1.23.0 go-build-constraint resource consumption
5 months ago
A vulnerability classified as problematic has been found in Google Go up to 1.22.6/1.23.0. Affected is an unknown function of the component go-build-constraint. The manipulation leads to resource consumption.
This vulnerability is traded as CVE-2024-34158. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8523 | lmxcms up to 1.4 SQL Command Execution Module admin.php formatData data code injection
5 months ago
A vulnerability was found in lmxcms up to 1.4 and classified as critical. Affected by this issue is the function formatData of the file /admin.php?m=Acquisi&a=testcj&lid=1 of the component SQL Command Execution Module. The manipulation of the argument data leads to code injection.
This vulnerability is handled as CVE-2024-8523. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2024-45034 | Apache Airflow up to 2.10.0 DAG Folder unnecessary privileges
5 months ago
A vulnerability was found in Apache Airflow up to 2.10.0 and classified as critical. Affected by this issue is some unknown functionality of the component DAG Folder Handler. The manipulation leads to execution with unnecessary privileges.
This vulnerability is handled as CVE-2024-45034. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-7652 | Mozilla Thunderbird ECMA-262 type confusion
5 months ago
A vulnerability was found in Mozilla Thunderbird. It has been declared as critical. This vulnerability affects unknown code of the component ECMA-262 Handler. The manipulation leads to type confusion.
This vulnerability was named CVE-2024-7652. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8538 | Big File Uploads Plugin up to 2.1.2 on WordPress information disclosure
5 months ago
A vulnerability has been found in Big File Uploads Plugin up to 2.1.2 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to information disclosure.
This vulnerability was named CVE-2024-8538. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-6849 | Preloader Plus Plugin up to 2.2.1 on WordPress SVG File Upload cross site scripting
5 months ago
A vulnerability was found in Preloader Plus Plugin up to 2.2.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component SVG File Upload Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-6849. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-8521 | Wavelog up to 1.8.0 Live QSO /qso index manual cross site scripting
5 months ago
A vulnerability, which was classified as problematic, was found in Wavelog up to 1.8.0. Affected is the function index of the file /qso of the component Live QSO. The manipulation of the argument manual leads to cross site scripting.
This vulnerability is traded as CVE-2024-8521. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
idekCTF 2024 Writeup - Advanced iframe Magic
5 months ago
In idekCTF 2024, there was an interesting problem called srcdoc-memos from @icesfont,
idekCTF 2024 筆記之 iframe 高級魔法
5 months ago
在 idekCTF 2024 中,由 icesfont 所出的一道題目 srcdoc-memos 十分有趣,牽涉到了許多 iframe 的相關知識。我沒有實際參加比賽,但賽
CVE-2024-8317 | WP AdCenter Plugin up to 2.5.6 on WordPress ad_alignment cross site scripting
5 months ago
A vulnerability was found in WP AdCenter Plugin up to 2.5.6 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument ad_alignment leads to cross site scripting.
This vulnerability is handled as CVE-2024-8317. The attack may be launched remotely. There is no exploit available.
vuldb.com