diff --git a/cache/Nsfocus.dat b/cache/Nsfocus.dat index 8a2fc1c1016..2ab8d135e37 100644 --- a/cache/Nsfocus.dat +++ b/cache/Nsfocus.dat @@ -110,3 +110,18 @@ b07a1ec58f70215aa021180da41ee232 6348e9f3756f4714dfbb7dd2aff3a730 a8ec06a4e0f47231252875fb8fefa36a 8c674861023757c78b0f5cfcf0b0bda3 +9b368c17888c65df6929d8f87e4b2d06 +38f84c839bb56448823c2d67f5a9b457 +67abdcdc9c614adccc233e6062481acb +aa39b65667b1ed217b8bb5dc7f610621 +6971705f6fd26d8ffcfe7dcf2829e56e +ba69c37ce2af176e6e5d299663cbd1a9 +f10a69b7878eaf1de9ebee4177f4144b +cc45cd2691130df4abe65400f883ac1d +2f25e9d021f931417f4f4b0ea4655db5 +262be7833d03f45251a687bb13bbbdaf +e64524aa786d405936863429af4eca8b +c2ca3de98c882ba5f8d73ab0796b5754 +14075a463d3f3d9fc4afff6075200729 +9b62437976f086ff6604f2db9f22753f +27c8185a1e0fd60507c890696885af8a diff --git a/data/cves.db b/data/cves.db index 27958fb4ca6..3056174d1c7 100644 Binary files a/data/cves.db and b/data/cves.db differ diff --git a/docs/index.html b/docs/index.html index b36035f90d7..e762e9377f5 100644 --- a/docs/index.html +++ b/docs/index.html @@ -1,4 +1,4 @@ - + @@ -38,7 +38,7 @@

眈眈探求 | + 2023-09-18 07:04:38 安全事件周报 2023-09-11 第37周 详情 @@ -350,7 +350,7 @@

眈眈探求 | + 2023-09-18 22:15:47 SQLpage is a SQL-only webapp builder. Someone using SQLpage versions prior to 0.11.1, whose SQLpage instance is exposed publicly, with a database connection string specified in the `sqlpage/sqlpage.json` configuration file (not in an environment variable), with the web_root is the current working directory (the default), and with their database exposed publicly, is vulnerable to an attacker retrieving database connection information from SQLPage and using it to connect to their database directly. Version 0.11.0 fixes this issue. Some workarounds are available. Using an environment variable instead of the configuration file to specify the database connection string prevents exposing it on vulnerable versions. Using a different web root (that is not a parent of the SQLPage configuration directory) fixes the issue. One should also avoid exposing one's database publicly. 详情 @@ -358,7 +358,7 @@

眈眈探求 | + 2023-09-18 22:15:47 Pow is a authentication and user management solution for Phoenix and Plug-based apps. Starting in version 1.0.14 and prior to version 1.0.34, use of `Pow.Store.Backend.MnesiaCache` is susceptible to session hijacking as expired keys are not being invalidated correctly on startup. A session may expire when all `Pow.Store.Backend.MnesiaCache` instances have been shut down for a period that is longer than a session's remaining TTL. Version 1.0.34 contains a patch for this issue. As a workaround, expired keys, including all expired sessions, can be manually invalidated. 详情 @@ -1734,7 +1734,7 @@

眈眈探求 | + 2023-09-18 20:07:48 MOZILLA Multiple product Vulnerability 详情 @@ -1742,7 +1742,7 @@

眈眈探求 | + 2023-09-18 20:07:47 MOZILLA Multiple product Vulnerability 详情 @@ -1750,7 +1750,7 @@

眈眈探求 | + 2023-09-18 20:07:47 MOZILLA Multiple product Vulnerability 详情 @@ -2092,123 +2092,123 @@

眈眈探求 | - Titan FTP Server开放重定向漏洞 - 详情 + 9b368c17888c65df6929d8f87e4b2d06 + CVE-2023-36923 + 2023-09-19 03:21:04 + SAP PowerDesigner代码注入漏洞 + 详情 - 8ecba32dbfef2d8973f668bc11f1a385 - CVE-2023-39578 - 2023-09-18 07:19:58 - 跨站脚本漏洞 - 详情 + 38f84c839bb56448823c2d67f5a9b457 + CVE-2023-3365 + 2023-09-19 03:21:04 + WordPress MultiParcels Shipping For WooCommerce plugin授权错误漏洞 + 详情 - 06d7e2ba70b7bd0b1fbabe332f2e346d - CVE-2023-39708 - 2023-09-18 07:19:58 - Inventory Management System跨站脚本漏洞 - 详情 + 67abdcdc9c614adccc233e6062481acb + CVE-2023-3522 + 2023-09-19 03:21:04 + a2 License Portal System SQL注入漏洞 + 详情 - d16b66c1e1605f77ef7e4b175c8e6a84 - CVE-2023-23772 - 2023-09-18 07:19:58 - Motorola MBTS Site Controller加密签名验证错误漏洞 - 详情 + aa39b65667b1ed217b8bb5dc7f610621 + CVE-2023-38762 + 2023-09-19 03:21:04 + ChurchCRM SQL注入漏洞 + 详情 - 498fb080153240c0ac0563e2900f006e - CVE-2023-41005 - 2023-09-18 07:19:58 - pagekit任意代码执行漏洞 - 详情 + 6971705f6fd26d8ffcfe7dcf2829e56e + CVE-2023-27411 + 2023-09-19 03:21:04 + Siemens RUGGEDCOM CROSSBOW SQL注入漏洞 + 详情 - 880d51fcf2a7a5066fe4a6a921988757 - CVE-2023-40826 - 2023-09-18 07:19:58 - pf4j路径遍历漏洞 - 详情 + ba69c37ce2af176e6e5d299663cbd1a9 + CVE-2022-48580 + 2023-09-19 03:21:04 + ScienceLogic SL1命令注入漏洞 + 详情 - a7a091a2bd4e5a3b852ede7ef595e1f2 - CVE-2023-39615 - 2023-09-18 07:19:58 - Libxml2越界读取漏洞 - 详情 + f10a69b7878eaf1de9ebee4177f4144b + CVE-2023-38213 + 2023-09-19 03:21:04 + Adobe Dimension越界读取漏洞 + 详情 - 3799be0904da892dec49ad2cbbc5132b - CVE-2023-0654 - 2023-09-18 07:19:58 - Cloudflare WARP Mobile Client渲染UI层或帧限制错误漏洞 - 详情 + cc45cd2691130df4abe65400f883ac1d + CVE-2023-3857 + 2023-09-19 03:21:04 + phpscriptpoint Ecommerce跨站脚本漏洞 + 详情 - 48b85fe24ba567ec2d155e7cd88711af - CVE-2022-47069 - 2023-09-18 07:19:58 - p7zip堆缓冲区溢出漏洞 - 详情 + 2f25e9d021f931417f4f4b0ea4655db5 + CVE-2023-3850 + 2023-09-19 03:21:04 + Lost and Found Information System SQL注入漏洞 + 详情 - 81cb0c8f6ad4b141b4d773bb58fb41db - CVE-2022-48065 - 2023-09-18 07:19:58 - GNU Binutils内存泄露漏洞 - 详情 + 262be7833d03f45251a687bb13bbbdaf + CVE-2023-3845 + 2023-09-19 03:21:04 + mooSocial mooDating跨站脚本漏洞 + 详情 - 5a7ded38347c1c65963513bd24d71353 - CVE-2022-48547 - 2023-09-18 07:19:58 - Cacti跨站脚本漏洞 - 详情 + e64524aa786d405936863429af4eca8b + CVE-2023-3839 + 2023-09-19 03:21:04 + DedeBIZ SQL注入漏洞 + 详情 - 83840beb7ed03b10477f4599a205a7bc - CVE-2022-48570 - 2023-09-18 07:19:58 - Crypto++越界写入漏洞 - 详情 + c2ca3de98c882ba5f8d73ab0796b5754 + CVE-2023-3834 + 2023-09-19 03:21:04 + Bug Finder EX-RATE跨站脚本漏洞 + 详情 - f29419a9f961ac2518bffbc7b367d4e4 - CVE-2023-24515 - 2023-09-18 07:19:58 - Artica Pandora FMS服务器端请求伪造漏洞 - 详情 + 14075a463d3f3d9fc4afff6075200729 + CVE-2023-3830 + 2023-09-19 03:21:04 + Bug Finder SASS BILLER跨站脚本漏洞 + 详情 - afb625aedd81891c198f84d4099c4025 - CVE-2023-36281 - 2023-09-18 07:19:58 - LangChain代码注入漏洞 - 详情 + 9b62437976f086ff6604f2db9f22753f + CVE-2023-26961 + 2023-09-19 03:21:04 + Alteryx Server跨站脚本漏洞 + 详情 - 5146b49d6f4b436eac2840e8a5ac5202 - CVE-2023-37426 - 2023-09-18 07:19:58 - Aruba Networks EdgeConnect SD-WAN Orchestrator硬编码凭据使用漏洞 - 详情 + 27c8185a1e0fd60507c890696885af8a + CVE-2023-3970 + 2023-09-19 03:21:04 + GZ Scripts Availability Booking Calendar PHP跨站脚本漏洞 + 详情