diff --git a/cache/Tenable (Nessus).dat b/cache/Tenable (Nessus).dat index dca05da4664..1e94d1b32c3 100644 --- a/cache/Tenable (Nessus).dat +++ b/cache/Tenable (Nessus).dat @@ -184,3 +184,13 @@ b7c55675e473a905ba15bf84a535d23a f968527478b6017203e184ec4200de4d c239db33de976c8c4f6e9b5c44bd91b3 f57a898b45cfc90b1252c7672c88ca28 +6e71989836e1ff82f38414549d1066f4 +0d8bfc5a664d5e9c846b5f689c19635c +1781d40b4b0955a4d1e8ae8fac86d8fe +df69561f3b1d960fe902204418e1e916 +cdbc809db58b27f5f753dae319dfd168 +994a2d1809bb0d80e2f5306aec0b9823 +750a13999a8cc7060d9b5dfd632fbec0 +f822e91a354e635894cbca7ab6594b3a +35d95b29c8948aacb6771ceb3d4d7e79 +1e333e04c4a85ec7b87d4e7664c63d86 diff --git a/data/cves.db b/data/cves.db index db086a792a1..6696589359d 100644 Binary files a/data/cves.db and b/data/cves.db differ diff --git a/docs/index.html b/docs/index.html index 0544f671df9..3ef51b8f93a 100644 --- a/docs/index.html +++ b/docs/index.html @@ -1,4 +1,4 @@ - + @@ -283,6 +283,86 @@

眈眈探求 | TITLE URL + + 6e71989836e1ff82f38414549d1066f4 + CVE-2024-25027 + 2024-03-31 12:15:50 + IBM Security Verify Access 10.0.6 could disclose sensitive snapshot information due to missing encryption. IBM X-Force ID: 281607. + 详情 + + + + 0d8bfc5a664d5e9c846b5f689c19635c + CVE-2024-22353 + 2024-03-31 12:15:50 + IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.3 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 280400. + 详情 + + + + 1781d40b4b0955a4d1e8ae8fac86d8fe + CVE-2023-50959 + 2024-03-31 12:15:50 + IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2,19.0.1, 19.0.2, 19.0.3,20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1,2 2.0.2, 23.0.1, and 23.0.2 may allow end users to query more documents than expected from a connected Enterprise Content Management system when configured to use a system account. IBM X-Force ID: 275938. + 详情 + + + + df69561f3b1d960fe902204418e1e916 + CVE-2023-50311 + 2024-03-31 12:15:49 + IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. IBM X-Force ID: 273612. + 详情 + + + + cdbc809db58b27f5f753dae319dfd168 + CVE-2020-36828 + 2024-03-31 09:15:10 + A vulnerability was found in DiscuzX up to 3.4-20200818. It has been classified as problematic. Affected is the function show_next_step of the file upload/install/include/install_function.php. The manipulation of the argument uchidden leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 3.4-20210119 is able to address this issue. The name of the patch is 4a9673624f46f7609486778ded9653733020c567. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-258612. + 详情 + + + + 994a2d1809bb0d80e2f5306aec0b9823 + CVE-2017-20191 + 2024-03-31 09:15:10 + A vulnerability was found in Zimbra zm-admin-ajax up to 8.8.1. It has been classified as problematic. This affects the function XFormItem.prototype.setError of the file WebRoot/js/ajax/dwt/xforms/XFormItem.js of the component Form Textbox Field Error Handler. The manipulation of the argument message leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 8.8.2 is able to address this issue. The identifier of the patch is bb240ce0c71c01caabaa43eed30c78ba8d7d3591. It is recommended to upgrade the affected component. The identifier VDB-258621 was assigned to this vulnerability. + 详情 + + + + 750a13999a8cc7060d9b5dfd632fbec0 + CVE-2015-10131 + 2024-03-31 06:15:07 + A vulnerability was found in chrisy TFO Graphviz Plugin up to 1.9 on WordPress and classified as problematic. Affected by this issue is the function admin_page_load/admin_page of the file tfo-graphviz-admin.php. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version 1.10 is able to address this issue. The name of the patch is 594c953a345f79e26003772093b0caafc14b92c2. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-258620. + 详情 + + + + f822e91a354e635894cbca7ab6594b3a + CVE-2024-3118 + 2024-03-31 05:15:07 + A vulnerability, which was classified as critical, has been found in Dreamer CMS up to 4.1.3. This issue affects some unknown processing of the component Attachment Handler. The manipulation leads to permission issues. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258779. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. + 详情 + + + + 35d95b29c8948aacb6771ceb3d4d7e79 + CVE-2024-3117 + 2024-03-31 02:15:09 + A vulnerability classified as critical was found in YouDianCMS up to 9.5.12. This vulnerability affects unknown code of the file App\Lib\Action\Admin\ChannelAction.class.php. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-258778 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. + 详情 + + + + 1e333e04c4a85ec7b87d4e7664c63d86 + CVE-2023-46808 + 2024-03-31 02:15:08 + An file upload vulnerability in Ivanti ITSM before 2023.4, allows an authenticated remote user to perform file writes to the server. Successful exploitation may lead to execution of commands in the context of non-root user. + 详情 + + 7f1f0b4edbcebebd4b64393bfd69648e CVE-2024-3091 @@ -366,7 +446,7 @@

眈眈探求 | + 2024-03-29 17:15:21 Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. The tarballs included extra .m4 files, which contained instructions for building with automake that did not exist in the repository. These instructions, through a series of complex obfuscations, extract a prebuilt object file from one of the test archives, which is then used to modify specific functions in the code while building the liblzma package. This issue results in liblzma being used by additional software, like sshd, to provide functionality that will be interpreted by the modified functions. 详情 @@ -374,7 +454,7 @@

眈眈探求 | + 2024-03-29 17:15:20 An issue in Huashi Private Cloud CDN Live Streaming Acceleration Server hgateway-sixport v.1.1.2 allows a remote attacker to execute arbitrary code via the manager/ipping.php component. 详情 @@ -382,7 +462,7 @@

眈眈探求 | + 2024-03-29 17:15:20 Cross-Site Request Forgery (CSRF) vulnerability in All In One WP Security & Firewall Team All In One WP Security & Firewall.This issue affects All In One WP Security & Firewall: from n/a through 5.2.6. 详情 @@ -390,7 +470,7 @@

眈眈探求 | + 2024-03-29 17:15:19 Missing Authorization vulnerability in realmag777 BEAR.This issue affects BEAR: from n/a through 1.1.4.3. 详情 @@ -398,7 +478,7 @@

眈眈探求 | + 2024-03-29 17:15:19 Cross-Site Request Forgery (CSRF) vulnerability in realmag777 HUSKY – Products Filter for WooCommerce (formerly WOOF).This issue affects HUSKY – Products Filter for WooCommerce (formerly WOOF): from n/a through 1.3.5.1. 详情 @@ -406,7 +486,7 @@

眈眈探求 | + 2024-03-29 17:15:18 Cross-Site Request Forgery (CSRF) vulnerability in Tumult Inc Tumult Hype Animations.This issue affects Tumult Hype Animations: from n/a through 1.9.11. 详情 @@ -414,7 +494,7 @@

眈眈探求 | + 2024-03-29 17:15:18 Cross-Site Request Forgery (CSRF) vulnerability in GamiPress.This issue affects GamiPress: from n/a through 6.8.5. 详情 @@ -422,7 +502,7 @@

眈眈探求 | + 2024-03-29 17:15:17 Cross-Site Request Forgery (CSRF) vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.6.2. 详情 @@ -430,7 +510,7 @@

眈眈探求 | + 2024-03-29 17:15:17 Server-Side Request Forgery (SSRF) vulnerability in Brave Brave Popup Builder.This issue affects Brave Popup Builder: from n/a through 0.6.5. 详情 @@ -438,91 +518,11 @@

眈眈探求 | + 2024-03-29 17:15:16 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps Landing Page Builder allows Stored XSS.This issue affects Landing Page Builder: from n/a through 1.5.1.7. 详情 - - d3b52217fef64ee1339af12b1f756bfc - CVE-2023-42974 - 2024-03-28 16:15:08 - A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Sonoma 14.2. An app may be able to execute arbitrary code with kernel privileges. - 详情 - - - - 28509477474de2ed54cd7b70708b1199 - CVE-2023-42962 - 2024-03-28 16:15:08 - This issue was addressed with improved checks This issue is fixed in iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. A remote attacker may be able to cause a denial-of-service. - 详情 - - - - 66a17d6fbf7ab37f2ee892ecc4898a1c - CVE-2023-42956 - 2024-03-28 16:15:08 - The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2. Processing web content may lead to a denial-of-service. - 详情 - - - - 8557515aaad8b3fb2eafab764ae4ee50 - CVE-2023-42950 - 2024-03-28 16:15:08 - A use after free issue was addressed with improved memory management. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. Processing maliciously crafted web content may lead to arbitrary code execution. - 详情 - - - - eb714c6eaa034decbbdcb28ef33c43b9 - CVE-2023-42947 - 2024-03-28 16:15:08 - A path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. An app may be able to break out of its sandbox. - 详情 - - - - 140ef325724cea96f83ff291b536ead5 - CVE-2023-42936 - 2024-03-28 16:15:08 - This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. An app may be able to access user-sensitive data. - 详情 - - - - ca4481a749c668341a3881de2a526ac3 - CVE-2023-42931 - 2024-03-28 16:15:08 - The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. A process may gain admin privileges without proper authentication. - 详情 - - - - 0359c6de823482f3fa031fb94e1d7561 - CVE-2023-42930 - 2024-03-28 16:15:08 - This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. An app may be able to modify protected parts of the file system. - 详情 - - - - 3ea930dc0ab0a283c47533c50c715c1c - CVE-2023-42913 - 2024-03-28 16:15:08 - This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.2. Remote Login sessions may be able to obtain full disk access permissions. - 详情 - - - - 8d867f8f0eeb125a8c541c3614efa3fb - CVE-2023-42896 - 2024-03-28 16:15:07 - An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Sonoma 14.2. An app may be able to modify protected parts of the file system. - 详情 - - @@ -1974,7 +1974,7 @@

眈眈探求 | + 2024-03-29 09:22:00 baserCMS跨站脚本漏洞 详情 @@ -1982,7 +1982,7 @@

眈眈探求 | + 2024-03-29 09:22:00 Wireshark拒绝服务漏洞 详情 @@ -1990,7 +1990,7 @@

眈眈探求 | + 2024-03-29 09:22:00 GitLab CE/EE跨站脚本漏洞 详情 @@ -1998,7 +1998,7 @@

眈眈探求 | + 2024-03-29 09:22:00 flusity-CMS跨站请求伪造漏洞 详情 @@ -2006,7 +2006,7 @@

眈眈探求 | + 2024-03-29 09:22:00 Archer Platform跨站脚本漏洞 详情 @@ -2014,7 +2014,7 @@

眈眈探求 | + 2024-03-29 09:22:00 Dromara Hertzbeat JNDI注入漏洞 详情 @@ -2022,7 +2022,7 @@

眈眈探求 | + 2024-03-29 09:22:00 XWiki licensor application信息泄露漏洞 详情 @@ -2030,7 +2030,7 @@

眈眈探求 | + 2024-03-29 09:22:00 Tenda AC23堆栈缓冲区溢出漏洞 详情 @@ -2038,7 +2038,7 @@

眈眈探求 | + 2024-03-29 09:22:00 Autodesk AutoCAD内存破坏漏洞 详情 @@ -2046,7 +2046,7 @@

眈眈探求 | + 2024-03-29 09:22:00 ZhongBangKeJi CRMEB路径遍历漏洞 详情 @@ -2054,7 +2054,7 @@

眈眈探求 | + 2024-03-29 09:22:00 PMB SQL注入漏洞 详情 @@ -2062,7 +2062,7 @@

眈眈探求 | + 2024-03-29 09:22:00 Mozilla Focus iOS跨站脚本漏洞 详情 @@ -2070,7 +2070,7 @@

眈眈探求 | + 2024-03-29 09:22:00 ChurchCRM SQL注入漏洞 详情 @@ -2078,7 +2078,7 @@

眈眈探求 | + 2024-03-29 09:22:00 Enhavo CMS跨站脚本漏洞 详情 @@ -2086,7 +2086,7 @@

眈眈探求 | + 2024-03-29 09:22:00 He3任意代码执行漏洞 详情 @@ -2094,7 +2094,7 @@

眈眈探求 | + 2024-03-29 07:19:38 LIVEBOX Collaboration vDesk跨站脚本漏洞 详情 @@ -2102,7 +2102,7 @@

眈眈探求 | + 2024-03-29 07:19:38 Progress Software WS_FTP Server跨站脚本漏洞 详情 @@ -2110,7 +2110,7 @@

眈眈探求 | + 2024-03-29 07:19:38 Terminalfour存储型跨站脚本漏洞 详情 @@ -2118,7 +2118,7 @@

眈眈探求 | + 2024-03-29 07:19:38 Kirby CMS HTML注入漏洞 详情 @@ -2126,7 +2126,7 @@

眈眈探求 | + 2024-03-29 07:19:38 Apache Answer跨站脚本漏洞 详情 @@ -2134,7 +2134,7 @@

眈眈探求 | + 2024-03-29 07:19:38 ConnectWise ScreenConnect路径遍历漏洞 详情 @@ -2142,7 +2142,7 @@

眈眈探求 | + 2024-03-29 07:19:38 Apache Answer竞争条件漏洞 详情 @@ -2150,7 +2150,7 @@

眈眈探求 | + 2024-03-29 07:19:38 Kirby CMS跨站脚本漏洞 详情 @@ -2158,7 +2158,7 @@

眈眈探求 | + 2024-03-29 07:19:38 Flusity-CMS跨站脚本漏洞 详情 @@ -2166,7 +2166,7 @@

眈眈探求 | + 2024-03-29 07:19:38 Umbraco跨站脚本漏洞 详情 @@ -2174,7 +2174,7 @@

眈眈探求 | + 2024-03-29 07:19:38 Health Level 7 FHIR Core Libraries路径遍历漏洞 详情 @@ -2182,7 +2182,7 @@

眈眈探求 | + 2024-03-29 07:19:38 Apache Server跨站脚本漏洞 详情 @@ -2190,7 +2190,7 @@

眈眈探求 | + 2024-03-29 07:19:38 Umbraco跨站脚本漏洞 详情 @@ -2198,7 +2198,7 @@

眈眈探求 | + 2024-03-29 07:19:38 Elastic Agent信息泄露漏洞 详情 @@ -2206,7 +2206,7 @@

眈眈探求 | + 2024-03-29 07:19:38 h2o加密签名验证错误漏洞 详情