diff --git a/cache/Nsfocus.dat b/cache/Nsfocus.dat index 16650088063..82daaec2948 100644 --- a/cache/Nsfocus.dat +++ b/cache/Nsfocus.dat @@ -165,3 +165,18 @@ b2f58e8f62b4e9339bbb478150ec06c3 915db4f34909051e3f6c1c7a5cb386e4 72f83f5a2a24b29878dd4011390f438c ec4502947e25e47010f7d4710347b8c0 +971a81fba778ecec14671a555e020494 +50427f357dc166483301cbb4329c9e2a +351c3bb521b71a31b49ba32091af01d1 +7a5082f0db5f8ad0c5aef57b363ff539 +9d3e40f8f28fe5cebbd35a7aef8added +03f52611f0a11a748dbef49708e54985 +8865ba7501c7be11bce6f55053b158bf +2f782c77ec6757439d4412ef701ad036 +80ae1353b9fbdd289ce6765167c52656 +aa59055cfc2f23f6d4cafa17a421b795 +68cdf900cb1bd9ae9b729a95362264e8 +6b12d8e3fa6b20ba95b451e687109379 +d29d82787c2da193123e4d040ee03992 +04b55bd10751bcc91cfd0b94a4387fea +c40978a5190426452e38a2539d387922 diff --git a/data/cves.db b/data/cves.db index 24f2a4621e2..f8220526d10 100644 Binary files a/data/cves.db and b/data/cves.db differ diff --git a/docs/index.html b/docs/index.html index 7e835da3d5b..503a4c303bc 100644 --- a/docs/index.html +++ b/docs/index.html @@ -1,4 +1,4 @@ - + @@ -294,7 +294,7 @@

眈眈探求 | + 2023-09-16 23:15:07 A vulnerability has been found in Pluck CMS 4.7.18 and classified as problematic. This vulnerability affects unknown code of the file install.php of the component Installation Handler. The manipulation of the argument contents with the input leads to cross site scripting. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. VDB-239854 is the identifier assigned to this vulnerability. 详情 @@ -302,7 +302,7 @@

眈眈探求 | + 2023-09-16 21:15:47 A vulnerability, which was classified as problematic, was found in Topaz OFD 2.11.0.201. This affects an unknown part of the file C:\Program Files\Topaz OFD\Warsaw\core.exe of the component Protection Module Warsaw. The manipulation leads to unquoted search path. Attacking locally is a requirement. The identifier VDB-239853 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. 详情 @@ -310,7 +310,7 @@

眈眈探求 | + 2023-09-16 09:15:07 The Dropbox Folder Share plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.9.7 via the 'link' parameter. This can allow unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. 详情 @@ -318,7 +318,7 @@

眈眈探求 | + 2023-09-16 06:15:07 Multiple stored cross-site scripting (XSS) vulnerabilities in Usermin 2.000 allow remote attackers to inject arbitrary web script or HTML via the folder name parameter while creating the folder to manage the folder tab, filter tab, and forward mail tab. 详情 @@ -326,7 +326,7 @@

眈眈探求 | + 2023-09-16 05:15:45 The Horizontal scrolling announcement for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'horizontal-scrolling' shortcode in versions up to, and including, 9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. 详情 @@ -334,7 +334,7 @@

眈眈探求 | + 2023-09-16 02:15:07 The Allow PHP in Posts and Pages plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.0.4 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server. 详情 @@ -342,7 +342,7 @@

眈眈探求 | + 2023-09-16 01:15:08 An issue in NETIS SYSTEMS WF2409Ev4 v.1.0.1.705 allows a remote attacker to execute arbitrary code and obtain sensitive information via the password parameter in the /etc/shadow.sample component. 详情 @@ -350,7 +350,7 @@

眈眈探求 | + 2023-09-16 01:15:08 A cross-site scripting (XSS) vulnerability in the Admin Control Panel of vBulletin 5.7.5 and 6.0.0 allows attackers to execute arbitrary web scripts or HTML via the /login.php?do=login url parameter. 详情 @@ -358,7 +358,7 @@

眈眈探求 | + 2023-09-16 01:15:07 A cross-site scripting (XSS) vulnerability in FileBrowser before v2.23.0 allows an authenticated attacker to escalate privileges to Administrator via user interaction with a crafted HTML file or URL. 详情 @@ -366,7 +366,7 @@

眈眈探求 | + 2023-09-16 00:15:08 Cross Site Scripting vulnerability in CSZCMS v.1.3.0 allows a local attacker to execute arbitrary code via a crafted script to the Additional Meta Tag parameter in the Pages Content Menu component. 详情 @@ -374,7 +374,7 @@

眈眈探求 | + 2023-09-16 00:15:07 An issue was discovered in Qubo Smart Plug10A version HSP02_01_01_14_SYSTEM-10 A, allows local attackers to gain sensitive information and other unspecified impact via UART console. 详情 @@ -1798,7 +1798,7 @@

眈眈探求 | + 2023-09-16 20:10:41 APACHE AIRFLOW Vulnerability 详情 @@ -1806,7 +1806,7 @@

眈眈探求 | + 2023-09-16 20:10:41 Adobe InCopy 缓冲区错误漏洞 详情 @@ -1814,7 +1814,7 @@

眈眈探求 | + 2023-09-16 20:10:41 APPLE MACOS Vulnerability 详情 @@ -1822,7 +1822,7 @@

眈眈探求 | + 2023-09-16 20:10:05 APACHE AIRFLOW Vulnerability 详情 @@ -1830,7 +1830,7 @@

眈眈探求 | + 2023-09-16 20:10:05 Adobe InCopy 资源管理错误漏洞 详情 @@ -1838,7 +1838,7 @@

眈眈探求 | + 2023-09-16 20:10:05 MOZILLA Multiple product Vulnerability 详情 @@ -1846,7 +1846,7 @@

眈眈探求 | + 2023-09-16 20:10:05 APPLE Multiple product Vulnerability 详情 @@ -1854,7 +1854,7 @@

眈眈探求 | + 2023-09-16 20:10:05 ZOHOCORP MANAGEENGINE_ADMANAGER_PLUS Vulnerability 详情 @@ -1862,7 +1862,7 @@

眈眈探求 | + 2023-09-16 20:10:04 GOLANG GO Vulnerability 详情 @@ -1870,7 +1870,7 @@

眈眈探求 | + 2023-09-16 20:10:04 MOZILLA Multiple product Vulnerability 详情 @@ -1971,6 +1971,126 @@

眈眈探求 | TITLE URL + + 971a81fba778ecec14671a555e020494 + CVE-2020-36761 + 2023-09-18 03:20:59 + WordPress Top 10 Plugin跨站请求伪造漏洞 + 详情 + + + + 50427f357dc166483301cbb4329c9e2a + CVE-2021-4423 + 2023-09-18 03:20:59 + WordPress RAYS Grid Plugin跨站请求伪造漏洞 + 详情 + + + + 351c3bb521b71a31b49ba32091af01d1 + CVE-2023-2078 + 2023-09-18 03:20:59 + WordPress Buy Me a Coffee – Button and Widget Plugin plugin授权错误漏洞 + 详情 + + + + 7a5082f0db5f8ad0c5aef57b363ff539 + CVE-2023-38404 + 2023-09-18 03:20:59 + Veritas Technologies Infoscale Operations Manager任意文件上传漏洞 + 详情 + + + + 9d3e40f8f28fe5cebbd35a7aef8added + CVE-2023-28754 + 2023-09-18 03:20:59 + Apache ShardingSphere-Agent不受信数据反序列化漏洞 + 详情 + + + + 03f52611f0a11a748dbef49708e54985 + CVE-2023-3753 + 2023-09-18 03:20:59 + Creativeitem Mastery LMS跨站脚本漏洞 + 详情 + + + + 8865ba7501c7be11bce6f55053b158bf + CVE-2023-33876 + 2023-09-18 03:20:59 + Foxit Reader内存错误引用漏洞 + 详情 + + + + 2f782c77ec6757439d4412ef701ad036 + CVE-2023-37289 + 2023-09-18 03:20:59 + InfoDoc Document On-line Submission and Approval System任意文件上传漏洞 + 详情 + + + + 80ae1353b9fbdd289ce6765167c52656 + CVE-2022-46651 + 2023-09-18 03:20:59 + Apache Airflow信息泄露漏洞 + 详情 + + + + aa59055cfc2f23f6d4cafa17a421b795 + CVE-2021-43759 + 2023-09-18 03:20:59 + Adobe Media Encoder越界读取漏洞 + 详情 + + + + 68cdf900cb1bd9ae9b729a95362264e8 + CVE-2023-3167 + 2023-09-18 03:20:59 + WordPress Mail Queue Plugin跨站脚本漏洞 + 详情 + + + + 6b12d8e3fa6b20ba95b451e687109379 + CVE-2020-36756 + 2023-09-18 03:20:59 + WordPress 10WebAnalytics Plugin跨站请求伪造漏洞 + 详情 + + + + d29d82787c2da193123e4d040ee03992 + CVE-2023-33990 + 2023-09-18 03:20:59 + SAP SQL Anywhere拒绝服务漏洞 + 详情 + + + + 04b55bd10751bcc91cfd0b94a4387fea + CVE-2023-37597 + 2023-09-18 03:20:59 + Issabel PBX跨站请求伪造漏洞 + 详情 + + + + c40978a5190426452e38a2539d387922 + CVE-2021-4407 + 2023-09-18 03:20:59 + WordPress Custom Banners Plugin跨站请求伪造漏洞 + 详情 + + f355e297672e1c43d23b211d3ee872e8 CVE-2023-39094 @@ -2091,126 +2211,6 @@

眈眈探求 | 详情 - - 814eb1ccb375eab6369c053a5ace552d - CVE-2020-22623 - 2023-09-14 03:20:56 - Jinfornet Jreport目录遍历漏洞 - 详情 - - - - 54c591662f9076fe7c6eaaf2129b83d2 - CVE-2023-20224 - 2023-09-14 03:20:56 - Cisco ThousandEyes Enterprise Agent参数注入漏洞 - 详情 - - - - 41e30fb118e923458db6b464422c09bb - CVE-2023-2 - 2023-09-14 03:20:56 - Cisco Prime Infrastructure和Evolved Programmable Network Manager跨站脚本漏洞(CVE-2023-2 - 详情 - - - - e76a62d0ec600c9026fbc20a854cfd0a - CVE-2022-4894 - 2023-09-14 03:20:56 - HP LaserJet Printers不受控制的搜索路径元素漏洞 - 详情 - - - - e86f6ec47e23f439bae3a372618fa5db - CVE-2023-4389 - 2023-09-14 03:20:56 - Linux Kernel内存错误引用漏洞 - 详情 - - - - fa59875d140a2a3ca2f726ece901bd75 - CVE-2023-40272 - 2023-09-14 03:20:56 - Apache Airflow Spark Provider输入验证错误漏洞 - 详情 - - - - 6da2c6165ec60c6517f1e588fbe62801 - CVE-2021-4320 - 2023-09-14 03:20:56 - Google Chrome内存错误引用漏洞 - 详情 - - - - 1c4ed0c65409d02c1ff3c921d9447592 - CVE-2023-3130 - 2023-09-14 03:20:56 - WordPress Short URL plugin跨站脚本漏洞 - 详情 - - - - 43c7f61c77dd783474e71466b2880fa1 - CVE-2020-10962 - 2023-09-14 03:20:56 - PowerShell App Deployment Toolkit访问控制错误漏洞 - 详情 - - - - 9d387648e5857c6d9a15df1815ffc996 - CVE-2023-38303 - 2023-09-14 03:20:56 - Webmin跨站脚本漏洞 - 详情 - - - - d51e1333c1178b085879fcb61ea8bc9e - - 2023-09-14 03:20:56 - WordPress WooCommerce Checkout & Funnel Builder by CartFlows Plugin跨站请求伪造漏洞( - 详情 - - - - 7064cd1a93cd316cb8dd901561853630 - CVE-2021-4386 - 2023-09-14 03:20:56 - WordPress WP Security Question Plugin跨站请求伪造漏洞 - 详情 - - - - 52f43b0ff8cb90dfa320adf9917bb4e0 - CVE-2021-4392 - 2023-09-14 03:20:56 - WordPress eCommerce Product Catalog Plugin跨站请求伪造漏洞 - 详情 - - - - 5df99eeff9b02b8d44c774bdfebd7d6f - CVE-2020-36748 - 2023-09-14 03:20:56 - WordPress Dokan Plugin跨站请求伪造漏洞 - 详情 - - - - 093ead0c5d860eb9259391d683d22b92 - CVE-2021-4399 - 2023-09-14 03:20:56 - WordPress Edwiser Bridge Plugin跨站请求伪造漏洞 - 详情 - -