diff --git a/cache/Nsfocus.dat b/cache/Nsfocus.dat index 0f502508124..54d6b097d46 100644 --- a/cache/Nsfocus.dat +++ b/cache/Nsfocus.dat @@ -150,3 +150,18 @@ ea8a19af507112e643980f4a220fce83 a337f2354a3503d59786acc94840435c 7e092777c3c1f415f0b64d4452f54762 9ce02d37c5fe2187ec5d7d081c1971ae +f5fe9133cc9539f4e6e2efcd6968308c +ca72fddd4bbfdcf7531048b2ee9d72e8 +7245ba145c1a0de09d8f70f5ebb2e81a +247c467fb38393cdece0320403582765 +a70073ae02e240040507e03e3d928571 +66f34cec4dc79adb82279c005d4a8ecf +0b8b6aea051e0606022e0996680a4074 +31325878e76b2f80386715bc31439083 +bf11f84ac210a634a56cf433751fa23e +a258156d8aa7102f556bf4fe48d2bf96 +2076cba2d6bfba3ee4f324c4c6b86278 +8afb427efda362db24fa9cb8e43d5d63 +56facd6acce5d926bf87587c1c3810d2 +4c0f929068f47a9c7ecbe2b145299e74 +a092d5defdfcd58c864f82faf71e4b8b diff --git a/data/cves.db b/data/cves.db index 78dee025d45..4c7c9c1ca90 100644 Binary files a/data/cves.db and b/data/cves.db differ diff --git a/docs/index.html b/docs/index.html index cbda6600907..25415dc2558 100644 --- a/docs/index.html +++ b/docs/index.html @@ -1,4 +1,4 @@ - + @@ -366,7 +366,7 @@

眈眈探求 | + 2024-12-11 12:15:19 The Waymark plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. 详情 @@ -374,7 +374,7 @@

眈眈探求 | + 2024-12-11 11:15:06 The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.1 via the 'get_legacy_cookies' function. This makes it possible for unauthenticated attackers to extract sensitive data including titles and permalinks of private, password-protected, pending, and draft posts. 详情 @@ -382,7 +382,7 @@

眈眈探求 | + 2024-12-11 11:15:06 The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the uucss_data, update_rapidload_settings, wp_ajax_update_htaccess_file, uucss_update_rule, upload_rules, get_all_rules, update_titan_settings, preload_page, and activate_module functions in all versions up to, and including, 2.4.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify plugin settings or conduct SQL injection attacks. 详情 @@ -390,7 +390,7 @@

眈眈探求 | + 2024-12-11 11:15:04 The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.10 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as administrator. 详情 @@ -398,7 +398,7 @@

眈眈探求 | + 2024-12-11 10:15:07 Missing Authorization vulnerability in Ninja Team Notibar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Notibar: from n/a through 2.1.4. 详情 @@ -406,7 +406,7 @@

眈眈探求 | + 2024-12-11 10:15:07 Insufficient permissions in the TeamViewer Patch & Asset Management component prior to version 24.12 on Windows allows a local authenticated user to delete arbitrary files. TeamViewer Patch & Asset Management is part of TeamViewer Remote Management. 详情 @@ -414,7 +414,7 @@

眈眈探求 | + 2024-12-11 10:15:06 CWE-20: Improper Input Validation vulnerability exists that could lead to a denial of service and a loss of confidentiality, integrity of the controller when an unauthenticated crafted Modbus packet is sent to the device. 详情 @@ -422,7 +422,7 @@

眈眈探求 | + 2024-12-11 10:15:06 Rapid7 Insight Platform versions prior to November 13th 2024, suffer from a privilege escalation vulnerability whereby, due to a lack of authorization checks, an attacker can successfully update the password policy in the platform settings as a standard user by crafting an API (the functionality was not possible through the platform's User Interface). This vulnerability has been fixed as of November 13th 2024. 详情 @@ -430,7 +430,7 @@

眈眈探求 | + 2024-12-11 09:15:05 The WP Pipes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘x1’ parameter in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. 详情 @@ -438,7 +438,7 @@

眈眈探求 | + 2024-12-11 09:15:05 The WPC Order Notes for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.2. This is due to missing or incorrect nonce validation on the ajax_update_order_note() function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. 详情 @@ -2108,123 +2108,123 @@

眈眈探求 | - WordPress Lenxel Core for Lenxel(LNX) LMS Plugin跨站脚本漏洞 - 详情 + f5fe9133cc9539f4e6e2efcd6968308c + CVE-2024-49387 + 2024-12-12 03:37:17 + Acronis Cyber Protect信息泄露漏洞 + 详情 - 11398c77d757f8a44befc6a1c1ea47d3 - CVE-2024-10673 - 2024-12-11 09:25:37 - WordPress Top Store theme未授权任意插件安装漏洞 - 详情 + ca72fddd4bbfdcf7531048b2ee9d72e8 + CVE-2024-45276 + 2024-12-12 03:37:17 + Helmholz REX100身份验证不足漏洞 + 详情 - 3860b1051ea469c13b150126ccc27dec - CVE-2024-10674 - 2024-12-11 09:25:37 - WordPress Shop Mania theme未授权任意插件安装漏洞 - 详情 + 7245ba145c1a0de09d8f70f5ebb2e81a + + 2024-12-12 03:37:17 + PHPGurukul User Registration & Login and User Management System跨站请求伪造漏洞(CVE- + 详情 - 36c2e4bfd6d25fb83aac8d50bb2a4140 - CVE-2024-10667 - 2024-12-11 09:25:37 - WordPress Content Slider Block Plugin信息泄露漏洞 - 详情 + 247c467fb38393cdece0320403582765 + CVE-2024-45274 + 2024-12-12 03:37:17 + Helmholz REX100访问控制错误漏洞 + 详情 - 3a5778dca15231662366dfeb26ac88f2 - CVE-2024-10588 - 2024-12-11 09:25:37 - WordPress Debug Tool Plugin未授权数据访问漏洞 - 详情 + a70073ae02e240040507e03e3d928571 + CVE-2024-45275 + 2024-12-12 03:37:17 + Helmholz REX100信任管理问题漏洞 + 详情 - e47196a2885ab12637c978b39aa3b58c - CVE-2024-10779 - 2024-12-11 09:25:37 - WordPress Cowidgets – Elementor Addons Plugin信息泄露漏洞 - 详情 + 66f34cec4dc79adb82279c005d4a8ecf + CVE-2024-9974 + 2024-12-12 03:37:17 + Carlo Montero Online Eyewear Shop SQL注入漏洞 + 详情 - ef3e8c11b98085217b37a53308d5d50a - CVE-2024-10285 - 2024-12-11 09:25:37 - WordPress CE21 Suite Plugin敏感信息泄露漏洞 - 详情 + 0b8b6aea051e0606022e0996680a4074 + CVE-2024-47945 + 2024-12-12 03:37:17 + Rittal IoT Interface & CMC III Processing Unit会话劫持漏洞 + 详情 - 86ff960aaf3ddb15314e383ece28779c - CVE-2024-10625 - 2024-12-11 09:25:37 - WordPress WooCommerce Support Ticket System Plugin任意文件删除漏洞 - 详情 + 31325878e76b2f80386715bc31439083 + CVE-2024-9985 + 2024-12-12 03:37:17 + Ragic Enterprise Cloud Database任意代码执行漏洞 + 详情 - 4a4168454f53dc0406dd8ffb28cdf16a - CVE-2024-10770 - 2024-12-11 09:25:37 - WordPress Envo Extra Plugin信息泄露漏洞 - 详情 + bf11f84ac210a634a56cf433751fa23e + CVE-2024-9925 + 2024-12-12 03:37:17 + TAI Smart Factory QPLANT SF SQL注入漏洞 + 详情 - a7fbfa7389348e06f3322d2aa9735b2a - CVE-2024-10284 - 2024-12-11 09:25:37 - WordPress CE21 Suite Plugin身份认证绕过漏洞 - 详情 + a258156d8aa7102f556bf4fe48d2bf96 + CVE-2024-47944 + 2024-12-12 03:37:17 + Rittal IoT Interface & CMC III Processing Unit代码执行漏洞 + 详情 - 78de477ae9857ac8d94e0ce3589269f7 - CVE-2024-9775 - 2024-12-11 09:25:37 - WordPress Anih - Creative Agency WordPress Theme跨站脚本漏洞 - 详情 + 2076cba2d6bfba3ee4f324c4c6b86278 + CVE-2024-9982 + 2024-12-12 03:37:17 + ESi AIM LINE Marketing Platform SQL注入漏洞 + 详情 - e52b98ef7414c088b7cd36a5c97db314 - CVE-2024-10669 - 2024-12-11 09:25:37 - WordPress Countdown Timer Block Plugin信息泄露漏洞 - 详情 + 8afb427efda362db24fa9cb8e43d5d63 + CVE-2024-47824 + 2024-12-12 03:37:17 + matrix-react-sdk信息泄露漏洞 + 详情 - 22c953925bbb435f84dad07c780bd0de - CVE-2024-10586 - 2024-12-11 09:25:37 - WordPress Debug Tool Plugin任意文件创建漏洞 - 详情 + 56facd6acce5d926bf87587c1c3810d2 + + 2024-12-12 03:37:17 + PHPGurukul User Registration & Login and User Management System SQL注入漏洞(CVE- + 详情 - d94fbccd3fc942f27f00a3b4dc5faa1a - CVE-2024-10693 - 2024-12-11 09:25:37 - WordPress SKT Addons for Elementor Plugin信息泄露漏洞 - 详情 + 4c0f929068f47a9c7ecbe2b145299e74 + CVE-2024-9895 + 2024-12-12 03:37:17 + WordPress plugin Smart Online Order for Clover跨站脚本漏洞 + 详情 - 092ba82551c3144c64d385e618425922 - CVE-2024-10294 - 2024-12-11 09:25:37 - WordPress CE21 Suite Plugin未授权数据修改漏洞 - 详情 + a092d5defdfcd58c864f82faf71e4b8b + CVE-2024-49388 + 2024-12-12 03:37:17 + Acronis Cyber Protect信息泄露漏洞 + 详情