diff --git a/cache/Nsfocus.dat b/cache/Nsfocus.dat index bdaa00c092d..72b741eb16f 100644 --- a/cache/Nsfocus.dat +++ b/cache/Nsfocus.dat @@ -160,3 +160,18 @@ e0aa4544774272e2c98d6a9bb8890204 412d669f8ac690c0651a21833bab92c9 5837c79c7195b6add1024fdb7e91aa88 88e378320d4e928721b5fbacf7420682 +e61c1efc1f5af7804ab1c3528fef37d9 +39601cb762962eb366703dc30bc886de +33ce96cd71dedd3c235106156b2ff324 +c7def4ea696c108eb93b692bddee83bc +6d07ec69b7b043a85b0f0660928c98ee +442c553f5cedf44e6097d1fb2be8f74c +aa3a5ecf8eee986897e474c563a99537 +2139217ea92319abac23850b845cbac2 +dcc105dcd48b1f0e2001703e945514e8 +587b01605d72146d30f39133a5a97582 +ae4eb6b339a9b6d4ce1788aa00284ab5 +f02065024751c6d3c806bce29e3c5a17 +9c4fa38a0b44f16307cbeddb0c807366 +46800081e623fb2ec201249e4ed3fcc6 +b944360e4c315f7aab4510a9656672a6 diff --git a/data/cves.db b/data/cves.db index 95e5711462f..7a295b7b86f 100644 Binary files a/data/cves.db and b/data/cves.db differ diff --git a/docs/index.html b/docs/index.html index 98115e51c47..7c720d8e2ac 100644 --- a/docs/index.html +++ b/docs/index.html @@ -1,4 +1,4 @@ - + @@ -30,7 +30,7 @@

眈眈探求 | + 2023-10-23 07:15:02 安全事件周报 2023-10-16 第42周 详情 @@ -302,7 +302,7 @@

眈眈探求 | + 2023-10-23 23:15:00 carRental 1.0 is vulnerable to Incorrect Access Control (Arbitrary File Read on the Back-end System). 详情 @@ -310,7 +310,7 @@

眈眈探求 | + 2023-10-23 22:15:00 The reference count changes made as part of the CVE-2023-33951 and CVE-2023-33952 fixes exposed a use-after-free flaw in the way memory objects were handled when they were being used to store a surface. When running inside a VMware guest with 3D acceleration enabled, a local, unprivileged user could potentially use this flaw to escalate their privileges. 详情 @@ -318,7 +318,7 @@

眈眈探求 | + 2023-10-23 22:15:00 kodbox 1.44 is vulnerable to Cross Site Scripting (XSS). Customizing global HTML results in storing XSS. 详情 @@ -326,7 +326,7 @@

眈眈探求 | + 2023-10-23 22:15:00 Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS v.9.2.1 allow an attacker to execute arbitrary code via a crafted script to the Header and Footer Tracking Codes of the SEO & Statistics. 详情 @@ -334,7 +334,7 @@

眈眈探求 | + 2023-10-23 22:15:00 Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title parameter in the News Menu component. 详情 @@ -342,7 +342,7 @@

眈眈探求 | + 2023-10-23 21:15:00 umputun remark42 version 1.12.1 and before has a Blind Server-Side Request Forgery (SSRF) vulnerability. 详情 @@ -350,7 +350,7 @@

眈眈探求 | + 2023-10-23 21:15:00 A stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Message field when creating a ticket. 详情 @@ -358,7 +358,7 @@

眈眈探求 | + 2023-10-23 21:15:00 UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to gain access to the application. 详情 @@ -366,7 +366,7 @@

眈眈探求 | + 2023-10-23 01:15:00 A vulnerability was found in Viessmann Vitogate 300 up to 2.1.3.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /cgi-bin/. The manipulation leads to direct request. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243140. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. 详情 @@ -374,7 +374,7 @@

眈眈探求 | + 2023-10-23 01:15:00 A vulnerability has been found in vnotex vnote up to 3.17.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Markdown File Handler. The manipulation with the input Click here leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-243139. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. 详情 @@ -382,7 +382,7 @@

眈眈探求 | + 2023-10-23 01:15:00 pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may compute a shared secret via an uncompressed public key that has not been validated. An attacker can send arbitrary SUCIs to the UDM, which tries to decrypt them via both its private key and the attacker's public key. 详情 @@ -390,7 +390,7 @@

眈眈探求 | + 2023-10-23 00:15:00 A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. Affected is an unknown function of the file /protocol/iscgwtunnel/uploadiscgwrouteconf.php. The manipulation of the argument GWLinkId leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-243138 is the identifier assigned to this vulnerability. 详情 @@ -398,7 +398,7 @@

眈眈探求 | + 2023-10-23 00:15:00 A vulnerability, which was classified as problematic, has been found in CodeAstro Internet Banking System 1.0. This issue affects some unknown processing of the file pages_view_client.php. The manipulation of the argument acc_name with the input Johnnie Reyes'"()&% leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-243137 was assigned to this vulnerability. 详情 @@ -406,7 +406,7 @@

眈眈探求 | + 2023-10-23 00:15:00 A vulnerability classified as problematic was found in CodeAstro Internet Banking System 1.0. This vulnerability affects unknown code of the file pages_deposit_money.php. The manipulation of the argument account_number with the input 421873905-->alert(9523)alert(1234)