diff --git a/cache/Nsfocus.dat b/cache/Nsfocus.dat index 235ba0f72a6..8d7cf00cdf7 100644 --- a/cache/Nsfocus.dat +++ b/cache/Nsfocus.dat @@ -104,3 +104,18 @@ f1488d3145128c518d163a6eae1908bf 98e5c5192719dbe6fb3fd8a606732af2 34aead0457d88fd33fb4ecc3c5c81150 a6df55963881c415e0de115554e2a147 +4caf72939219beecaefafc91ff79bc79 +c183850852315c512046bfa23a9b7002 +e4e247b96df34336e7f9d19f1df0cec7 +5f513754175ef4e3d5c691356e9f5e05 +2e7a2eccd1409a182b6e4017d8f6d600 +6e749efa47ae8af4335ef488d7518f1d +f26251067afccc5d86f07e5989dd1392 +3336f2a6a9fd2bc8cec199ce7c9c6d4d +287a72fafda23ffab3029392f75209c6 +77371a608acde45ada53532c877bbf9e +5514a066511bf8e9ea62468e0f3b8e33 +40c8b4110446728842fb8f981f3cf853 +3c9eced695f9fb607698ddbaf8311f91 +1a33b07ff86dcbd9aa94986081035eb3 +6b097b0b2cb2cfd3e6959f7351c04d90 diff --git a/data/cves.db b/data/cves.db index a71bbf9510f..9961630fa73 100644 Binary files a/data/cves.db and b/data/cves.db differ diff --git a/docs/index.html b/docs/index.html index d073d77930c..6f76f228346 100644 --- a/docs/index.html +++ b/docs/index.html @@ -1,4 +1,4 @@ - + @@ -366,7 +366,7 @@

眈眈探求 | + 2024-03-19 19:15:06 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 6.5.5 and 7.0.0-alpha.29, calling an invalid Parse Server Cloud Function name or Cloud Job name crashes the server and may allow for code injection, internal store manipulation or remote code execution. The patch in versions 6.5.5 and 7.0.0-alpha.29 added string sanitation for Cloud Function name and Cloud Job name. As a workaround, sanitize the Cloud Function name and Cloud Job name before it reaches Parse Server. 详情 @@ -374,7 +374,7 @@

眈眈探求 | + 2024-03-19 19:15:06 Open Source Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the date parameter at /admin/reports/index.php. 详情 @@ -382,7 +382,7 @@

眈眈探求 | + 2024-03-19 17:15:12 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Easy GA4 ( Google Analytics 4 ) allows Stored XSS.This issue affects HT Easy GA4 ( Google Analytics 4 ): from n/a through 1.1.7. 详情 @@ -390,7 +390,7 @@

眈眈探求 | + 2024-03-19 17:15:12 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-1730. Reason: This candidate is a duplicate of CVE-2024-1730. Notes: All CVE users should reference CVE-2024-1730 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. 详情 @@ -398,7 +398,7 @@

眈眈探求 | + 2024-03-19 17:15:12 Franklin Fueling System EVO 550 and EVO 5000 are vulnerable to a Path Traversal vulnerability that could allow an attacker to access sensitive files on the system. 详情 @@ -406,7 +406,7 @@

眈眈探求 | + 2024-03-19 17:15:12 A flaw was found in osbuild-composer. A condition can be triggered that disables GPG verification for package repositories, which can expose the build phase to a Man-in-the-Middle attack, allowing untrusted code to be installed into an image being built. 详情 @@ -414,7 +414,7 @@

眈眈探求 | + 2024-03-19 17:15:11 Cross-Site Request Forgery (CSRF) vulnerability in Tobias Conrad Builder for WooCommerce reviews shortcodes – ReviewShort.This issue affects Builder for WooCommerce reviews shortcodes – ReviewShort: from n/a through 1.01.3. 详情 @@ -422,7 +422,7 @@

眈眈探求 | + 2024-03-19 17:15:11 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maciej Bis Permalink Manager Lite allows Reflected XSS.This issue affects Permalink Manager Lite: from n/a through 2.4.3. 详情 @@ -430,7 +430,7 @@

眈眈探求 | + 2024-03-19 17:15:11 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dnesscarkey WP Armour – Honeypot Anti Spam allows Reflected XSS.This issue affects WP Armour – Honeypot Anti Spam: from n/a through 2.1.13. 详情 @@ -438,7 +438,7 @@

眈眈探求 | + 2024-03-19 17:15:10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Five Star Plugins Five Star Restaurant Menu allows Stored XSS.This issue affects Five Star Restaurant Menu: from n/a through 2.4.14. 详情 @@ -1971,6 +1971,126 @@

眈眈探求 | TITLE URL + + 4caf72939219beecaefafc91ff79bc79 + CVE-2023-41288 + 2024-03-21 03:22:26 + QNAP Systems Video Station操作系统命令注入漏洞 + 详情 + + + + c183850852315c512046bfa23a9b7002 + CVE-2023-41289 + 2024-03-21 03:22:26 + QNAP Systems QcalAgent操作系统命令注入漏洞 + 详情 + + + + e4e247b96df34336e7f9d19f1df0cec7 + CVE-2024-1411 + 2024-03-21 03:22:26 + WordPress Plugin PowerPack Addons for Elementor存储型跨站脚本漏洞 + 详情 + + + + 5f513754175ef4e3d5c691356e9f5e05 + CVE-2024-1425 + 2024-03-21 03:22:26 + WordPress Plugin EmbedPress存储型跨站脚本漏洞 + 详情 + + + + 2e7a2eccd1409a182b6e4017d8f6d600 + CVE-2023-47560 + 2024-03-21 03:22:26 + QNAP Systems QuMagie操作系统命令注入漏洞 + 详情 + + + + 6e749efa47ae8af4335ef488d7518f1d + CVE-2024-1445 + 2024-03-21 03:22:26 + WordPress Plugin Page scroll to id存储型跨站脚本漏洞 + 详情 + + + + f26251067afccc5d86f07e5989dd1392 + CVE-2024-21641 + 2024-03-21 03:22:26 + Flarum输入验证错误漏洞 + 详情 + + + + 3336f2a6a9fd2bc8cec199ce7c9c6d4d + CVE-2024-1586 + 2024-03-21 03:22:26 + WordPress The Schema & Structured Data for WP & AMP跨站脚本漏洞 + 详情 + + + + 287a72fafda23ffab3029392f75209c6 + CVE-2024-0247 + 2024-03-21 03:22:26 + CodeAstro Online Food Ordering System SQL注入漏洞 + 详情 + + + + 77371a608acde45ada53532c877bbf9e + CVE-2023-39296 + 2024-03-21 03:22:26 + QNAP Systems QTS QNAP Systems QuTS hero原型污染漏洞 + 详情 + + + + 5514a066511bf8e9ea62468e0f3b8e33 + CVE-2023-47559 + 2024-03-21 03:22:26 + QNAP Systems QuMagie跨站脚本漏洞 + 详情 + + + + 40c8b4110446728842fb8f981f3cf853 + CVE-2024-1928 + 2024-03-21 03:22:26 + SourceCodester Web-Based Student Clearance System SQL注入漏洞 + 详情 + + + + 3c9eced695f9fb607698ddbaf8311f91 + CVE-2023-47219 + 2024-03-21 03:22:26 + QNAP Systems QuMagie SQL注入漏洞 + 详情 + + + + 1a33b07ff86dcbd9aa94986081035eb3 + CVE-2023-45041 + 2024-03-21 03:22:26 + QNAP Systems QTS QNAP Systems QuTS hero缓冲区溢出漏洞 + 详情 + + + + 6b097b0b2cb2cfd3e6959f7351c04d90 + CVE-2024-1339 + 2024-03-21 03:22:26 + WordPress Plugin ImageRecycle pdf & image compression跨站请求伪造漏洞 + 详情 + + 98ba5df5ac53ce7c59dfd7bb28b38278 CVE-2023-5413 @@ -2091,126 +2211,6 @@

眈眈探求 | 详情 - - 5ce69dd3174e5a3a0e0342e212fdaa77 - CVE-2023-46131 - 2024-03-19 07:20:08 - Grails不受控制的资源消耗漏洞 - 详情 - - - - 3530fc9a09e620e6b33160d96d8a5ed1 - CVE-2023-49032 - 2024-03-19 07:20:08 - LDAP Tool Box Self Service Password任意代码执行漏洞 - 详情 - - - - 72abbc2cf8f1db408564add1cf9285d3 - CVE-2023-51390 - 2024-03-19 07:20:08 - journalpump访问控制错误漏洞 - 详情 - - - - 8810fc95262bf5466b41d8c8691e7dd7 - CVE-2023-6768 - 2024-03-19 07:20:08 - Amazing Little Poll身份认证绕过漏洞 - 详情 - - - - 790a3a2a2ab45f308085fec908f6c0ce - CVE-2023-6976 - 2024-03-19 07:20:08 - Mlflow任意文件写入漏洞 - 详情 - - - - 6666bf24cbf3001ec2541eab50ae6013 - CVE-2023-0011 - 2024-03-19 07:20:08 - u-blox TOBY-L2操作系统命令注入漏洞 - 详情 - - - - f7ca54586218980a3ab360a06eb12ad2 - CVE-2023-50628 - 2024-03-19 07:20:08 - libming缓冲区溢出漏洞 - 详情 - - - - a160ce114474a674a22e5ed9317fdd70 - CVE-2023-37544 - 2024-03-19 07:20:08 - Apache Pulsar身份认证错误漏洞 - 详情 - - - - 3b821c795726573468aad8e83efc689d - CVE-2023-6769 - 2024-03-19 07:20:08 - Amazing Little Poll跨站脚本漏洞 - 详情 - - - - cecff1a9d753fd63aa80ef06de85011e - CVE-2023-27172 - 2024-03-19 07:20:08 - Xpand IT Write-back Manager身份认证次数限制错误漏洞 - 详情 - - - - acc29703b4c7f516901155fef6708603 - CVE-2023-6974 - 2024-03-19 07:20:08 - Mlflow服务器端请求伪造漏洞 - 详情 - - - - 046f810ee7d34f8783c666d83a7670d9 - CVE-2023-6975 - 2024-03-19 07:20:08 - Mlflow路径遍历漏洞 - 详情 - - - - 095639ced36d0366b4b3c1d54e63db12 - CVE-2023-47704 - 2024-03-19 07:20:08 - IBM Security Guardium Key Lifecycle Manager硬编码凭据使用漏洞 - 详情 - - - - 34df67c7ff4cfffe4ab5d71235b73396 - CVE-2023-47702 - 2024-03-19 07:20:08 - IBM Security Guardium Key Lifecycle Manager路径遍历漏洞 - 详情 - - - - 6bd7854606a3229da2a17f094882d108 - CVE-2023-47705 - 2024-03-19 07:20:08 - IBM Security Guardium Key Lifecycle Manager输入验证错误漏洞 - 详情 - -