diff --git a/cache/Nsfocus.dat b/cache/Nsfocus.dat index f8dfd85f08f..47456ce853e 100644 --- a/cache/Nsfocus.dat +++ b/cache/Nsfocus.dat @@ -110,3 +110,18 @@ dbc0913696cafec13a47c2dee27cd8c2 58a8e6a03cc3086fb513c0bd4fe5f289 b3d7ea8a0b0204b196a0a464e66f73de 4d285100b27bd8f04b467bda616fa0ff +7814029b14f351fdde4330d8ccd01c24 +c18f77010460fa75a05e834d6ff8dd3d +945718d7b5462d88a6870eb6d5db0498 +a8a95473373cf1ae794ff5e7086880f0 +fd61514e58689180051990cae22c35d9 +0a23ff6171b29396f0cb71b9538947db +c9fbfe2950091bc2284dc48c34dff8e8 +f0e5e6d1e7d83e00a9fbe69d5c60dfca +d91440307dcccc509b9c7febb08006ad +da683e95470c336767715ac6f5680b2d +f68416098fba9ea10df4a975852eaa3f +c55178da0d071073d36ef2930ae7bff5 +15fd12608509466434284ab873b83488 +7d1b5152dc9b57973d531bf732a29fa5 +bae391c3fcd81f351570cecbee24eb6a diff --git a/data/cves.db b/data/cves.db index e83cfcea9be..94bc6bcb522 100644 Binary files a/data/cves.db and b/data/cves.db differ diff --git a/docs/index.html b/docs/index.html index 379ba74a306..523857a3c4b 100644 --- a/docs/index.html +++ b/docs/index.html @@ -1,4 +1,4 @@ - + @@ -366,7 +366,7 @@

眈眈探求 | + 2024-12-03 11:15:04 The Campaign Monitor Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.5.7. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. 详情 @@ -374,7 +374,7 @@

眈眈探求 | + 2024-12-03 10:15:05 Dell NetWorker Management Console, version(s) 19.11, contain(s) an Improper Verification of Cryptographic Signature vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Code execution. 详情 @@ -382,7 +382,7 @@

眈眈探求 | + 2024-12-03 10:15:05 Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate the S3 secrets of any other user. This is only possible if: * ozone.s3g.secret.http.enabled is set to true. The default value of this configuration is false. * The user configured in ozone.s3g.kerberos.principal is also configured in ozone.s3.administrators or ozone.administrators. Users are recommended to upgrade to Apache Ozone version 1.4.1 which disables the affected endpoint. 详情 @@ -390,7 +390,7 @@

眈眈探求 | + 2024-12-03 10:15:05 The Charity Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.2 via the 'nacharity_elementor_template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts created by Elementor that they should not have access to. 详情 @@ -398,7 +398,7 @@

眈眈探求 | + 2024-12-03 10:15:05 The WP Mailster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mst_subscribe' shortcode in all versions up to, and including, 1.8.17.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. 详情 @@ -406,7 +406,7 @@

眈眈探求 | + 2024-12-03 10:15:05 The AWeber Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.5.7. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. 详情 @@ -414,7 +414,7 @@

眈眈探求 | + 2024-12-03 09:15:05 The BMLT Tabbed Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bmlt_tabbed_map' shortcode in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. 详情 @@ -422,7 +422,7 @@

眈眈探求 | + 2024-12-03 09:15:04 The IdeaPush plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the idea_push_taxonomy_save_routine function in all versions up to, and including, 8.71. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete terms for the "boards" taxonomy. 详情 @@ -430,7 +430,7 @@

眈眈探求 | + 2024-12-03 08:15:06 The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swin-campaign' shortcode in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. 详情 @@ -438,7 +438,7 @@

眈眈探求 | + 2024-12-03 08:15:06 The jAlbum Bridge plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ar’ parameter in all versions up to, and including, 2.0.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. 详情 @@ -1987,6 +1987,126 @@

眈眈探求 | TITLE URL + + 7814029b14f351fdde4330d8ccd01c24 + CVE-2024-31835 + 2024-12-05 03:36:55 + FlatPress跨站脚本漏洞 + 详情 + + + + c18f77010460fa75a05e834d6ff8dd3d + CVE-2024-42514 + 2024-12-05 03:36:55 + Mitel MiContact Center Business信息泄露漏洞 + 详情 + + + + 945718d7b5462d88a6870eb6d5db0498 + CVE-2024-46079 + 2024-12-05 03:36:55 + Scriptcase跨站脚本漏洞 + 详情 + + + + a8a95473373cf1ae794ff5e7086880f0 + CVE-2024-45999 + 2024-12-05 03:36:55 + Peter Goodhall Cloudlog SQL注入漏洞 + 详情 + + + + fd61514e58689180051990cae22c35d9 + CVE-2024-9411 + 2024-12-05 03:36:55 + OFSoft OFCMS跨站脚本漏洞 + 详情 + + + + 0a23ff6171b29396f0cb71b9538947db + CVE-2024-9423 + 2024-12-05 03:36:55 + HP LaserJet Printers拒绝服务漏洞 + 详情 + + + + c9fbfe2950091bc2284dc48c34dff8e8 + CVE-2024-20515 + 2024-12-05 03:36:55 + Cisco Identity Services Engine信息泄露漏洞 + 详情 + + + + f0e5e6d1e7d83e00a9fbe69d5c60dfca + CVE-2024-20393 + 2024-12-05 03:36:55 + Cisco Small Business多款产品信息泄露漏洞 + 详情 + + + + d91440307dcccc509b9c7febb08006ad + CVE-2024-7315 + 2024-12-05 03:36:55 + WordPress plugin WPvivid信息泄露漏洞 + 详情 + + + + da683e95470c336767715ac6f5680b2d + CVE-2024-9333 + 2024-12-05 03:36:55 + M-Files Connector访问绕过漏洞 + 详情 + + + + f68416098fba9ea10df4a975852eaa3f + CVE-2024-8254 + 2024-12-05 03:36:55 + WordPress plugin Email Subscribers by Icegram Express代码注入漏洞 + 详情 + + + + c55178da0d071073d36ef2930ae7bff5 + CVE-2024-8800 + 2024-12-05 03:36:55 + WordPress plugin RabbitLoader反射型跨站脚本漏洞 + 详情 + + + + 15fd12608509466434284ab873b83488 + CVE-2024-8967 + 2024-12-05 03:36:55 + WordPress plugin PWA — easy way to Progressive Web App存储型跨站脚本漏洞 + 详情 + + + + 7d1b5152dc9b57973d531bf732a29fa5 + CVE-2024-9172 + 2024-12-05 03:36:55 + WordPress plugin Demo Importer Plus跨站脚本漏洞 + 详情 + + + + bae391c3fcd81f351570cecbee24eb6a + CVE-2024-9222 + 2024-12-05 03:36:55 + WordPress plugin Paid Membership Subscriptions跨站脚本漏洞 + 详情 + + a3be5a2e3da1785f58036036e6e8f402 CVE-2024-10543 @@ -2107,126 +2227,6 @@

眈眈探求 | 详情 - - 129a5f999f19b2c690c08769223302bf - CVE-2024-52020 - 2024-12-03 12:47:01 - NETGEAR R8500命令注入漏洞 - 详情 - - - - d4d3e0a2ebadbb45b8f2aa1f7c1a687a - CVE-2023-29120 - 2024-12-03 12:47:01 - Enel X Waybox操作系统命令注入漏洞 - 详情 - - - - 2e2d734e701b82e0a318a8d93b845311 - CVE-2024-49522 - 2024-12-03 12:47:01 - Adobe Substance 3D Painter越界写入漏洞 - 详情 - - - - f7ba5d97a716f43411f8a004436664cc - CVE-2024-51362 - 2024-12-03 12:47:01 - LSC Smart Connect Indoor IP Camera信息泄露漏洞 - 详情 - - - - 147fe9cb59e6f705f4f916c2b898a49e - CVE-2024-51023 - 2024-12-03 12:47:01 - D-Link DIR_823G命令注入漏洞 - 详情 - - - - 95706a76c7363b44c03a4923f566b359 - CVE-2024-51024 - 2024-12-03 12:47:01 - D-Link DIR_823G命令注入漏洞 - 详情 - - - - cd0d059ea80f2892d504665b7a893483 - CVE-2024-49377 - 2024-12-03 12:47:01 - OctoPrint跨站脚本漏洞 - 详情 - - - - 4b55fce5f5ca9d74dd0eac2978b312e8 - CVE-2024-49773 - 2024-12-03 12:47:01 - SuiteCRM SQL注入漏洞 - 详情 - - - - c5212850893fd7f7f2e3692e152a137f - CVE-2024-50335 - 2024-12-03 12:47:01 - SuiteCRM跨站脚本漏洞 - 详情 - - - - f798b76651f3ba259a71cd2395b9f0d1 - CVE-2024-0134 - 2024-12-03 12:47:01 - NVIDIA Container Toolkit和NVIDIA GPU Operator UNIX符号链接漏洞 - 详情 - - - - 2d2fe58155760ea2c1def184dc0b3b08 - CVE-2023-29118 - 2024-12-03 12:47:01 - Enel X Waybox SQL注入漏洞 - 详情 - - - - 3d27c7c3e6f1fe77e94147142f1c6308 - CVE-2023-29126 - 2024-12-03 12:47:01 - Enel X Waybox PHP类型欺骗漏洞 - 详情 - - - - 55ccb74233bf64196dfdaba80f38bfee - CVE-2024-51015 - 2024-12-03 12:47:01 - NETGEAR R7000P命令注入漏洞 - 详情 - - - - b833f17140d10529bd4a01ef15cae2f1 - CVE-2024-52023 - 2024-12-03 12:47:01 - NETGEAR多款产品堆栈溢出漏洞 - 详情 - - - - 56a21ab913beae9f6145e1aa21a2dc33 - CVE-2024-52029 - 2024-12-03 12:47:01 - NETGEAR R7000P堆栈溢出漏洞 - 详情 - -