diff --git a/cache/Nsfocus.dat b/cache/Nsfocus.dat index b4133e0dedf..4dffe140b85 100644 --- a/cache/Nsfocus.dat +++ b/cache/Nsfocus.dat @@ -183,3 +183,18 @@ a411c09690f1a56dff2cbf5aca21e797 4aea955d28f30a949004f9f48d8adc42 b9dacb737c72e84158a9c294368fe136 06b4aff5242044ae6ebe9ee464deb6e5 +4966eb50a7c846062b18eb1e4877f31d +a6e8ba54d8dbef2511d8d459042ad7b2 +c37e8b915ab8ee03cc5495b378e228bb +28eb3488e46e36efbc142411917579f3 +7865d4286f550caf1e3a287ce3879ae3 +9b623ede881c65bef4edfa12e4870ca3 +2a0a8bdde1cd011539e0bba5b083cbf3 +d0be807b26c0a61f0e6fa9d73710345f +2c0f7e527ea9a5728ef849a0126ab45d +a7f41892d47022c54fab3cb133702a1b +0fd3ed8800df57cb07201d5917090cc3 +c2d329a503c795b2eceffe89ec4edd86 +532507aeb8417881067388b69c3f97b1 +67017ab6186c29742e3228da558c6e1d +f5b7be577083816725890411fe2c6f35 diff --git a/cache/Tenable (Nessus).dat b/cache/Tenable (Nessus).dat index fdfacdc28c7..3359d1be340 100644 --- a/cache/Tenable (Nessus).dat +++ b/cache/Tenable (Nessus).dat @@ -132,3 +132,13 @@ ee94cf7abb232ed99350034788151977 e2a755f5a3a595adb4e85c7c12280582 03252ee2471f5d9ee58a9196c2d3ae4a b775d126999b5d05a986aae5119eb5fc +79aaa806fe78dcebac32d2a0db19285a +1098c3773de625453ac861b71734adfd +282d490803a650a727631a46ee7eedf0 +a589c02909bc7c835ec122d7bbe63780 +cd4f4a0f570da509010fae209cbb1092 +5429864f1736816d8b56055dbf71a3f2 +d701099b8259413de8fbd24544e20ae3 +e1301cab30338f72830ce1113966111a +21c87cd561d7f8e03e2363e3d8cccb6e +91d2bf707499754a12bf01c96ac98441 diff --git a/data/cves.db b/data/cves.db index 518d8c6e345..39a9aea27d7 100644 Binary files a/data/cves.db and b/data/cves.db differ diff --git a/docs/index.html b/docs/index.html index 6dedbde0967..9113eed3fbe 100644 --- a/docs/index.html +++ b/docs/index.html @@ -1,4 +1,4 @@ - + @@ -283,6 +283,86 @@

眈眈探求 | TITLE URL + + 79aaa806fe78dcebac32d2a0db19285a + CVE-2024-9322 + 2024-09-29 03:15:02 + A vulnerability was found in code-projects Supply Chain Management 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/edit_manufacturer.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. + 详情 + + + + 1098c3773de625453ac861b71734adfd + CVE-2024-9321 + 2024-09-29 01:15:10 + A vulnerability was found in SourceCodester Online Railway Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/inquiries/view_details.php. The manipulation of the argument id leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. + 详情 + + + + 282d490803a650a727631a46ee7eedf0 + CVE-2024-9320 + 2024-09-29 00:15:03 + A vulnerability has been found in SourceCodester Online Timesheet App 1.0 and classified as problematic. This vulnerability affects unknown code of the file /endpoint/add-timesheet.php of the component Add Timesheet Form. The manipulation of the argument day/task leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. + 详情 + + + + a589c02909bc7c835ec122d7bbe63780 + CVE-2024-9319 + 2024-09-29 00:15:02 + A vulnerability, which was classified as critical, was found in SourceCodester Online Timesheet App 1.0. This affects an unknown part of the file /endpoint/delete-timesheet.php. The manipulation of the argument timesheet leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. + 详情 + + + + cd4f4a0f570da509010fae209cbb1092 + CVE-2024-9318 + 2024-09-28 23:15:13 + A vulnerability, which was classified as critical, has been found in SourceCodester Advocate Office Management System 1.0. Affected by this issue is some unknown functionality of the file /control/activate.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. + 详情 + + + + 5429864f1736816d8b56055dbf71a3f2 + CVE-2024-9317 + 2024-09-28 21:15:10 + A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. Affected by this vulnerability is the function delete_category of the file /classes/Master.php?f=delete_category. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. + 详情 + + + + d701099b8259413de8fbd24544e20ae3 + CVE-2024-9316 + 2024-09-28 20:15:02 + A vulnerability classified as critical has been found in code-projects Blood Bank Management System 1.0. Affected is an unknown function of the file /admin/blood/update/B+.php. The manipulation of the argument Bloodname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. + 详情 + + + + e1301cab30338f72830ce1113966111a + CVE-2024-9315 + 2024-09-28 19:15:12 + A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/maintenance/manage_department.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. + 详情 + + + + 21c87cd561d7f8e03e2363e3d8cccb6e + CVE-2024-9300 + 2024-09-28 15:15:14 + A vulnerability classified as problematic was found in SourceCodester Online Railway Reservation System 1.0. This vulnerability affects unknown code of the file contact_us.php of the component Message Us Form. The manipulation of the argument fullname/email/message leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. + 详情 + + + + 91d2bf707499754a12bf01c96ac98441 + CVE-2024-9299 + 2024-09-28 14:15:02 + A vulnerability classified as problematic has been found in SourceCodester Online Railway Reservation System 1.0. This affects an unknown part of the file /?page=reserve. The manipulation of the argument First Name/Middle Name/Last Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. + 详情 + + 65e677fd6168fe910ce5c0404b034658 CVE-2024-8715 @@ -334,7 +414,7 @@

眈眈探求 | + 2024-09-27 22:15:13 A vulnerability, which was classified as critical, has been found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. Affected by this issue is some unknown functionality of the file saveNewPwd.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. 详情 @@ -342,7 +422,7 @@

眈眈探求 | + 2024-09-27 22:15:13 EDK2 contains a vulnerability in the PeCoffLoaderRelocateImage(). An Attacker may cause memory corruption due to an overflow via an adjacent network. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability. 详情 @@ -350,7 +430,7 @@

眈眈探求 | + 2024-09-27 22:15:12 HCL Nomad is susceptible to an insufficient session expiration vulnerability. Under certain circumstances, an unauthenticated attacker could obtain old session information. 详情 @@ -358,7 +438,7 @@

眈眈探求 | + 2024-09-27 21:15:03 A vulnerability classified as critical was found in skyselang yylAdmin up to 3.0. Affected by this vulnerability is the function list of the file /app/admin/controller/file/File.php of the component Backend. The manipulation of the argument is_disable leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. 详情 @@ -366,7 +446,7 @@

眈眈探求 | + 2024-09-27 03:15:02 Sharp NEC Projectors (NP-CB4500UL, NP-CB4500WL, NP-CB4700UL, NP-P525UL, NP-P525UL+, NP-P525ULG, NP-P525ULJL, NP-P525WL, NP-P525WL+, NP-P525WLG, NP-P525WLJL, NP-CG6500UL, NP-CG6500WL, NP-CG6700UL, NP-P605UL, NP-P605UL+, NP-P605ULG, NP-P605ULJL, NP-CA4120X, NP-CA4160W, NP-CA4160X, NP-CA4200U, NP-CA4200W, NP-CA4202W, NP-CA4260X, NP-CA4300X, NP-CA4355X, NP-CD2100U, NP-CD2120X, NP-CD2300X, NP-CR2100X, NP-CR2170W, NP-CR2170X, NP-CR2200U, NP-CR2200W, NP-CR2280X, NP-CR2310X, NP-CR2350X, NP-MC302XG, NP-MC332WG, NP-MC332WJL, NP-MC342XG, NP-MC372X, NP-MC372XG, NP-MC382W, NP-MC382WG, NP-MC422XG, NP-ME342UG, NP-ME372W, NP-ME372WG, NP-ME372WJL, NP-ME382U, NP-ME382UG, NP-ME382UJL, NP-ME402X, NP-ME402XG, NP-ME402XJL, NP-CB4500XL, NP-CG6400UL, NP-CG6400WL, NP-CG6500XL, NP-PE455UL, NP-PE455ULG, NP-PE455WL, NP-PE455WLG, NP-PE505XLG, NP-CB4600U, NP-CF6600U, NP-P474U, NP-P554U, NP-P554U+, NP-P554UG, NP-P554UJL, NP-CG6600UL, NP-P547UL, NP-P547ULG, NP-P547ULJL, NP-P607UL+, NP-P627UL, NP-P627UL+, NP-P627ULG, NP-P627ULJL, NP-PV710UL-B, NP-PV710UL-B1, NP-PV710UL-W, NP-PV710UL-W+, NP-PV710UL-W1, NP-PV730UL-BJL, NP-PV730UL-WJL, NP-PV800UL-B, NP-PV800UL-B+, NP-PV800UL-B1, NP-PV800UL-BJL, NP-PV800UL-W, NP-PV800UL-W+, NP-PV800UL-W1, NP-PV800UL-WJL, NP-CA4200X, NP-CA4265X, NP-CA4300U, NP-CA4300W, NP-CA4305X, NP-CA4400X, NP-CD2125X, NP-CD2200W, NP-CD2300U, NP-CD2310X, NP-CR2105X, NP-CR2200X, NP-CR2205W, NP-CR2300U, NP-CR2300W, NP-CR2315X, NP-CR2400X, NP-MC333XG, NP-MC363XG, NP-MC393WJL, NP-MC423W, NP-MC423WG, NP-MC453X, NP-MC453X, NP-MC453XG, NP-MC453XJL, NP-ME383WG, NP-ME403U, NP-ME403UG, NP-ME403UJL, NP-ME423W, NP-ME423WG, NP-ME423WJL, NP-ME453X, NP-ME453XG, NP-CB4400USL, NP-CB4400WSL, NP-CB4510UL, NP-CB4510WL, NP-CB4510XL, NP-CB4550USL, NP-CB6700UL, NP-CG6510UL, NP-PE456USL, NP-PE456USLG, NP-PE456USLJL, NP-PE456WSLG, NP-PE506UL, NP-PE506ULG, NP-PE506ULJL, NP-PE506WL, NP-PE506WLG, NP-PE506WLJL) allows an attacker to cause a denial-of-service (DoS) condition via SNMP service. 详情 @@ -443,86 +523,6 @@

眈眈探求 | 详情 - - 9b86bf105d42fefbd759e5b2698a72b5 - CVE-2024-7781 - 2024-09-26 05:15:12 - The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.7.5. This is due to improper authentication via the Social Login widget. This makes it possible for unauthenticated attackers to log in as the first user to have logged in with a social media account, including administrator accounts. Attackers can exploit the vulnerability even if the Social Login element has been disabled, as long as it was previously enabled and used. The vulnerability was partially patched in version 4.7.5, and fully patched in version 4.7.8. - 详情 - - - - 6875d3bdfe5bb1ac331afacfaa8a2518 - CVE-2024-7772 - 2024-09-26 05:15:12 - The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file uploads due to a mishandled file type validation in the 'validate' function in all versions up to, and including, 4.6.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. - 详情 - - - - b656d22e6fe4af76692760c3eed82920 - CVE-2024-45836 - 2024-09-26 05:15:12 - Cross-site scripting vulnerability exists in the web management page of PLANEX COMMUNICATIONS network cameras. If a logged-in user accesses a specific file, an arbitrary script may be executed on the web browser of the user. - 详情 - - - - 93da909fddaa5e3e25c9ada243fd7183 - CVE-2024-45372 - 2024-09-26 05:15:12 - MZK-DP300N firmware versions 1.04 and earlier contains a cross-site request forger vulnerability. Viewing a malicious page while logging in to the web management page of the affected product may lead the user to perform unintended operations such as changing the login password, etc. - 详情 - - - - 4d63aa657dc702eded55c67245ad16e3 - CVE-2024-47045 - 2024-09-26 04:15:07 - User interface (UI) misrepresentation of critical information issue exists in multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION. If this vulnerability is exploited, an attacker who identified WAN-side IPv6 address may access the product's Device Setting page via WAN-side. Note that, affects products are also provided by NIPPON TELEGRAPH AND TELEPHONE WEST CORPORATION, but the vulnerability only affects products subscribed and used in NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION areas. - 详情 - - - - b6a82d25410f1e429cd76556eb7792e7 - CVE-2023-52950 - 2024-09-26 04:15:06 - Missing encryption of sensitive data vulnerability in login component in Synology Active Backup for Business Agent before 2.7.0-3221 allows adjacent man-in-the-middle attackers to obtain user credential via unspecified vectors. - 详情 - - - - 706c62e11f9af8583999354bb68d95be - CVE-2023-52949 - 2024-09-26 04:15:06 - Missing authentication for critical function vulnerability in proxy settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows local users to obtain user credential via unspecified vectors. - 详情 - - - - ad0456891122afde0cde5162a4f11325 - CVE-2023-52948 - 2024-09-26 04:15:06 - Missing encryption of sensitive data vulnerability in settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows local users to obtain user credential via unspecified vectors. - 详情 - - - - 7ef143f98cb9eda14c112e31dc080d5d - CVE-2023-52947 - 2024-09-26 04:15:06 - Missing authentication for critical function vulnerability in logout functionality in Synology Active Backup for Business Agent before 2.6.3-3101 allows local users to logout the client via unspecified vectors. The backup functionality will continue to operate and will not be affected by the logout. - 详情 - - - - 1e7d5e4f96b1a90fb7d1a1af59045e9f - CVE-2023-52946 - 2024-09-26 04:15:05 - Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in vss service component in Synology Drive Client before 3.5.0-16084 allows remote attackers to overwrite trivial buffers and crash the client via unspecified vectors. - 详情 - - @@ -1979,10 +1979,130 @@

眈眈探求 | TITLE URL + + 4966eb50a7c846062b18eb1e4877f31d + CVE-2024-40502 + 2024-09-29 09:21:39 + Hospital Management System Project SQL注入漏洞 + 详情 + + + + a6e8ba54d8dbef2511d8d459042ad7b2 + CVE-2024-34329 + 2024-09-29 09:21:39 + Entrust Datacard XPS Card Printer Driver不安全权限漏洞 + 详情 + + + + c37e8b915ab8ee03cc5495b378e228bb + CVE-2024-6828 + 2024-09-29 09:21:39 + WordPress Redux Framework Plugin JSON文件上传漏洞 + 详情 + + + + 28eb3488e46e36efbc142411917579f3 + CVE-2024-6885 + 2024-09-29 09:21:39 + WordPress MaxiBlocks Plugin任意文件删除漏洞 + 详情 + + + + 7865d4286f550caf1e3a287ce3879ae3 + CVE-2024-1575 + 2024-09-29 09:21:39 + Zyxel WBE660S权限管理错误漏洞 + 详情 + + + + 9b623ede881c65bef4edfa12e4870ca3 + CVE-2024-6638 + 2024-09-29 09:21:39 + NI LabVIEW整数溢出漏洞 + 详情 + + + + 2a0a8bdde1cd011539e0bba5b083cbf3 + CVE-2024-6122 + 2024-09-29 09:21:39 + NI SystemLink Server默认权限错误漏洞 + 详情 + + + + d0be807b26c0a61f0e6fa9d73710345f + CVE-2024-41012 + 2024-09-29 09:21:39 + Linux Kernel内存错误引用漏洞 + 详情 + + + + 2c0f7e527ea9a5728ef849a0126ab45d + CVE-2024-41709 + 2024-09-29 09:21:39 + Backdrop CMS跨站脚本漏洞 + 详情 + + + + a7f41892d47022c54fab3cb133702a1b + CVE-2024-24507 + 2024-09-29 09:21:39 + Act-On跨站脚本漏洞 + 详情 + + + + 0fd3ed8800df57cb07201d5917090cc3 + CVE-2024-6791 + 2024-09-29 09:21:39 + NI VeriStand目录路径遍历漏洞 + 详情 + + + + c2d329a503c795b2eceffe89ec4edd86 + CVE-2024-38944 + 2024-09-29 09:21:39 + Q-Free MAXTIME Suite代码注入漏洞 + 详情 + + + + 532507aeb8417881067388b69c3f97b1 + CVE-2024-21552 + 2024-09-29 09:21:39 + SuperAGI代码注入漏洞 + 详情 + + + + 67017ab6186c29742e3228da558c6e1d + CVE-2024-32152 + 2024-09-29 09:21:39 + Ankitects Anki黑名单绕过漏洞 + 详情 + + + + f5b7be577083816725890411fe2c6f35 + CVE-2024-29073 + 2024-09-29 09:21:39 + Ankitects Anki任意脚本执行漏洞 + 详情 + + 4f8ca4bd2b4ad5239e714c74836f5bd8 CVE-2024-34952 - 2024-09-27 12:42:09 + 2024-09-27 12:42:09 TaurusXin ncmdump拒绝服务漏洞 详情 @@ -1990,7 +2110,7 @@

眈眈探求 | + 2024-09-27 12:42:09 Micro Focus ArcSight Enterprise Security Manager存储型跨站脚本漏洞 详情 @@ -1998,7 +2118,7 @@

眈眈探求 | + 2024-09-27 12:42:09 Mintplex Labs AnythingLLM输入验证错误漏洞 详情 @@ -2006,7 +2126,7 @@

眈眈探求 | + 2024-09-27 12:42:09 ZOHO ManageEngine PAM360权限错误漏洞 详情 @@ -2014,7 +2134,7 @@

眈眈探求 | + 2024-09-27 12:42:09 Fluent Bit服务器解析错误漏洞 详情 @@ -2022,7 +2142,7 @@

眈眈探求 | + 2024-09-27 12:42:09 ANUJ KUMAR Directory Management System跨站脚本漏洞 详情 @@ -2030,7 +2150,7 @@

眈眈探求 | + 2024-09-27 12:42:09 Anuj Kumar Directory Management System SQL注入漏洞 详情 @@ -2038,7 +2158,7 @@

眈眈探求 | + 2024-09-27 12:42:09 Lunary未授权的数据集删除漏洞 详情 @@ -2046,7 +2166,7 @@

眈眈探求 | + 2024-09-27 12:42:09 rems Electricity Consumption Monitoring Tool SQL注入漏洞 详情 @@ -2054,7 +2174,7 @@

眈眈探求 | + 2024-09-27 12:42:09 Carlo Montero Event Registration System跨站脚本漏洞 详情 @@ -2062,7 +2182,7 @@

眈眈探求 | + 2024-09-27 12:42:09 scrapy信息泄露漏洞 详情 @@ -2070,7 +2190,7 @@

眈眈探求 | + 2024-09-27 12:42:09 Carlo Montero Event Registration System跨站脚本漏洞 详情 @@ -2078,7 +2198,7 @@

眈眈探求 | + 2024-09-27 12:42:09 Event Registration System SQL注入漏洞 详情 @@ -2086,7 +2206,7 @@

眈眈探求 | + 2024-09-27 12:42:09 WordPress plugin All in One SEO存储型跨站脚本漏洞 详情 @@ -2094,131 +2214,11 @@

眈眈探求 | + 2024-09-27 12:42:09 ZOHO ManageEngine ADAudit Plus SQL注入漏洞 详情 - - 3fb444a02f17f3b31dfe0251beb67ba7 - CVE-2024-41600 - 2024-09-27 09:23:11 - lin-CMS Springboot不安全权限漏洞 - 详情 - - - - 6ef559d727d3603c3098f08be3f41da1 - CVE-2024-41597 - 2024-09-27 09:23:11 - ProcessWire跨站请求伪造漏洞 - 详情 - - - - 4a0d6cd584c0aeffcbc3c5b8fc756164 - CVE-2024-6281 - 2024-09-27 09:23:11 - parisneo/lollms路径遍历漏洞 - 详情 - - - - 46b0e3450075fd7ce7635ca12ce70855 - CVE-2024-39123 - 2024-09-27 09:23:11 - Calibre-Web跨站脚本漏洞 - 详情 - - - - 63b086bd8bfb0fe947c185f6a6e6ec54 - CVE-2024-41107 - 2024-09-27 09:23:11 - Apache CloudStack身份认证绕过漏洞 - 详情 - - - - 2fde53b0b7e735df0b42b44aa8e53c4a - CVE-2024-32007 - 2024-09-27 09:23:11 - Apache CXF JOSE code内存释放错误漏洞 - 详情 - - - - ed5bd05d20bf58c3a0107dd9cf427fa8 - CVE-2024-37066 - 2024-09-27 09:23:11 - Wyze V4 Pro firmware命令注入漏洞 - 详情 - - - - d16a9aa510e221d10f3b4fecfd1722bd - CVE-2024-39963 - 2024-09-27 09:23:11 - Tenda AX12和Tenda AX9远程命令执行漏洞 - 详情 - - - - 54bf2a5051bb55e673f01a796e41c690 - CVE-2024-40724 - 2024-09-27 09:23:11 - Assimp堆缓冲区溢出漏洞 - 详情 - - - - f1ffc467fb5fdd2e47367ee680ac20d8 - CVE-2024-0006 - 2024-09-27 09:23:11 - Yugabyte Platform信息泄露漏洞 - 详情 - - - - 15bbf939bf9390721cc12e07ef0abfe7 - CVE-2024-6908 - 2024-09-27 09:23:11 - Yugabyte Platform权限管理错误漏洞 - 详情 - - - - 499e9daf36dc2969b836e6220e1ff0ca - CVE-2024-24970 - 2024-09-27 09:23:11 - HP Application Enabling Software Driver权限管理错误漏洞 - 详情 - - - - 6f47ec0925abe2083a18dd1a7a2e4e5b - CVE-2024-6895 - 2024-09-27 09:23:11 - Yugabyte Platform信息泄露漏洞 - 详情 - - - - 2ffca39cab49103cd8a29104ff6062f6 - CVE-2024-39962 - 2024-09-27 09:23:11 - D-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router远程代码执行漏洞 - 详情 - - - - bffd6bdd56df27f8e1821c3ed3cff752 - CVE-2024-27489 - 2024-09-27 09:23:11 - WMCMS PHP外部变量修改漏洞 - 详情 - -