diff --git a/cache/Nsfocus.dat b/cache/Nsfocus.dat index e5d36f93638..5ab30e20583 100644 --- a/cache/Nsfocus.dat +++ b/cache/Nsfocus.dat @@ -108,3 +108,18 @@ dbd4c473777ec38bbee8ffc487a0b3d4 1938695484b752d95385a8074fe688f5 0cc5d2332f9f86c1646068ec78244a65 10bf73589aecf96421e80e8f3765ef9f +9ec813549ba3f618cdc08acbbe7fd27b +76c9d55611436289e0ca7cf480ac7e52 +17f7c839c2284c85451f432cc0466258 +ecd5408a500ba109a6d2682f5314a78e +a3dcac0e28c0a7ff3be67f4c04b566c1 +85fb67ab9749a5c359c70b6015971b14 +b3e930f070b12040a1fdaff8c906df42 +68641d1194284edf66fe39907a509721 +32dd8ae83bf5535bfa7420c20feef5dd +d6ab038604fd4f556e31d1222a09064c +58e8bf78583018912a54f496a4443053 +6b221298e17d642fe13bb1b56015372b +381b4edd5b4665d42a26b32a2adb84ac +79f502561fabb0fe2ceb41cb78da3cf7 +eeb7ad500cf01ce29d668962caebb99b diff --git a/data/cves.db b/data/cves.db index b060f080d36..460edff4048 100644 Binary files a/data/cves.db and b/data/cves.db differ diff --git a/docs/index.html b/docs/index.html index e6eecf8908b..8f6a7c6b557 100644 --- a/docs/index.html +++ b/docs/index.html @@ -1,4 +1,4 @@ - + @@ -286,7 +286,7 @@

眈眈探求 | + 2024-09-24 11:51:49 Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input validation, affecting the “id_form_msg_title” parameter, among others. This vulnerability could allow a remote user to send a specially crafted URL to a victim and retrieve their credentials. 详情 @@ -294,7 +294,7 @@

眈眈探求 | + 2024-09-24 11:50:58 Path traversal vulnerability in Scriptcase version 9.4.019, in /scriptcase/devel/compat/nm_edit_php_edit.php (in the “subpage” parameter), which allows unauthenticated remote users to bypass SecurityManager's intended restrictions and list and/or read a parent directory via a “/...” or directly into a path used in the POST parameter “field_file” by a web application. 详情 @@ -302,7 +302,7 @@

眈眈探求 | + 2024-09-24 11:48:36 Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ via a POST request. An attacker could upload malicious files to the server due to the application not properly verifying user input. 详情 @@ -310,7 +310,7 @@

眈眈探求 | + 2024-09-24 11:00:45 The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.2 via the Content Switcher widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including private, draft, and pending Elementor templates. 详情 @@ -318,7 +318,7 @@

眈眈探求 | + 2024-09-24 10:50:25 Cross-Site Scripting (XSS) vulnerability in the Oct8ne system. This flaw could allow an attacker to embed harmful JavaScript code into the body of a chat message. This manipulation occurs when the chat content is intercepted and altered, leading to the execution of the JavaScript payload. 详情 @@ -326,7 +326,7 @@

眈眈探求 | + 2024-09-24 10:24:43 IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registration and unregistration operations which could expose sensitive information to an attacker with access to the system. 详情 @@ -334,7 +334,7 @@

眈眈探求 | + 2024-09-24 08:47:05 External Control of File Name or Path, : Incorrect Permission Assignment for Critical Resource vulnerability in Olgu Computer Systems e-Belediye allows Manipulating Web Input to File System Calls.This issue affects e-Belediye: before 2.0.642. 详情 @@ -342,7 +342,7 @@

眈眈探求 | + 2024-09-24 07:30:46 The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_imageId' and 'edit_imageDelete' parameters in all versions up to, and including, 4.8.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. 详情 @@ -350,7 +350,7 @@

眈眈探求 | + 2024-09-24 07:30:45 The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions hooked via AJAX like wpeg_settings and wpeg_add_gallery in all versions up to, and including, 4.8.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify galleries. 详情 @@ -358,7 +358,7 @@

眈眈探求 | + 2024-09-24 07:30:45 The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API secrets stored in plaintext in the publicly visible plugin source. This can allow unauthenticated attackers to impersonate W3 Total Cache and gain access to user account information in successful conditions. This would not impact the WordPress users site in any way. 详情 @@ -1979,6 +1979,126 @@

眈眈探求 | TITLE URL + + 9ec813549ba3f618cdc08acbbe7fd27b + CVE-2024-31394 + 2024-09-26 03:27:10 + a-blog cms目录遍历漏洞 + 详情 + + + + 76c9d55611436289e0ca7cf480ac7e52 + CVE-2024-3518 + 2024-09-26 03:27:10 + WordPress Plugin Media Library AssistantSQL注入漏洞 + 详情 + + + + 17f7c839c2284c85451f432cc0466258 + CVE-2024-21683 + 2024-09-26 03:27:10 + Atlassian Confluence Data Center and Server远程代码执行漏洞 + 详情 + + + + ecd5408a500ba109a6d2682f5314a78e + CVE-2024-5040 + 2024-09-26 03:27:10 + LCDS LAquis SCADA路径遍历漏洞 + 详情 + + + + a3dcac0e28c0a7ff3be67f4c04b566c1 + CVE-2024-34274 + 2024-09-26 03:27:10 + OpenBD反序列化漏洞 + 详情 + + + + 85fb67ab9749a5c359c70b6015971b14 + CVE-2024-31756 + 2024-09-26 03:27:10 + MarvinTest Solutions Hardware Access Driver权限提升漏洞 + 详情 + + + + b3e930f070b12040a1fdaff8c906df42 + CVE-2024-35061 + 2024-09-26 03:27:10 + NASA AIT-Core远程代码执行漏洞 + 详情 + + + + 68641d1194284edf66fe39907a509721 + CVE-2024-35060 + 2024-09-26 03:27:10 + NASA AIT-Core任意命令执行漏洞 + 详情 + + + + 32dd8ae83bf5535bfa7420c20feef5dd + CVE-2024-3519 + 2024-09-26 03:27:10 + WordPress Plugin Media Library Assistant跨站脚本漏洞 + 详情 + + + + d6ab038604fd4f556e31d1222a09064c + CVE-2024-0453 + 2024-09-26 03:27:10 + WordPress plugin AI ChatBot未授权的数据修改漏洞 + 详情 + + + + 58e8bf78583018912a54f496a4443053 + CVE-2024-30420 + 2024-09-26 03:27:10 + a-blog cms服务器请求伪造漏洞 + 详情 + + + + 6b221298e17d642fe13bb1b56015372b + CVE-2024-33525 + 2024-09-26 03:27:10 + ILIAS存储型跨站脚本漏洞 + 详情 + + + + 381b4edd5b4665d42a26b32a2adb84ac + CVE-2024-31989 + 2024-09-26 03:27:10 + Argo CD算法加密漏洞 + 详情 + + + + 79f502561fabb0fe2ceb41cb78da3cf7 + CVE-2024-25724 + 2024-09-26 03:27:10 + RTI Connext Professional缓冲区溢出漏洞 + 详情 + + + + eeb7ad500cf01ce29d668962caebb99b + CVE-2024-4154 + 2024-09-26 03:27:10 + Lunary未授权的信息修改漏洞 + 详情 + + 048b41b4debc34d43a382716cc4931e1 CVE-2024-31979 @@ -2099,126 +2219,6 @@

眈眈探求 | 详情 - - d13c9d8372201885ca2d58405947956c - CVE-2024-21155 - 2024-09-24 12:43:15 - Oracle ZFS Storage Appliance Kit product信息泄露漏洞 - 详情 - - - - 00d56c1da98b3727cc1a45cba8ed270f - CVE-2024-21169 - 2024-09-24 12:43:15 - Oracle E-Business Suite信息泄露漏洞 - 详情 - - - - 37b4670b5039fe7ed364c15da32774a0 - CVE-2024-21168 - 2024-09-24 12:43:15 - Oracle JD Edwards信息泄露漏洞 - 详情 - - - - bcca318885734383c4e4021f4e0074c7 - CVE-2024-21158 - 2024-09-24 12:43:15 - Oracle PeopleSoft Enterprise PeopleTools信息泄露漏洞 - 详情 - - - - 861ac9dc64a16905eaaf9bc9cbd2cc84 - CVE-2024-6336 - 2024-09-24 12:43:15 - GitHub Enterprise Server配置错误漏洞 - 详情 - - - - b3d7e6b8f6542fbd5bcac3ec81358946 - CVE-2024-21153 - 2024-09-24 12:43:15 - Oracle E-Business Suite信息泄露漏洞 - 详情 - - - - c83f096aedee84264dece6b0d5056e0f - CVE-2024-21152 - 2024-09-24 12:43:15 - Oracle E-Business Suite信息泄露漏洞 - 详情 - - - - e663bf46007bf121b3bafdbe9970dc1e - CVE-2024-21188 - 2024-09-24 12:43:15 - Oracle Financial Services Applications授权错误漏洞 - 详情 - - - - 71fe7d10a2c71ac466f96d7cc0190fd3 - CVE-2024-3172 - 2024-09-24 12:43:15 - Google Chrome数据验证错误漏洞 - 详情 - - - - f97ce115a1164a0a99decf03519ac4f4 - CVE-2020-36765 - 2024-09-24 12:43:15 - Google Chrome策略实施不足漏洞 - 详情 - - - - 04f1d7d3068b4260c82a634d2ed69975 - CVE-2023-7012 - 2024-09-24 12:43:15 - Google Chrome数据验证错误漏洞 - 详情 - - - - b8a9a448cb211a1cccdc91ef8e96e4be - CVE-2024-21126 - 2024-09-24 12:43:15 - Oracle Database Server不受控制的资源消耗漏洞 - 详情 - - - - 263eafe142b767d88ceccecfb67235a1 - CVE-2024-21148 - 2024-09-24 12:43:15 - Oracle E-Business Suite信息泄露漏洞 - 详情 - - - - 0cd63f67f4f5db0084838e142d3e8805 - CVE-2024-21136 - 2024-09-24 12:43:15 - Oracle Retail Applications信息泄露漏洞 - 详情 - - - - 9d345ca82b6a9861a9f1528218904a85 - CVE-2024-6395 - 2024-09-24 12:43:15 - GitHub Enterprise Server信息泄露漏洞 - 详情 - -