diff --git a/cache/Nsfocus.dat b/cache/Nsfocus.dat index b580ecedea7..3917ce96522 100644 --- a/cache/Nsfocus.dat +++ b/cache/Nsfocus.dat @@ -170,3 +170,18 @@ e4dfd75af7aa27a8263e59f021210a87 f6ea966c24667910442cefbf7abbfc79 46cc468b325d415d36c360f25f03d383 9a4f02331f6c89f6d0d1c9f712367bb1 +60227c3f245cc78eed3ac210a13411b2 +cae51761be3376ff8e5216b49f43318b +4b58c9c3e781bbafbc2ff5016f1641e6 +a08d89f54ec074798cc2f4f5fa7cd743 +0f248f11bfd6ae65ab997d518f9efa5b +9a279b81a53d062b3f7087174c2199fa +a63c40076c63b78c8b0ecc578e817b6d +a38ef66e3ed4cfbce8451481976ce220 +c892311da715a7167a2c3052f3069c3e +840d50139b84f3b0af4c08ceac6da948 +cff48a55ccb52162aaeaa5694f227732 +31246e985fe0dd02d50cf6be9eee49e8 +7cc7c7238920b7ea08fd9c457803e1b3 +06943f74aa039a7e5ecd1d5872490f9b +c623e8c569d648e6e2db769889dca363 diff --git a/data/cves.db b/data/cves.db index 45e3ea124cc..e2b13f60b87 100644 Binary files a/data/cves.db and b/data/cves.db differ diff --git a/docs/index.html b/docs/index.html index c2d7da83f27..34499e37135 100644 --- a/docs/index.html +++ b/docs/index.html @@ -1,4 +1,4 @@ - + @@ -366,7 +366,7 @@

眈眈探求 | + 2023-09-20 22:15:00 There is an unauthorized access vulnerability in TP-LINK ER5120G 4.0 2.0.0 Build 210817 Rel.80868n, which allows attackers to obtain sensitive information of the device without authentication, obtain user tokens, and ultimately log in to the device backend management. 详情 @@ -374,7 +374,7 @@

眈眈探求 | + 2023-09-20 22:15:00 SimpleImportProduct Prestashop Module v6.2.9 was discovered to contain a SQL injection vulnerability via the key parameter at send.php. 详情 @@ -382,7 +382,7 @@

眈眈探求 | + 2023-09-20 22:15:00 Faktory is a language-agnostic persistent background job server. Prior to version 1.8.0, the Faktory web dashboard can suffer from denial of service by a crafted malicious url query param `days`. The vulnerability is related to how the backend reads the `days` URL query parameter in the Faktory web dashboard. The value is used directly without any checks to create a string slice. If a very large value is provided, the backend server ends up using a significant amount of memory and causing it to crash. Version 1.8.0 fixes this issue. 详情 @@ -390,7 +390,7 @@

眈眈探求 | + 2023-09-20 22:15:00 Cross Site Scripting (XSS) vulnerability in Netbox 3.5.1, allows attackers to execute arbitrary code via Name field in device-roles/add function. 详情 @@ -398,7 +398,7 @@

眈眈探求 | + 2023-09-20 22:15:00 Buffer Overflow vulnerability in JerryScript version 3.0, allows remote attackers to execute arbitrary code via ecma_stringbuilder_append_raw component at /jerry-core/ecma/base/ecma-helpers-string.c. 详情 @@ -406,7 +406,7 @@

眈眈探求 | + 2023-09-20 22:15:00 SQL injection vulnerability in PrestaShop opartsavecart through 2.0.7 allows remote attackers to run arbitrary SQL commands via OpartSaveCartDefaultModuleFrontController::initContent() and OpartSaveCartDefaultModuleFrontController::displayAjaxSendCartByEmail() methods. 详情 @@ -414,7 +414,7 @@

眈眈探求 | + 2023-09-20 21:15:00 Insecure Permissions vulnerability in icmsdev iCMS v.7.0.16 allows a remote attacker to obtain sensitive information. 详情 @@ -422,7 +422,7 @@

眈眈探求 | + 2023-09-20 21:15:00 Cross Site Request Forgery (CSRF) vulnerability in icmsdev iCMSv.7.0.16 allows a remote attacker to execute arbitrary code via the user.admincp.php, members.admincp.php, and group.admincp.php files. 详情 @@ -430,7 +430,7 @@

眈眈探求 | + 2023-09-20 21:15:00 MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php. 详情 @@ -438,7 +438,7 @@

眈眈探求 | + 2023-09-20 21:15:00 A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'selector' parameter in '/reset-password'. 详情 @@ -446,7 +446,7 @@

眈眈探求 | + 2023-09-20 19:15:00 A cross-site scripting (XSS) vulnerability in /hoteldruid/visualizza_contratto.php of Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the destinatario_email1 parameter. 详情 @@ -454,7 +454,7 @@

眈眈探求 | + 2023-09-20 19:15:00 A cross-site scripting (XSS) vulnerability in /hoteldruid/clienti.php of Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the nometipotariffa1 parameter. 详情 @@ -462,7 +462,7 @@

眈眈探求 | + 2023-09-20 19:15:00 Hoteldruid v3.0.5 was discovered to contain multiple SQL injection vulnerabilities at /hoteldruid/clienti.php via the annonascita, annoscaddoc, giornonascita, giornoscaddoc, lingua_cli, mesenascita, and mesescaddoc parameters. 详情 @@ -470,7 +470,7 @@

眈眈探求 | + 2023-09-20 19:15:00 Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the id_utente_log parameter at /hoteldruid/personalizza.php. 详情 @@ -478,7 +478,7 @@

眈眈探求 | + 2023-09-20 19:15:00 Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/interconnessioni.php. 详情 @@ -486,7 +486,7 @@

眈眈探求 | + 2023-09-20 19:15:00 Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the numcaselle parameter at /hoteldruid/creaprezzi.php. 详情 @@ -494,7 +494,7 @@

眈眈探求 | + 2023-09-20 19:15:00 IBM Storage Protect 8.1.0.0 through 8.1.19.0 could allow a privileged user to obtain sensitive information from the administrative command line client. IBM X-Force ID: 263456. 详情 @@ -502,7 +502,7 @@

眈眈探求 | + 2023-09-20 19:15:00 An information leak in KUKURUDELI Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages. 详情 @@ -510,7 +510,7 @@

眈眈探求 | + 2023-09-20 18:15:00 phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data is directly passed to the PHP 'unserialize()' function in multiple places. An example is the functionality to manage tables in 'tables.php' where the 'ma[]' POST parameter is deserialized. 详情 @@ -518,7 +518,7 @@

眈眈探求 | + 2023-09-20 18:15:00 A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start versions 4, 5, 6, 7 as well as Visual Project Explorer 1.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'service' parameter in 'headstart_snapshot.php'. 详情 @@ -1798,7 +1798,7 @@

眈眈探求 | + 2023-09-20 20:12:31 GOLANG GO Vulnerability 详情 @@ -1806,7 +1806,7 @@

眈眈探求 | + 2023-09-20 20:12:30 GOLANG GO Vulnerability 详情 @@ -1814,7 +1814,7 @@

眈眈探求 | + 2023-09-20 20:12:30 Adobe ColdFusion 访问控制错误漏洞 详情 @@ -1822,7 +1822,7 @@

眈眈探求 | + 2023-09-20 20:12:24 GOOGLE ANDROID Vulnerability 详情 @@ -2092,123 +2092,123 @@

眈眈探求 | - XXL-JOB跨站请求伪造漏洞 - 详情 + 60227c3f245cc78eed3ac210a13411b2 + CVE-2023-4139 + 2023-09-21 03:20:53 + WordPress WP Ultimate CSV Importer plugin信息泄露漏洞 + 详情 - fd60a1b1a9a4746aae07da3316336263 - CVE-2020-24187 - 2023-09-21 03:20:36 - JerryScript空指针解引用漏洞 - 详情 + cae51761be3376ff8e5216b49f43318b + CVE-2023-4511 + 2023-09-21 03:20:53 + Wireshark无限循环漏洞 + 详情 - ab1d9f24a1865887807b33f484b29a3b - CVE-2023-37625 - 2023-09-21 03:20:36 - NetBox跨站脚本漏洞 - 详情 + 4b58c9c3e781bbafbc2ff5016f1641e6 + CVE-2023-36317 + 2023-09-21 03:20:53 + Student Study Center Desk Management System跨站脚本漏洞 + 详情 - 88863fe5f39e29b0b772833e7549b76d - CVE-2022-37051 - 2023-09-21 03:20:36 - Freedesktop Poppler拒绝服务漏洞 - 详情 + a08d89f54ec074798cc2f4f5fa7cd743 + CVE-2023-3671 + 2023-09-21 03:20:53 + WordPress MultiParcels Shipping For WooCommerce plugin跨站脚本漏洞 + 详情 - 516e3433662f2da512d3225e642d6413 - CVE-2021-26505 - 2023-09-21 03:20:36 - hello.js原型污染漏洞 - 详情 + 0f248f11bfd6ae65ab997d518f9efa5b + CVE-2023-2843 + 2023-09-21 03:20:53 + WordPress MultiParcels Shipping For WooCommerce plugin SQL注入漏洞 + 详情 - 41ae95844bcfad2779ab542030e7cd35 - CVE-2020-36136 - 2023-09-21 03:20:36 - CSZCMS SQL注入漏洞 - 详情 + 9a279b81a53d062b3f7087174c2199fa + CVE-2023-4180 + 2023-09-21 03:20:53 + Free Hospital Management System for Small Practices SQL注入漏洞 + 详情 - 264a82acb3338d2500c4f8675f8b81c9 - CVE-2022-29654 - 2023-09-21 03:20:36 - Nasm缓冲区溢出漏洞 - 详情 + a63c40076c63b78c8b0ecc578e817b6d + CVE-2023-39707 + 2023-09-21 03:20:53 + Inventory Management System跨站脚本漏洞 + 详情 - b7a21af49d49e8b4621576fdd1d26103 - CVE-2021-28429 - 2023-09-21 03:20:36 - FFmpeg整数溢出漏洞 - 详情 + a38ef66e3ed4cfbce8451481976ce220 + CVE-2023-40890 + 2023-09-21 03:20:53 + ZBar堆栈缓冲区溢出漏洞 + 详情 - 45b5665d5d669617e2ecca14b4207a6b - CVE-2023-3263 - 2023-09-21 03:20:36 - Dataprobe iBoot PDU身份验证绕过漏洞 - 详情 + c892311da715a7167a2c3052f3069c3e + CVE-2023-39437 + 2023-09-21 03:20:53 + SAP Business One跨站脚本漏洞 + 详情 - e311c7ecabaff0559c9cf9ccc8722523 - CVE-2023-40274 - 2023-09-21 03:20:36 - zola目录遍历漏洞 - 详情 + 840d50139b84f3b0af4c08ceac6da948 + CVE-2023-37569 + 2023-09-21 03:20:53 + ESDS Emagic Data Center Management Suit操作系统命令注入漏洞 + 详情 - 98fce2547da1cf66951a677e9e9b68d7 - CVE-2022-47011 - 2023-09-21 03:20:36 - GNU Binutils内存泄漏漏洞 - 详情 + cff48a55ccb52162aaeaa5694f227732 + CVE-2023-37683 + 2023-09-21 03:20:53 + PHPGurukul Online Nurse Hiring System跨站脚本漏洞 + 详情 - f9b44d1fc96c9b5d44096dabf40ee1d8 - CVE-2023-2803 - 2023-09-21 03:20:36 - WordPress Ultimate Addons for Contact Form 7 plugin跨站脚本漏洞 - 详情 + 31246e985fe0dd02d50cf6be9eee49e8 + CVE-2023-4556 + 2023-09-21 03:20:53 + Online Graduate Tracer System SQL注入漏洞 + 详情 - 787e0ec36cd63d7d97ac95f93c628d4c - CVE-2023-39292 - 2023-09-21 03:20:36 - Mitel MiVoice Office 400 SMB Controller SQL注入漏洞 - 详情 + 7cc7c7238920b7ea08fd9c457803e1b3 + CVE-2023-2174 + 2023-09-21 03:20:53 + WordPress BadgeOS plugin授权错误漏洞 + 详情 - 3c30cf1a904fd1699d6296285eaa5ff6 - CVE-2023-30188 - 2023-09-21 03:20:36 - Ascensio System ONLYOFFICE Document Server内存耗尽漏洞 - 详情 + 06943f74aa039a7e5ecd1d5872490f9b + CVE-2023-40582 + 2023-09-21 03:20:53 + find-exec命令注入漏洞 + 详情 - c4fcce5d197c8d3fc38b8b7d5ad49f3b - CVE-2023-38858 - 2023-09-21 03:20:36 - Faad2缓冲区溢出漏洞 - 详情 + c623e8c569d648e6e2db769889dca363 + CVE-2023-4209 + 2023-09-21 03:20:53 + WordPress POEditor plugin跨站请求伪造漏洞 + 详情 @@ -2230,7 +2230,7 @@

眈眈探求 | + 2023-09-20 03:15:14 The Widget Responsive for Youtube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube' shortcode in versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. 详情 @@ -2238,7 +2238,7 @@

眈眈探求 | + 2023-09-20 03:15:14 The WordPress Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wp_charts' shortcode in versions up to, and including, 0.7.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. 详情