diff --git a/cache/Nsfocus.dat b/cache/Nsfocus.dat index cde00958fb4..41c3ac2443b 100644 --- a/cache/Nsfocus.dat +++ b/cache/Nsfocus.dat @@ -195,3 +195,18 @@ efa7cedfe038cc8c6402b98731c238f9 11021bc99038f9e526d37ad001f31830 876076e8d62fea3f9e585652cb471a43 ec2f0bb1825d1769151f6a2c997003ca +34c0f108f9a0bd5d671bf2d862b3764c +d383f195197fae1e5dcc11a9faefb4b7 +3abf721754e7fa225ae46815624276dc +31fbe034774abbb50354956a3faf34a9 +9fbd4d8be94c090b7579147b6f67d332 +794a419519eb5fa57d6fc4166245e17b +d8dc8e6c8051f481dcb62faea6c8c438 +0bf70b9667cba6814226f70fa4fcc6dc +b373b7de564f65905bcc69c56f7dbec3 +589ed5982e113983061435b8be93f3cd +79323f395d72f5161a7cbbcf97c7bf26 +694fd9a66ee9ecfda2f1c3d63672fb8b +c9ce8e1675bbe5a8d83c718fc916c85f +e9ff2f42cf312627a92b320ea2c679be +341c1c06b5b71ee9206962447877468e diff --git a/data/cves.db b/data/cves.db index ae92d7a774e..99d569184f4 100644 Binary files a/data/cves.db and b/data/cves.db differ diff --git a/docs/index.html b/docs/index.html index da0c15d8a8b..845f3db1ccf 100644 --- a/docs/index.html +++ b/docs/index.html @@ -1,4 +1,4 @@ - + @@ -366,7 +366,7 @@

眈眈探求 | + 2024-11-26 10:15:04 ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript. 详情 @@ -374,7 +374,7 @@

眈眈探求 | + 2024-11-26 10:15:04 The Parsi Date plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.1.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. 详情 @@ -382,7 +382,7 @@

眈眈探求 | + 2024-11-26 09:15:06 The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wcj_product_meta shortcode in all versions up to, and including, 7.2.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with ShopManager-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. 详情 @@ -390,7 +390,7 @@

眈眈探求 | + 2024-11-26 09:15:05 The Spotify Play Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's spotifyplaybutton shortcode in all versions up to, and including, 2.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. 详情 @@ -398,7 +398,7 @@

眈眈探求 | + 2024-11-26 09:15:05 The BNE Gallery Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' shortcode in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. 详情 @@ -406,7 +406,7 @@

眈眈探求 | + 2024-11-26 09:15:05 The Support SVG – Upload svg files in wordpress without hassle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. 详情 @@ -414,7 +414,7 @@

眈眈探求 | + 2024-11-26 09:15:05 An image with a version lower than the fuse version may potentially be booted lead to improper authentication. 详情 @@ -422,7 +422,7 @@

眈眈探求 | + 2024-11-26 09:15:04 Wrong configuration in Touch Pal application can collect user behavior data without awareness by the user. 详情 @@ -430,7 +430,7 @@

眈眈探求 | + 2024-11-26 09:15:04 A race condition exists in a driver potentially leading to a use-after-free condition. 详情 @@ -438,7 +438,7 @@

眈眈探求 | + 2024-11-26 09:15:04 In multiple functions that process 802.11 frames, out-of-bounds reads can occur due to insufficient validation. 详情 @@ -2019,6 +2019,126 @@

眈眈探求 | 详情 + + 34c0f108f9a0bd5d671bf2d862b3764c + CVE-2024-43242 + 2024-11-28 03:35:16 + WordPress插件Ultimate Membership Pro不可信数据反序列化漏洞 + 详情 + + + + d383f195197fae1e5dcc11a9faefb4b7 + CVE-2024-49616 + 2024-11-28 03:35:16 + WordPress plugin Rate Own Post SQL注入漏洞 + 详情 + + + + 3abf721754e7fa225ae46815624276dc + CVE-2024-43272 + 2024-11-28 03:35:16 + WordPress插件icegram未认证漏洞 + 详情 + + + + 31fbe034774abbb50354956a3faf34a9 + CVE-2024-7924 + 2024-11-28 03:35:16 + ZZCMS路径遍历漏洞 + 详情 + + + + 9fbd4d8be94c090b7579147b6f67d332 + + 2024-11-28 03:35:16 + WordPress插件Void Elementor Post Grid Addon for Elementor Page builder路径遍历漏洞(CVE-2 + 详情 + + + + 794a419519eb5fa57d6fc4166245e17b + CVE-2024-43280 + 2024-11-28 03:35:16 + WordPress插件Salon Booking System输入验证错误漏洞 + 详情 + + + + d8dc8e6c8051f481dcb62faea6c8c438 + CVE-2024-7949 + 2024-11-28 03:35:16 + SourceCodester Online Graduate Tracer System SQL注入漏洞 + 详情 + + + + 0bf70b9667cba6814226f70fa4fcc6dc + CVE-2022-1206 + 2024-11-28 03:35:16 + WordPress插件AdRotate Banner Manager任意文件上传漏洞 + 详情 + + + + b373b7de564f65905bcc69c56f7dbec3 + CVE-2024-5940 + 2024-11-28 03:35:16 + WordPress插件GiveWP未授权数据更改漏洞 + 详情 + + + + 589ed5982e113983061435b8be93f3cd + CVE-2024-5941 + 2024-11-28 03:35:16 + WordPress插件GiveWP未授权数据访问和删除漏洞 + 详情 + + + + 79323f395d72f5161a7cbbcf97c7bf26 + CVE-2024-5939 + 2024-11-28 03:35:16 + WordPress插件GiveWP未授权数据访问漏洞 + 详情 + + + + 694fd9a66ee9ecfda2f1c3d63672fb8b + CVE-2024-5932 + 2024-11-28 03:35:16 + WordPress插件GiveWP PHP对象注入漏洞 + 详情 + + + + c9ce8e1675bbe5a8d83c718fc916c85f + CVE-2024-7942 + 2024-11-28 03:35:16 + SourceCodester Leads Manager Tool跨站脚本漏洞 + 详情 + + + + e9ff2f42cf312627a92b320ea2c679be + CVE-2024-7927 + 2024-11-28 03:35:16 + ZZCMS 路径遍历漏洞 + 详情 + + + + 341c1c06b5b71ee9206962447877468e + CVE-2024-43326 + 2024-11-28 03:35:16 + WordPress插件Plugin Notes Plus未授权漏洞 + 详情 + + 6e359f1e29910e12097457982372b380 CVE-2024-45792 @@ -2107,126 +2227,6 @@

眈眈探求 | 详情 - - 98169601742c73a14d0da9b8826e93d1 - CVE-2024-40088 - 2024-11-27 03:35:03 - Vilo Mesh WiFi System目录遍历漏洞 - 详情 - - - - 54f35987d8927c409b18d6a2066987b5 - CVE-2024-40087 - 2024-11-27 03:35:03 - Vilo Mesh WiFi System访问控制错误漏洞 - 详情 - - - - a538437a8c076b60c2e538369c913566 - CVE-2024-7782 - 2024-11-27 03:35:03 - WordPress插件Contact Form by Bit Form任意文件删除漏洞 - 详情 - - - - 2c196a970c6d262dcdc0595a969551b1 - CVE-2024-40091 - 2024-11-27 03:35:03 - Vilo Mesh WiFi System信息泄露漏洞 - 详情 - - - - 0995e3725554f5ef9c2c12685a333249 - CVE-2024-7777 - 2024-11-27 03:35:03 - WordPress插件Contact Form by Bit Form任意文件读取和删除漏洞 - 详情 - - - - 46b44d37b489b3e6a1af23be0f6ac9d7 - CVE-2024-9677 - 2024-11-27 03:35:03 - Zyxel USG FLEX信息泄露漏洞 - 详情 - - - - f0947cfa9600689a6fffb0d0618e8caa - CVE-2024-41930 - 2024-11-26 09:24:59 - Media Fusion Teacher Performance Management System跨站脚本漏洞 - 详情 - - - - ea27d64ac6341fe0b61340500c40fc5a - CVE-2024-46256 - 2024-11-26 09:24:59 - NginxProxyManager命令注入漏洞 - 详情 - - - - 5fd87e8336ba8f99949ac2be34f28921 - CVE-2024-9202 - 2024-11-26 09:24:59 - Eclipse Dataspace Components授权错误漏洞 - 详情 - - - - 22624d98b994f512fb44febb30c7dc1b - CVE-2024-6436 - 2024-11-26 09:24:59 - Rockwell Automation Sequence Manager输入验证错误漏洞 - 详情 - - - - f379efb794d6e39a21c534144ac9dd57 - CVE-2024-45744 - 2024-11-26 09:24:59 - TopQuadrant TopBraid EDG信息泄露漏洞 - 详情 - - - - cb8686c0422d2287fc2fdecb557c201e - CVE-2024-25412 - 2024-11-26 09:24:59 - Flatpress跨站脚本漏洞 - 详情 - - - - bec2384e7b8281d935df749a25b4f514 - CVE-2024-25411 - 2024-11-26 09:24:59 - Flatpress跨站脚本漏洞 - 详情 - - - - 0b95e76773893a41d8d0a0731e225944 - CVE-2024-45745 - 2024-11-26 09:24:59 - TopQuadrant TopBraid EDG XML外部实体引用漏洞 - 详情 - - - - 0d51b1ed0575d30d0f38fd5bdac9a0e3 - CVE-2024-39433 - 2024-11-26 09:24:59 - Google Android越界写入漏洞 - 详情 - -