diff --git a/cache/Nsfocus.dat b/cache/Nsfocus.dat index 0214f59d37d..fecf285ff24 100644 --- a/cache/Nsfocus.dat +++ b/cache/Nsfocus.dat @@ -173,3 +173,18 @@ f1bb6f91fe982032614d7b20706997c0 c3a844b1306ebe28aa2b7bbeec40838f a72be3522d0fef307c7080ea431c833b 375dd2a503b238e3dfb3fd9caedda6f8 +72d285355e5aeba46c69b555aeffce2a +0aab5972ff1172b318d8d997faf9ea5a +ef33db2e3c05151f855828060ae66085 +686e789cc3d08921f9977d8e22708dc4 +f4485f9de9be0b6dd8e8175b82fea8fe +04b015dbeebd3d97c18b643d9bff216c +f48b0c44814a724c43d17b6629a5a9e8 +990425bb30e009e2edee36ea5dda506e +88a89bc301a7fc9574f1575877b473bf +05dec0c8c1c544949f7f6e965d25b2ba +b0f1c6c11886b20d670a89f3c2fc1fc1 +3838f2a9780c68320da276da28072387 +272ab5cd751ec4cf16466e7c2d8ef1d8 +8bd4ae41d32498bb5f36cc77aee710cd +29f04b5418ec88cb994a78e3d5523559 diff --git a/cache/RedQueen.dat b/cache/RedQueen.dat index 4307376f8d4..068af3a63ee 100644 --- a/cache/RedQueen.dat +++ b/cache/RedQueen.dat @@ -150,3 +150,7 @@ fc283269ab7a764b43cef8107420830b c790d644a78c6d64da55748b84c2f4ba 12ae7cd50e62ce911e7247b2380dc80a a95ab72502d8206a3fc1db3e578f1592 +c7e0c054351f524088af3afb4bab861e +e22b2879b6643fbd3aa90b813f018cb9 +1dcbbf0220f71c3455814c607426f1e3 +96f5e52f42c170f547f4037a8fc6490a diff --git a/data/cves.db b/data/cves.db index 710b0532474..81c36d401b2 100644 Binary files a/data/cves.db and b/data/cves.db differ diff --git a/docs/index.html b/docs/index.html index f7fae7f2414..0d41fc2421e 100644 --- a/docs/index.html +++ b/docs/index.html @@ -1,4 +1,4 @@ - + @@ -366,7 +366,7 @@

眈眈探求 | + 2024-07-02 11:15:11 A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /classes/Master.php?f=delete_category. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-270168. 详情 @@ -374,7 +374,7 @@

眈眈探求 | + 2024-07-02 11:15:11 A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Users.php?f=save. The manipulation of the argument img leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-270167. 详情 @@ -382,7 +382,7 @@

眈眈探求 | + 2024-07-02 11:15:11 A vulnerability has been found in Hitout Carsale 1.0 and classified as critical. This vulnerability affects unknown code of the file OrderController.java. The manipulation of the argument orderBy leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-270166 is the identifier assigned to this vulnerability. 详情 @@ -390,7 +390,7 @@

眈眈探求 | + 2024-07-02 11:15:10 The Post Meta Data Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$meta_key’ parameter in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. 详情 @@ -398,7 +398,7 @@

眈眈探求 | + 2024-07-02 11:15:10 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthenticated bypass to user registration in versions up to, and including, 4.2.6.8.1. This is due to missing checks in the 'check_validate_fields' function in the checkout. This makes it possible for unauthenticated attackers to register as the default role on the site, even if registration is disabled. 详情 @@ -406,7 +406,7 @@

眈眈探求 | + 2024-07-02 11:15:10 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized user registration due to a missing capability check on the 'register' function in all versions up to, and including, 4.2.6.8.1. This makes it possible for unauthenticated attackers to bypass disabled user registration to create a new account with the default role. 详情 @@ -414,7 +414,7 @@

眈眈探求 | + 2024-07-02 11:15:10 The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 3.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. 详情 @@ -422,7 +422,7 @@

眈眈探求 | + 2024-07-02 10:15:09 The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'embed-create-page' and 'embed-insert-pages' functions in all versions up to, and including, 3.2.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary posts and append arbitrary content to existing posts. 详情 @@ -430,7 +430,7 @@

眈眈探求 | + 2024-07-02 10:15:09 The Cost Calculator Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘textarea.description’ parameter in all versions up to, and including, 3.2.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. 详情 @@ -438,7 +438,7 @@

眈眈探求 | + 2024-07-02 10:15:08 Improper verification of intent by broadcast receiver vulnerability in GalaxyStore prior to version 4.5.81.0 allows local attackers to launch unexported activities of GalaxyStore. 详情 @@ -2100,123 +2100,123 @@

眈眈探求 | - WordPress plugin Shortcodes and extra features for Phlox theme存储型跨站脚本漏洞(CVE-2024 - 详情 + 72d285355e5aeba46c69b555aeffce2a + CVE-2024-3717 + 2024-07-03 03:22:41 + WordPress plugin Contact Form 7信息泄露漏洞 + 详情 - 5b89cf9fa9f2b3bb72bac7e1df45d99b - CVE-2024-3473 - 2024-07-02 09:20:25 - WordPress Plugin Header Footer Code Manager Pro反射型跨站脚本漏洞 - 详情 + 0aab5972ff1172b318d8d997faf9ea5a + CVE-2024-3724 + 2024-07-03 03:22:41 + WordPress plugin Happy Addons for Elementor存储型跨站脚本漏洞 + 详情 - bc1a29ca610c9c79e1036c3e72d8a38d - CVE-2024-3338 - 2024-07-02 09:20:25 - WordPress plugin Colibri Page Builder存储型跨站脚本漏洞 - 详情 + ef33db2e3c05151f855828060ae66085 + CVE-2024-3725 + 2024-07-03 03:22:41 + WordPress plugin Otter Blocks存储型跨站脚本漏洞 + 详情 - 017929cbb0237d0538db3bf2473757e1 - CVE-2024-3340 - 2024-07-02 09:20:25 - WordPress plugin Colibri Page Builder存储型跨站脚本漏洞 - 详情 + 686e789cc3d08921f9977d8e22708dc4 + CVE-2024-3728 + 2024-07-03 03:22:41 + WordPress plugin Essential Addons for Elementor存储型跨站脚本漏洞 + 详情 - a992dd9b9d7befb25aba7b1dcdfd6e69 - CVE-2024-3307 - 2024-07-02 09:20:25 - WordPress plugin HT Mega存储型跨站脚本漏洞 - 详情 + f4485f9de9be0b6dd8e8175b82fea8fe + CVE-2024-3729 + 2024-07-03 03:22:41 + WordPress plugin Frontend Admin by DynamiApps安全异处理错误漏洞 + 详情 - 50ae534999f8ec806f3e2a44e5652813 - CVE-2024-3308 - 2024-07-02 09:20:25 - WordPress plugin HT Mega存储型跨站脚本漏洞 - 详情 + 04b015dbeebd3d97c18b643d9bff216c + CVE-2024-3734 + 2024-07-03 03:22:41 + WordPress plugin FOX未授权任意函数执行漏洞 + 详情 - 124f3d02778b21fca0a13f1dfef369b1 - CVE-2024-3312 - 2024-07-02 09:20:25 - WordPress plugin Easy Custom Auto Excerpt信息泄露漏洞 - 详情 + f48b0c44814a724c43d17b6629a5a9e8 + CVE-2024-3743 + 2024-07-03 03:22:41 + WordPress plugin Elementor Addon Elements存储型跨站脚本漏洞 + 详情 - a52da995e3d93c73a70e703a654daf2f - CVE-2024-3337 - 2024-07-02 09:20:25 - WordPress plugin Colibri Page Builder存储型跨站脚本漏洞 - 详情 + 990425bb30e009e2edee36ea5dda506e + CVE-2024-3747 + 2024-07-03 03:22:41 + WordPress Plugin Blocksy存储型跨站脚本漏洞 + 详情 - 8dfe9bcf1d4f4f64a82fa78f2fab67a2 - CVE-2024-3233 - 2024-07-02 09:20:25 - WordPress plugin Ivory Search未授权数据修改漏洞 - 详情 + 88a89bc301a7fc9574f1575877b473bf + CVE-2024-3819 + 2024-07-03 03:22:41 + WordPress plugin Jeg Elementor Kit存储型跨站脚本漏洞 + 详情 - 4288c18dd157a24de3bd84b9517bdd80 - CVE-2024-3206 - 2024-07-02 09:20:25 - WordPress plugin Control Menu Visibility未授权访问漏洞 - 详情 + 05dec0c8c1c544949f7f6e965d25b2ba + CVE-2024-3849 + 2024-07-03 03:22:41 + WordPress plugin HoliThemes本地文件包含漏洞 + 详情 - c9b1dc7383fe1ad6719da60225a682ab - CVE-2024-3215 - 2024-07-02 09:20:25 - WordPress plugin Paid Memberships Pro跨站请求伪造漏洞 - 详情 + b0f1c6c11886b20d670a89f3c2fc1fc1 + CVE-2024-3870 + 2024-07-03 03:22:41 + WordPress plugin CFDB7信息泄露漏洞 + 详情 - 62537ef845085c6edaf17b7aea5c5f84 - CVE-2024-3161 - 2024-07-02 09:20:25 - WordPress plugin Jeg Elementor Kit存储型跨站脚本漏洞 - 详情 + 3838f2a9780c68320da276da28072387 + CVE-2024-3885 + 2024-07-03 03:22:41 + WordPress plugin Premium Addons for Elementor存储型跨站脚本漏洞 + 详情 - 2ad27fdc40028cea862a12bc16a2b56a - CVE-2024-3197 - 2024-07-02 09:20:25 - WordPress plugin Plus Addons for Elementor存储型跨站脚本漏洞 - 详情 + 272ab5cd751ec4cf16466e7c2d8ef1d8 + CVE-2024-3891 + 2024-07-03 03:22:41 + WordPress plugin Happy Addons for Elementor存储型跨站脚本漏洞 + 详情 - 624eddaf75d04f3d2ce8179bcbf14f2f - CVE-2024-3199 - 2024-07-02 09:20:25 - WordPress plugin Plus Addons for Elementor存储型跨站脚本漏洞 - 详情 + 8bd4ae41d32498bb5f36cc77aee710cd + CVE-2024-3895 + 2024-07-03 03:22:41 + WordPress plugin WP Datepicker未授权数据修改漏洞 + 详情 - abd48f5115d2618ecd598282aab0e997 - CVE-2024-3074 - 2024-07-02 09:20:25 - WordPress plugin Elementor ImageBox存储型跨站脚本漏洞 - 详情 + 29f04b5418ec88cb994a78e3d5523559 + CVE-2024-3897 + 2024-07-03 03:22:41 + WordPress plugin Popup Box未授权数据访问漏洞 + 详情