重大な露出リスク
CVE-2021-3262 Trispark Novusedu SQL injection
- CVSS 9.8
新たな重大 Trispark Novusedu SQL injection(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。
日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。
最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。
重大な露出リスク
新たな重大 Trispark Novusedu SQL injection(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。
重大な露出リスク
新たな重大 Vmware Aria Operations For Networks Auth Bypass(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。
重大な露出リスク
新たな重大 Bladex Springblade SQL Injection(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。
CISA KEV — 実環境での悪用が確認
本ダイジェストではこのカテゴリに該当なし。
本ダイジェストではこのカテゴリに該当なし。
本ダイジェストではこのカテゴリに該当なし。
An issue found in Earcms Ear App v.20181124 allows a remote attacker to execute arbitrary code via the uload/index-uplog.php.
TripSpark VEO Transportation-2.2.x-XP_BB-20201123-184084 NovusEDU-2.2.x-XP_BB-20201123-184084 allows unsafe data inputs in POST body para...
Motorola MBTS Site Controller accepts hard-coded backdoor password.
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation.
In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to S...
A heap-based buffer overflow exists in the qr_reader_match_centers function of ZBar 0.23.90.
A stack-based buffer overflow vulnerability exists in the lookup_sequence function of ZBar 0.23.90.
Qlik Sense HTTP Tunneling
An issue was discovered in FRRouting FRR 9.0.
The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been u...