Aggregator
CVE-2014-7785 | onesolutionapps AAAA Discount Bail 1.1 X.509 Certificate cryptographic issues (VU#582497)
1 year 8 months ago
A vulnerability has been found in onesolutionapps AAAA Discount Bail 1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is known as CVE-2014-7785. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
AI-Generated Personas: Trust and Deception
1 year 8 months ago
And the Ethical Dilemma of Using AI to Create Fake Online Personalities In recent years, advancements in artificial intelligence (AI) have given rise to powerful tools like StyleGAN and sophisticated language models such as ChatGPT. These technologies can create hyper-realistic images and conversations, blurring the line between authentic human presence and synthetic creations. While this […]
The post AI-Generated Personas: Trust and Deception appeared first on Security Boulevard.
David Michael Berry
Cicada3301
1 year 8 months ago
cohenido
CVE-2024-24751 | derhansen sf_event_mgt Extension up to 7.3.x on TYPO3 Backend Module RedirectResponse access control (GHSA-4576-pgh2-g34j)
1 year 8 months ago
A vulnerability was found in derhansen sf_event_mgt Extension up to 7.3.x on TYPO3. It has been rated as critical. This issue affects the function RedirectResponse of the component Backend Module. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2024-24751. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-21255 | Oracle PeopleSoft Enterprise PeopleTools 8.59/8.60/8.61 XMLPublisher Privilege Escalation
1 year 8 months ago
A vulnerability, which was classified as very critical, was found in Oracle PeopleSoft Enterprise PeopleTools 8.59/8.60/8.61. Affected is an unknown function of the component XMLPublisher. The manipulation leads to Privilege Escalation.
This vulnerability is traded as CVE-2024-21255. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-21214 | Oracle PeopleSoft Enterprise PeopleTools 8.59/8.60/8.61 Query improper authorization
1 year 8 months ago
A vulnerability was found in Oracle PeopleSoft Enterprise PeopleTools 8.59/8.60/8.61 and classified as critical. Affected by this issue is some unknown functionality of the component Query. The manipulation leads to improper authorization.
This vulnerability is handled as CVE-2024-21214. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-21252 | Oracle Product Hub up to 12.2.13 Item Catalog improper authorization
1 year 8 months ago
A vulnerability, which was classified as critical, was found in Oracle Product Hub up to 12.2.13. Affected is an unknown function of the component Item Catalog. The manipulation leads to improper authorization.
This vulnerability is traded as CVE-2024-21252. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-21284 | Oracle Banking Liquidity Management 14.5.0.12.0 Oracle Financial Service authorization
1 year 8 months ago
A vulnerability has been found in Oracle Banking Liquidity Management 14.5.0.12.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Oracle Financial Service. The manipulation leads to incorrect authorization.
This vulnerability is known as CVE-2024-21284. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-21285 | Oracle Banking Liquidity Management 14.5.0.12.0 Oracle Financial Service authorization
1 year 8 months ago
A vulnerability was found in Oracle Banking Liquidity Management 14.5.0.12.0 and classified as critical. Affected by this issue is some unknown functionality of the component Oracle Financial Service. The manipulation leads to incorrect authorization.
This vulnerability is handled as CVE-2024-21285. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45072 | IBM WebSphere Application Server 8.5/9.0 xml external entity reference
1 year 8 months ago
A vulnerability classified as problematic has been found in IBM WebSphere Application Server 8.5/9.0. Affected is an unknown function. The manipulation leads to xml external entity reference.
This vulnerability is traded as CVE-2024-45072. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-21216 | Oracle WebLogic Server 12.2.1.4.0/14.1.1.0.0 Core improper authentication (Nessus ID 209238)
1 year 8 months ago
A vulnerability was found in Oracle WebLogic Server 12.2.1.4.0/14.1.1.0.0. It has been classified as very critical. Affected is an unknown function of the component Core. The manipulation leads to improper authentication.
This vulnerability is traded as CVE-2024-21216. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47967 | Solidigm D7-P5510/D7-P5520/D7-P5620/D7-P5500/D7-P5600 denial of service
1 year 8 months ago
A vulnerability was found in Solidigm D7-P5510, D7-P5520, D7-P5620, D7-P5500 and D7-P5600. It has been classified as problematic. This affects an unknown part. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2024-47967. The attack needs to be approached locally. There is no exploit available.
vuldb.com
ESET partner breached to send data wipers to Israeli orgs
1 year 8 months ago
Hackers breached ESET's exclusive partner in Israel to send phishing emails to Israeli businesses that pushed data wipers disguised as antivirus software for destructive attacks. [...]
Lawrence Abrams
美国保险巨头遭数据勒索攻击,或影响大量客户个人信息
1 year 8 months ago
事件有可能波及数百万人
美国海军发布新版“网络防御指挥”系统
1 year 8 months ago
美国海军网络安全项目办公室升级网络安全风险与合规工具
CVE-2022-3552 | boxbilling prior 0.0.1 unrestricted upload (EDB-51108)
1 year 8 months ago
A vulnerability was found in boxbilling and classified as critical. This issue affects some unknown processing. The manipulation leads to unrestricted upload.
The identification of this vulnerability is CVE-2022-3552. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-43988 | nature fitness saijo mini-app on Line 13.6.1 Channel Access Token information disclosure
1 year 8 months ago
A vulnerability has been found in nature fitness saijo mini-app on Line 13.6.1 and classified as problematic. This vulnerability affects unknown code of the component Channel Access Token Handler. The manipulation leads to information disclosure.
This vulnerability was named CVE-2023-43988. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2023-43999 | COLORFUL_laundry mini-app on Line 13.6.1 Channel Access Token information disclosure
1 year 8 months ago
A vulnerability was found in COLORFUL_laundry mini-app on Line 13.6.1. It has been declared as problematic. This vulnerability affects unknown code of the component Channel Access Token Handler. The manipulation leads to information disclosure.
This vulnerability was named CVE-2023-43999. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2024-22301 | Ignazio Scimone Albo Pretorio On line Plugin up to 4.6.6 on WordPress information disclosure
1 year 8 months ago
A vulnerability classified as problematic has been found in Ignazio Scimone Albo Pretorio On line Plugin up to 4.6.6 on WordPress. This affects an unknown part. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-22301. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com