Aggregator
【安全圈】2024年第三季度勒索软件攻击事件回顾与趋势分析
10 months 2 weeks ago
CVE-2024-35294 | Schneider Elektronik Series 700 up to 0.1.17.6 missing authentication
10 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Schneider Elektronik Series 700 up to 0.1.17.6. Affected by this issue is some unknown functionality. The manipulation leads to missing authentication.
This vulnerability is handled as CVE-2024-35294. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-8885 | Sophos Intercept X prior 2024.3 on Windows Device Encryption unmaintained third party components
10 months 2 weeks ago
A vulnerability has been found in Sophos Intercept X on Windows and classified as problematic. This vulnerability affects unknown code of the component Device Encryption. The manipulation leads to use of unmaintained third party components.
This vulnerability was named CVE-2024-8885. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47611 | tukaani-project xz up to 5.6.2 argument injection
10 months 2 weeks ago
A vulnerability was found in tukaani-project xz up to 5.6.2 and classified as critical. This issue affects some unknown processing. The manipulation leads to argument injection.
The identification of this vulnerability is CVE-2024-47611. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-44097 | Google Android Server Certificate Parser certificate validation
10 months 2 weeks ago
A vulnerability was found in Google Android. It has been classified as problematic. Affected is an unknown function of the component Server Certificate Parser. The manipulation leads to improper certificate validation.
This vulnerability is traded as CVE-2024-44097. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-7855 | WP Hotel Booking Plugin up to 2.1.2 on WordPress unrestricted upload
10 months 2 weeks ago
A vulnerability classified as critical has been found in WP Hotel Booking Plugin up to 2.1.2 on WordPress. This affects an unknown part. The manipulation leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2024-7855. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-21530 | cocoon up to 0.3.x Encryption nonce re-use (ID 22)
10 months 2 weeks ago
A vulnerability was found in cocoon up to 0.3.x. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Encryption. The manipulation leads to reusing a nonce.
This vulnerability is known as CVE-2024-21530. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9174 | M-Files Hubshare 3.3.10.9/3.3.11.3/5.0.3.8/5.0.6.0 Social Module cross site scripting
10 months 2 weeks ago
A vulnerability classified as problematic was found in M-Files Hubshare 3.3.10.9/3.3.11.3/5.0.3.8/5.0.6.0. This vulnerability affects unknown code of the component Social Module. The manipulation leads to basic cross site scripting.
This vulnerability was named CVE-2024-9174. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9333 | M-Files Connector for Copilot up to 24.9.2 Access Control List permissions
10 months 2 weeks ago
A vulnerability, which was classified as critical, was found in M-Files Connector for Copilot up to 24.9.2. Affected is an unknown function of the component Access Control List Handler. The manipulation leads to preservation of permissions.
This vulnerability is traded as CVE-2024-9333. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-44030 | Mestres do WP Checkout Mestres WP Plugin up to 8.6 on WordPress path traversal
10 months 2 weeks ago
A vulnerability was found in Mestres do WP Checkout Mestres WP Plugin up to 8.6 on WordPress. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to path traversal.
This vulnerability was named CVE-2024-44030. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-35293 | Schneider Elektronik Series 700 up to 0.1.17.6 missing authentication
10 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Schneider Elektronik Series 700 up to 0.1.17.6. This affects an unknown part. The manipulation leads to missing authentication.
This vulnerability is uniquely identified as CVE-2024-35293. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-45186 | FileSender up to 2.48 Template injection
10 months 2 weeks ago
A vulnerability was found in FileSender up to 2.48. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Template Handler. The manipulation leads to injection.
This vulnerability is handled as CVE-2024-45186. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-24142 | SourceCodester School Task Manager 1.0 subject sql injection
10 months 2 weeks ago
A vulnerability was found in SourceCodester School Task Manager 1.0 and classified as critical. Affected by this issue is some unknown functionality. The manipulation of the argument subject leads to sql injection.
This vulnerability is handled as CVE-2024-24142. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-31294 | Fahad Mahmood WP Sort Order Plugin up to 1.3.1 on WordPress authorization
10 months 2 weeks ago
A vulnerability classified as problematic was found in Fahad Mahmood WP Sort Order Plugin up to 1.3.1 on WordPress. This vulnerability affects unknown code. The manipulation leads to missing authorization.
This vulnerability was named CVE-2024-31294. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2023-23640 | MainWP UpdraftPlus Extension Plugin up to 4.0.6 on WordPress authorization
10 months 2 weeks ago
A vulnerability was found in MainWP UpdraftPlus Extension Plugin up to 4.0.6 on WordPress. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to missing authorization.
The identification of this vulnerability is CVE-2023-23640. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-31246 | WPXPO PostX Plugin up to 3.2.3 on WordPress authorization
10 months 2 weeks ago
A vulnerability has been found in WPXPO PostX Plugin up to 3.2.3 on WordPress and classified as critical. This vulnerability affects unknown code. The manipulation leads to missing authorization.
This vulnerability was named CVE-2024-31246. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-41715 | goTenna Pro ATAK Plugin up to 1.9.12 Length observable response discrepancy (icsa-24-270-05)
10 months 2 weeks ago
A vulnerability classified as problematic was found in goTenna Pro ATAK Plugin up to 1.9.12. This vulnerability affects unknown code of the component Length Handler. The manipulation leads to observable response discrepancy.
This vulnerability was named CVE-2024-41715. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2024-8318 | Attributes for Blocks Plugin up to 1.0.6 on WordPress attributesForBlocks cross site scripting
10 months 2 weeks ago
A vulnerability was found in Attributes for Blocks Plugin up to 1.0.6 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation of the argument attributesForBlocks leads to cross site scripting.
The identification of this vulnerability is CVE-2024-8318. The attack may be initiated remotely. There is no exploit available.
vuldb.com
Is the Attack Group El Dorado Rebranding to BlackLock
10 months 2 weeks ago
cohenido