Aggregator
Premium WordPress 'Motors' theme vulnerable to admin takeover attacks
15 hours 11 minutes ago
A critical privilege escalation vulnerability has been discovered in the premium WordPress theme Motors, which allows unauthenticated attackers to hijack administrator accounts and take complete control of websites. [...]
Bill Toulas
Kairos
15 hours 14 minutes ago
You must login to view this content
cohenido
Interlock
15 hours 16 minutes ago
You must login to view this content
cohenido
Неожиданное открытие: когда-то Юпитер был в два раза больше себя и был настоящим магнитным монстром
15 hours 19 minutes ago
Новые расчёты проливают свет на раннюю эволюцию и необычное прошлое газового гиганта.
CVE-2024-57439 | RuoYi 4.8.0 Reset Password Interface denial of service (EUVD-2025-0188)
15 hours 20 minutes ago
A vulnerability was found in RuoYi 4.8.0. It has been declared as problematic. This vulnerability affects unknown code of the component Reset Password Interface. The manipulation leads to denial of service.
This vulnerability was named CVE-2024-57439. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-57438 | RuoYi 4.8.0 improper authentication (EUVD-2025-0165)
15 hours 20 minutes ago
A vulnerability was found in RuoYi 4.8.0. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to improper authentication.
The identification of this vulnerability is CVE-2024-57438. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2025-24856 | causal oidc 3.x OpenID Connect Authentication authentication bypass (EUVD-2025-0169)
15 hours 20 minutes ago
A vulnerability was found in causal oidc 3.x. It has been classified as critical. Affected is an unknown function of the component OpenID Connect Authentication. The manipulation leads to authentication bypass using alternate channel.
This vulnerability is traded as CVE-2025-24856. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-55416 | DevDojo Voyager up to 1.8.0 /admin/compass cross site scripting (EUVD-2025-0180)
15 hours 20 minutes ago
A vulnerability classified as problematic has been found in DevDojo Voyager up to 1.8.0. Affected is an unknown function of the file /admin/compass. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-55416. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-56923 | Silverpeas Core 6.4.1 My Subscriptions Name cross site scripting (EUVD-2025-0142)
15 hours 20 minutes ago
A vulnerability, which was classified as problematic, has been found in Silverpeas Core 6.4.1. Affected by this issue is some unknown functionality of the component My Subscriptions. The manipulation of the argument Name leads to cross site scripting.
This vulnerability is handled as CVE-2024-56923. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-55227 | Dolibarr CRM 21.0.0-beta Events/Agenda Title cross site scripting (EUVD-2025-0121)
15 hours 20 minutes ago
A vulnerability was found in Dolibarr CRM 21.0.0-beta. It has been classified as problematic. This affects an unknown part of the component Events/Agenda. The manipulation of the argument Title leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-55227. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-24530 | phpMyAdmin up to 5.2.1 Check Tables cross site scripting (EUVD-2025-0114 / Nessus ID 231867)
15 hours 20 minutes ago
A vulnerability was found in phpMyAdmin up to 5.2.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Check Tables. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-24530. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-24337 | WriteFreely up to 0.15.1 config.ini information disclosure (EUVD-2025-0126 / Nessus ID 214906)
15 hours 20 minutes ago
A vulnerability, which was classified as problematic, has been found in WriteFreely up to 0.15.1. Affected by this issue is some unknown functionality of the file config.ini. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2025-24337. The attack needs to be approached locally. There is no exploit available.
vuldb.com
CVE-2019-0985 | Microsoft Windows 7 SP1/2008 R2 SP1 Speech API memory corruption (ID 91544)
15 hours 33 minutes ago
A vulnerability was found in Microsoft Windows 7 SP1/2008 R2 SP1. It has been rated as critical. This issue affects some unknown processing of the component Speech API. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2019-0985. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2019-0941 | Microsoft IIS Request Filter data processing (ID 91544)
15 hours 33 minutes ago
A vulnerability was found in Microsoft IIS. It has been declared as problematic. This vulnerability affects unknown code of the component Request Filter. The manipulation leads to data processing error.
This vulnerability was named CVE-2019-0941. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2019-0943 | Microsoft Windows up to Server 2019 ALPC access control (ID 91544)
15 hours 33 minutes ago
A vulnerability was found in Microsoft Windows. It has been rated as critical. This issue affects some unknown processing of the component ALPC. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2019-0943. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2019-0959 | Microsoft Windows up to Server 2019 Common Log File System Driver access control (ID 91544)
15 hours 33 minutes ago
A vulnerability classified as critical has been found in Microsoft Windows up to Server 2019. Affected is an unknown function of the component Common Log File System Driver. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2019-0959. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2019-0960 | Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 Win32k access control (ID 91544)
15 hours 33 minutes ago
A vulnerability classified as critical was found in Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2. Affected by this vulnerability is an unknown functionality of the component Win32k. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2019-0960. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2019-0968 | Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2 GDI information disclosure (ID 91544)
15 hours 33 minutes ago
A vulnerability, which was classified as problematic, has been found in Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2. Affected by this issue is some unknown functionality of the component GDI. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2019-0968. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2019-0972 | Microsoft Windows up to Server 2019 Local Security Authority Subsystem Service 7pk security (ID 91544)
15 hours 33 minutes ago
A vulnerability, which was classified as critical, was found in Microsoft Windows. This affects an unknown part of the component Local Security Authority Subsystem Service. The manipulation leads to 7pk security features.
This vulnerability is uniquely identified as CVE-2019-0972. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com