Aggregator
News alert: Doppler fortifies ‘secrets management’ with Change Requests auditable approval feature
1 year 7 months ago
Security Boulevard
The Home of the Security Bloggers Network
CVE-2024-8352 | Social Web Suite Plugin up to 4.1.11 on WordPress path traversal
1 year 7 months ago
A vulnerability classified as critical was found in Social Web Suite Plugin up to 4.1.11 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to path traversal.
This vulnerability is known as CVE-2024-8352. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-47135 | Jtekt Electronics Kostac PLC Programming Software up to 1.6.14.0 KPP Project File Parser stack-based overflow
1 year 7 months ago
A vulnerability was found in Jtekt Electronics Kostac PLC Programming Software up to 1.6.14.0. It has been rated as critical. Affected by this issue is some unknown functionality of the component KPP Project File Parser. The manipulation leads to stack-based buffer overflow.
This vulnerability is handled as CVE-2024-47135. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-47136 | Jtekt Electronics Kostac PLC Programming Software up to 1.6.14.0 KPP Project File Parser out-of-bounds
1 year 7 months ago
A vulnerability classified as critical has been found in Jtekt Electronics Kostac PLC Programming Software up to 1.6.14.0. This affects an unknown part of the component KPP Project File Parser. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2024-47136. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-8159 | Faronics DeepFreeze 9.00.020.5760 IOCTL FarDisk.sys out-of-bounds
1 year 7 months ago
A vulnerability has been found in Faronics DeepFreeze 9.00.020.5760 and classified as problematic. This vulnerability affects unknown code in the library FarDisk.sys of the component IOCTL Handler. The manipulation leads to out-of-bounds read.
This vulnerability was named CVE-2024-8159. The attack needs to be approached locally. There is no exploit available.
vuldb.com
CVE-2024-42504 | HPE IceWall Federation Agent cross-site request forgery
1 year 7 months ago
A vulnerability was found in HPE IceWall Federation Agent, IceWall Gen11 Enterprise Edition and IceWall SSO Agent Option and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2024-42504. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9460 | Codezips Online Shopping Portal 1.0 index.php username sql injection
1 year 7 months ago
A vulnerability was found in Codezips Online Shopping Portal 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. The manipulation of the argument username leads to sql injection.
This vulnerability is traded as CVE-2024-9460. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-45871 | Bandisoft BandiView 7.05 sub_0x232bd8 denial of service
1 year 7 months ago
A vulnerability classified as problematic was found in Bandisoft BandiView 7.05. This vulnerability affects the function sub_0x232bd8. The manipulation leads to denial of service.
This vulnerability was named CVE-2024-45871. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2024-45872 | Bandisoft BandiView 7.05 sub_0x410d1d buffer overflow
1 year 7 months ago
A vulnerability, which was classified as critical, has been found in Bandisoft BandiView 7.05. This issue affects the function sub_0x410d1d. The manipulation leads to buffer overflow.
The identification of this vulnerability is CVE-2024-45872. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
【情报资料】美军围堵中国的行动之:行动路径
1 year 7 months ago
介绍美军2014年开始的围堵中国的“行动路径”系列联合军演。
Cicada3301
1 year 7 months ago
cohenido
CVE-2007-4737 | SpeedTech PHP Library stphpbutton.php STPHPLIB_DIR code injection (EDB-4358 / XFDB-36417)
1 year 7 months ago
A vulnerability has been found in SpeedTech PHP Library and classified as critical. This vulnerability affects unknown code in the library STPHPLIB_DIR of the file stphpbutton.php. The manipulation of the argument STPHPLIB_DIR leads to code injection.
This vulnerability was named CVE-2007-4737. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Akira
1 year 7 months ago
cohenido
Akira
1 year 7 months ago
cohenido
Kill
1 year 7 months ago
cohenido
Hunters
1 year 7 months ago
cohenido
CVE-2007-4737 | SpeedTech PHP Library stphpform.php STPHPLIB_DIR code injection (EDB-4358 / XFDB-36416)
1 year 7 months ago
A vulnerability has been found in SpeedTech PHP Library and classified as critical. This vulnerability affects unknown code of the file stphpform.php. The manipulation of the argument STPHPLIB_DIR leads to code injection.
This vulnerability was named CVE-2007-4737. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-44193 | Apple iTunes up to 12.12.2 on Windows Local Privilege Escalation (Nessus ID 207808)
1 year 7 months ago
A vulnerability was found in Apple iTunes up to 12.12.2 on Windows. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to Local Privilege Escalation.
This vulnerability is handled as CVE-2024-44193. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-23959 | Autel MaxiCharger AC Elite Business C50 BLE AppChargingControl stack-based overflow
1 year 7 months ago
A vulnerability, which was classified as critical, was found in Autel MaxiCharger AC Elite Business C50. This affects the function AppChargingControl of the component BLE. The manipulation leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2024-23959. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com