Aggregator
CVE-2024-1763 | Wp Social Login and Register Social Counter Plugin Status Update authorization
3 months ago
A vulnerability was found in Wp Social Login and Register Social Counter Plugin up to 3.0.0 on WordPress. It has been classified as problematic. Affected is an unknown function of the component Status Update Handler. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2024-1763. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2024-34799 | Repute Infosystems BookingPress Plugin up to 1.0.82 on WordPress authorization
3 months ago
A vulnerability has been found in Repute Infosystems BookingPress Plugin up to 1.0.82 on WordPress and classified as critical. This vulnerability affects unknown code. The manipulation leads to missing authorization.
This vulnerability was named CVE-2024-34799. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-47552 | Apache Seata up to 2.1.x deserialization
3 months ago
A vulnerability was found in Apache Seata up to 2.1.x and classified as problematic. This issue affects some unknown processing. The manipulation leads to deserialization.
The identification of this vulnerability is CVE-2024-47552. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-54016 | Apache Seata up to 2.2.0 Compression resource consumption
3 months ago
A vulnerability was found in Apache Seata up to 2.2.0. It has been classified as problematic. Affected is an unknown function of the component Compression Handler. The manipulation leads to resource consumption.
This vulnerability is traded as CVE-2024-54016. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-26787 | Linux Kernel up to 5.10.212/5.15.151/6.1.80/6.6.20/6.7.8 kernel/dma/debug.c mmci_cmd_irq memory corruption (Nessus ID 208000)
3 months ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 5.10.212/5.15.151/6.1.80/6.6.20/6.7.8. Affected by this issue is the function mmci_cmd_irq of the file kernel/dma/debug.c. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2024-26787. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Исчезающие аккаунты и убытки: владельцы интернет-магазинов попались в капкан на $14 млн
3 months ago
Сотрудничество с Nike и Disney оказалось ловушкой для тысяч предпринимателей.
AMI BMC 严重漏洞致使攻击者可远程绕过身份验证
3 months ago
安全客
Veeam与IBM发布备份和AIX系统高危漏洞补丁
3 months ago
Veeam和IBM发布补丁修复高危漏洞。攻击者可利用漏洞控制系统,用户需立即更新以防范威胁。
Уязвимость в PHP превратила тысячи серверов в теневые криптофермы
3 months ago
Злоумышленники блокируют брандмауэры для монополизации доступа к захваченным ресурсам.
MarsCode X 多维表格|用AI 开发多维表格插件(报名可领AI代码模板)
3 months ago
MarsCode X 多维表格|用AI 开发多维表格插件(报名可领AI代码模板)
3 months ago
【安全圈】研究人员利用AI“越狱”技术,成功创建Chrome信息窃取程序
3 months ago
关键词人工智能近日,一项名为“沉浸式世界”(Immersive World)的突破性技术引发了广泛关注。
【安全圈】331款恶意应用伪装上架,超6000万用户中招!钓鱼广告和全屏弹窗泛滥成灾
3 months ago
关键词恶意软件网络安全研究人员近日警告称,一场大规模的广告欺诈活动正在利用 Google Play 商店中发布
【安全圈】Bybit 遭遇高级多阶段攻击,细节曝光
3 months ago
关键词安全漏洞加密货币交易所 Bybit 发现其以太坊冷钱包存在未经授权的操作,导致重大安全漏洞。
【安全圈】刘某兜售情报投敌叛国,被判死刑!
3 months ago
关键词国家安全近日,国家安全机关成功侦破一起某科研单位工作人员私自拷贝、复制并向境外间谍情报机关出卖大量国家秘
谨防假冒的 GitHub “安全警报”让黑客劫持您的帐户登录凭据
3 months ago
安全客
FreeBuf 早报 | Linux 内核越界写入漏洞致权限提升;NAKIVO 备份漏洞存攻击风险
3 months ago
Linux内核存在近20年的严重漏洞(CVE-2025-0927),允许本地用户获取root权限,影响多版本系统。
Six Governments Likely Use Israeli Paragon Spyware to Hack IM Apps and Harvest Data
3 months ago
The governments of Australia, Canada, Cyprus, Denmark, Israel, and Singapore are likely customers of spyware developed by Israeli company Paragon Solutions, according to a new report from The Citizen Lab.
Paragon, founded in 2019 by Ehud Barak and Ehud Schneorson, is the maker of a surveillance tool called Graphite that's capable of harvesting sensitive data from instant messaging applications
The Hacker News
寻找“AI天才少年” 快来报名“天枢杯”青少年人工智能安全创新大赛
3 months ago
首届“天枢杯”青少年人工智能安全创新大赛3月20日正式启动报名。你是那个“AI天才少年”吗?欢迎报名参赛。