Aggregator
CVE-2024-23597 | TvRock 0.9t8a cross-site request forgery
CVE-2024-28775 | IBM WebSphere Automation 1.7.0 Web UI cross site scripting (XFDB-285648)
CVE-2024-31413 | OMRON CX-One Project File buffer overflow (OMSR-2024-002)
CVE-2024-28764 | IBM WebSphere Automation 1.7.0 csv injection (XFDB-285623)
CVE-2024-4036 | Sydney Toolbox Plugin up to 1.30 on WordPress cross site scripting
CVE-2024-4265 | Master Addons Plugin up to 2.0.5.9 on WordPress cross site scripting
CVE-2023-7241 | Webroot AntiVirus/Endpoint Protection prior 9.0.35.17 on Windows WRSA.EXE privileges management
Akira
xxl-job_2.4.1ssrf导致Rce漏洞代码分析(CVE-2024-24113)
CVE-2008-6631 | BlogPHP 2.0 index.php Username cross site scripting (EDB-31774 / XFDB-42370)
20,000 WordPress Sites at Risk of File Upload & Deletion Exploits
A critical security alert has been issued to WordPress site administrators following the discovery of two high-severity vulnerabilities in the “WP Ultimate CSV Importer” plugin. With over 20,000 active installations, the plugin’s flaws pose a significant risk to affected websites, potentially leading to complete site takeovers by attackers. CVE Identified: File Upload and Deletion Exploits […]
The post 20,000 WordPress Sites at Risk of File Upload & Deletion Exploits appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Prince Ransomware – An Automated Open-Source Ransomware Builder Freely Available on GitHub
The cybersecurity landscape has witnessed a concerning development with the emergence of “Prince Ransomware,” an open-source ransomware builder that was freely accessible on GitHub until recently. This tool, written in the Go programming language, has been exploited by cybercriminals to launch sophisticated ransomware attacks with minimal technical expertise. The recent attack on Mackay Memorial Hospital […]
The post Prince Ransomware – An Automated Open-Source Ransomware Builder Freely Available on GitHub appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
QR Code Phishing (Quishing) Attack Your Smartphones To Steal Microsoft Accounts Credentials
Cybersecurity researchers have identified a growing trend in phishing attacks leveraging QR codes, a tactic known as “quishing.” These attacks exploit the widespread use of smartphones to deceive users into exposing sensitive credentials, particularly targeting Microsoft accounts. According to recent findings, attackers are embedding malicious URLs within QR codes to bypass traditional security measures and […]
The post QR Code Phishing (Quishing) Attack Your Smartphones To Steal Microsoft Accounts Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.