Aggregator
CVE-2024-5020 | Colibri Page Builder Plugin on WordPress FancyBox JavaScript Library cross site scripting
CVE-2024-5020 | Easy Social Feed Premium Plugin on WordPress FancyBox JavaScript Library cross site scripting
CVE-2024-5020 | Accordion Slider Plugin on WordPress FancyBox JavaScript Library cross site scripting
CVE-2024-11880 | B Testimonial Plugin up to 1.2.2 on WordPress cross site scripting
CVE-2024-8962 | WPBITS Addons for Elementor Page Builder Plugin up to 1.5.2 on WordPress SVG File Upload cross site scripting
MobSF XSS Vulnerability Let Attackers Inject Malicious Scripts
A critical vulnerability has been identified in the Mobile Security Framework (MobSF) that allows attackers to inject malicious scripts into the system. This vulnerability, CVE-2024-53999 is a Stored Cross-Site Scripting (XSS) flaw found in the “Diff or Compare” functionality, which occurs due to improper handling of file uploads with script-laden filenames. Details of the Vulnerability […]
The post MobSF XSS Vulnerability Let Attackers Inject Malicious Scripts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2024-11935 | Email Address Obfuscation Plugin up to 1.0.1 on WordPress class cross site scripting
CVE-2024-11903 | WP eCards Plugin up to 1.3.904 on WordPress cross site scripting
CVE-2024-10664 | Knowledge Base Documentation & Wiki Plugin up to 2.16.3.3 on WordPress Database authorization
CVE-2024-11466 | Intro Tour Tutorial DeepPresentation Plugin up to 6.5.2 on WordPress cross site scripting
美国公司大幅裁减中层经理职位
CVE-2024-11769 | Florist One Flower Delivery Plugin up to 3.9 on WordPress cross site scripting
Are We Too Trusting of Employees?
Trust is not a one-way street. Employees who trust their organization and leadership are one lane, but the organization must trust its employees, too.
The post Are We Too Trusting of Employees? appeared first on Security Boulevard.
The ASA flaw CVE-2014-2120 is being actively exploited in the wild
CVE-2024-11643 | AllAccessible Accessibility Plugin up to 1.3.4 on WordPress Option Update authorization
CVE-2023-6978 | WP Job Manager Plugin up to 1.7 on WordPress cross site scripting
CVE-2024-11814 | Additional Custom Order Status for WooCommerce Plugin cross site scripting
CVE-2024-10567 | TI WooCommerce Wishlist Plugin up to 2.9.1 on WordPress Setup Wizard Access authorization
Weekly Threat Landscape Digest – Week 49
This week’s cybersecurity digest delves into critical vulnerabilities and emerging threat actor activities, underscoring the urgent need for proactive security […]
The post Weekly Threat Landscape Digest – Week 49 appeared first on HawkEye.