Aggregator
CVE-2023-6941 | Keap Official Opt-in Forms Plugin up to 1.0.11 on WordPress Setting cross site scripting (EUVD-2023-59138)
CVE-2021-24151 | WP Editor Plugin up to 1.2.6 on WordPress Setting sql injection (EUVD-2021-11065)
CVE-2022-0402 | Super Forms Plugin up to 6.0.3 on WordPress AJAX Action bob_czy_panstwa_sprawa_zostala_rozwiazana cross site scripting (EUVD-2022-15547)
CVE-2022-3739 | WP Best Quiz Plugin up to 1.0 on WordPress cross site scripting (EUVD-2022-43095)
CVE-2022-1538 | Theme Demo Import Plugin up to 1.1.0 on WordPress Imported File unrestricted upload (EUVD-2022-24834)
CVE-2022-3829 | Font Awesome 4 Menus Plugin up to 4.7.0 on WordPress Setting cross site scripting (EUVD-2022-43169)
CVE-2022-3764 | Form Vibes Plugin prior 1.4.6 on WordPress delete_entries sql injection (EUVD-2022-43118)
CVE-2023-0479 | Print Invoice & Delivery Notes for WooCommerce Plugin cross site scripting (EUVD-2023-12531)
CVE-2023-0824 | UserPlus Plugin up to 2.0 on WordPress cross-site request forgery (EUVD-2023-12827)
Insomnia API Client Vulnerability Enables Arbitrary Code Execution via Template Injection
A severe security vulnerability in the Insomnia API Client, a widely used tool by developers and security testers for interacting with APIs, has been uncovered by researchers at an offensive security consultancy. Discovered by Technical Director Marcio Almeida and Head of Research Justin Steven, the flaw allows for arbitrary code execution through a mechanism known […]
The post Insomnia API Client Vulnerability Enables Arbitrary Code Execution via Template Injection appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2023-36558 | Microsoft ASP.NET/.NET/Visual Studio information disclosure (Nessus ID 239747)
CVE-2023-36049 | Microsoft .NET/.NET Framework/Visual Studio privilege escalation (Nessus ID 239747)
CVE-2024-28835 | GnuTLS up to 3.8.3 PEM Bundle Verification uncaught exception (RHSA-2024:1879 / EUVD-2024-25921)
CVE-2020-14145 | OpenSSH up to 8.3 Algorithm Negotiation information disclosure (Nessus ID 239762)
CVE-2023-29533 | Mozilla Firefox up to 111 Notification (Bug 1814597 / Nessus ID 239763)
CVE-2023-29533 | Mozilla Thunderbird up to 102.9 Notification (Bug 1814597 / Nessus ID 239763)
CVE-2025-43200 | Apple watchOS iCloud Link Remote Code Execution (EUVD-2025-18428 / Nessus ID 238308)
Threat Actors Exploit Vercel Hosting Platform to Distribute Remote Access Malware
CyberArmor has uncovered a sophisticated phishing campaign exploiting Vercel, a widely used frontend hosting platform, to distribute a malicious variant of LogMeIn, a legitimate remote access tool. Over the past two months, threat actors have orchestrated at least 28 distinct campaigns, targeting more than 1,271 users with deceptive emails that lead to fraudulent pages hosted […]
The post Threat Actors Exploit Vercel Hosting Platform to Distribute Remote Access Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.