Aggregator
Medusa Blog
7 months 3 weeks ago
cohenido
Medusa Blog
7 months 3 weeks ago
cohenido
Medusa Blog
7 months 3 weeks ago
cohenido
CVE-2025-46417 | Picklescan up to 0.0.24 DNS ssl.get_server_certificate incomplete blacklist (GHSA-93mv-x874-956g)
7 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Picklescan up to 0.0.24. Affected by this issue is the function ssl.get_server_certificate of the component DNS Handler. The manipulation leads to incomplete blacklist.
This vulnerability is handled as CVE-2025-46417. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Хакеры спасают Microsoft от Microsoft — и получают миллионы
7 months 3 weeks ago
Первый Zero Day Quest собрал лучших специалистов и принёс более $1,6 млн наград.
CVE-2025-46419 | Westermo WeOS up to 5.23.x ESP Packet improper validation of syntactic correctness of input (87F4AD7F74C2BE69CA1B4C24F29B82EA)
7 months 3 weeks ago
A vulnerability classified as critical was found in Westermo WeOS up to 5.23.x. Affected by this vulnerability is an unknown functionality of the component ESP Packet Handler. The manipulation leads to improper validation of syntactic correctness of input.
This vulnerability is known as CVE-2025-46419. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-1976 | Brocade Fabric OS up to 9.1.1d6 code injection
7 months 3 weeks ago
A vulnerability classified as critical has been found in Brocade Fabric OS up to 9.1.1d6. Affected is an unknown function. The manipulation leads to code injection.
This vulnerability is traded as CVE-2025-1976. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-1453 | Category Posts Widget Plugin up to 4.9.19 on WordPress Setting cross site scripting
7 months 3 weeks ago
A vulnerability was found in Category Posts Widget Plugin up to 4.9.19 on WordPress. It has been rated as problematic. This issue affects some unknown processing of the component Setting Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-1453. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-2558 | the-wound Plugin up to 0.0.1 on WordPress file inclusion
7 months 3 weeks ago
A vulnerability was found in the-wound Plugin up to 0.0.1 on WordPress. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to file inclusion.
This vulnerability was named CVE-2025-2558. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-30059 | Microsoft Intune for Android Mobile Application Management on Android access control
7 months 3 weeks ago
A vulnerability was found in Microsoft Intune for Android Mobile Application Management on Android. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2024-30059. An attack has to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-30050 | Microsoft Windows up to Server 2022 23H2 Mark of the Web protection mechanism
7 months 3 weeks ago
A vulnerability classified as problematic was found in Microsoft Windows. Affected by this vulnerability is an unknown functionality of the component Mark of the Web. The manipulation leads to protection mechanism failure.
This vulnerability is known as CVE-2024-30050. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-26215 | Microsoft Windows Server 2008 R2 SP1 up to Server 2022 DHCP Server resource consumption
7 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Microsoft Windows. This issue affects some unknown processing of the component DHCP Server. The manipulation leads to resource consumption.
The identification of this vulnerability is CVE-2024-26215. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-26251 | Microsoft SharePoint Server 2016/2019/Subscription Edition cross site scripting
7 months 3 weeks ago
A vulnerability was found in Microsoft SharePoint Server 2016/2019/Subscription Edition. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-26251. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-26257 | Microsoft Office LTSC/365 Apps for Enterprise Excel double free
7 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Microsoft Office LTSC and 365 Apps for Enterprise. Affected is an unknown function of the component Excel. The manipulation leads to double free.
This vulnerability is traded as CVE-2024-26257. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-26193 | Microsoft Azure Migrate improper authorization
7 months 3 weeks ago
A vulnerability was found in Microsoft Azure Migrate. It has been classified as critical. This affects an unknown part. The manipulation leads to improper authorization.
This vulnerability is uniquely identified as CVE-2024-26193. The attack can only be done within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-26203 | Microsoft Azure Data Studio access control
7 months 3 weeks ago
A vulnerability was found in Microsoft Azure Data Studio. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2024-26203. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-25905 | Multi Step Form Plugin up to 1.7.17 on WordPress cross-site request forgery
7 months 3 weeks ago
A vulnerability was found in Multi Step Form Plugin up to 1.7.17 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2024-25905. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2023-50324 | IBM Cognos Command Center 10.2.4.1/10.2.5 Response Header X-AspNet-Version information disclosure (XFDB-275038)
7 months 3 weeks ago
A vulnerability was found in IBM Cognos Command Center 10.2.4.1/10.2.5. It has been declared as problematic. This vulnerability affects unknown code of the component Response Header Handler. The manipulation of the argument X-AspNet-Version leads to information disclosure.
This vulnerability was named CVE-2023-50324. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-3893 | Classified Listing Plugin up to 3.0.10.3 on WordPress Attachment authorization (ID 3073754)
7 months 3 weeks ago
A vulnerability was found in Classified Listing Plugin up to 3.0.10.3 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Attachment Handler. The manipulation leads to missing authorization.
This vulnerability is handled as CVE-2024-3893. The attack may be launched remotely. There is no exploit available.
vuldb.com