A vulnerability was found in Oracle Tape Library ACSLS 8.5. It has been rated as very critical. This issue affects some unknown processing of the component Application Server. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2019-2729. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A suspected Chinese threat actor targeted a large U.S. organization earlier this year as part of a four-month-long intrusion.
According to Broadcom-owned Symantec, the first evidence of the malicious activity was detected on April 11, 2024 and continued until August. However, the company doesn't rule out the possibility that the intrusion may have occurred earlier.
"The attackers moved laterally
Researchers have uncovered an arbitrary file read zero-day in the Mitel MiCollab collaboration platform, allowing attackers to access files on a server's filesystem. [...]
A vulnerability was found in AnyWhere Elementor Plugin up to 1.2.11 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Post Handler. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2024-10777. The attack may be launched remotely. There is no exploit available.
A vulnerability classified as problematic was found in Accounting for WooCommerce Plugin up to 1.6.6 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-11324. The attack can be initiated remotely. There is no exploit available.
A vulnerability, which was classified as problematic, was found in WIP WooCarousel Lite Plugin up to 1.1.6 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-11779. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability has been found in NewsMunch Plugin up to 1.0.35 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-10848. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in Simple Redirection Plugin up to 1.5 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2024-11341. The attack may be launched remotely. There is no exploit available.
A vulnerability classified as problematic was found in Contact Form Builder Plugin up to 4.10.4 on WordPress. Affected by this vulnerability is the function livesite-pay of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-10056. The attack can be launched remotely. There is no exploit available.