Aggregator
CVE-2024-10453 | Elementor Website Builder Plugin up to 3.25.9 on WordPress Typography Setting cross site scripting
7 months 4 weeks ago
A vulnerability was found in Elementor Website Builder Plugin up to 3.25.9 on WordPress and classified as problematic. Affected by this issue is some unknown functionality of the component Typography Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-10453. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-11722 | DynamiApps Frontend Admin Plugin up to 3.25.1 on WordPress sql injection
7 months 4 weeks ago
A vulnerability has been found in DynamiApps Frontend Admin Plugin up to 3.25.1 on WordPress and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection.
This vulnerability is known as CVE-2024-11722. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-12875 | Easy Digital Downloads Plugin up to 3.3.2 on WordPress File information disclosure
7 months 4 weeks ago
A vulnerability, which was classified as problematic, was found in Easy Digital Downloads Plugin up to 3.3.2 on WordPress. Affected is an unknown function of the component File Handler. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-12875. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-11607 | GTPayment Donations Plugin up to 1.0.0 on WordPress cross-site request forgery
7 months 4 weeks ago
A vulnerability, which was classified as problematic, has been found in GTPayment Donations Plugin up to 1.0.0 on WordPress. This issue affects some unknown processing. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2024-11607. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2023-31279 | Sierra Wireless AirVantage Management Service improper authentication (swi-psa-2023-002)
7 months 4 weeks ago
A vulnerability classified as critical was found in Sierra Wireless AirVantage. This vulnerability affects unknown code of the component Management Service. The manipulation leads to improper authentication.
This vulnerability was named CVE-2023-31279. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2023-31280 | Sierra Wireless AirVantage Online Warranty Checker Tool information disclosure (swi-psa-2023-002)
7 months 4 weeks ago
A vulnerability classified as problematic has been found in Sierra Wireless AirVantage. This affects an unknown part of the component Online Warranty Checker Tool. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2023-31280. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2022-34668 | NVIDIA NVFlare up to 2.1.3 Pickle deserialization (GHSA-6qv6-q77g-7qm6 / EDB-51051)
7 months 4 weeks ago
A vulnerability was found in NVIDIA NVFlare up to 2.1.3. It has been rated as critical. Affected by this issue is some unknown functionality of the component Pickle Handler. The manipulation leads to deserialization.
This vulnerability is handled as CVE-2022-34668. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2012-3834 | AlienVault Open Source Security Information Management 3.1 time[0][0] sql injection (EDB-18800 / XFDB-75290)
7 months 4 weeks ago
A vulnerability was found in AlienVault Open Source Security Information Management 3.1. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation of the argument time[0][0] leads to sql injection.
This vulnerability is handled as CVE-2012-3834. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2010-4301 | Wireshark 1.4.0/1.4.1 resource management (Bug 5303 / EDB-15973)
7 months 4 weeks ago
A vulnerability classified as problematic was found in Wireshark 1.4.0/1.4.1. This vulnerability affects unknown code. The manipulation leads to improper resource management.
This vulnerability was named CVE-2010-4301. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-53920 | GNU Emacs up to 30.0.92 elisp-mode.el code injection (Nessus ID 213301)
7 months 4 weeks ago
A vulnerability was found in GNU Emacs up to 30.0.92. It has been classified as critical. Affected is an unknown function of the file elisp-mode.el. The manipulation leads to code injection.
This vulnerability is traded as CVE-2024-53920. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
Another JWT Algorithm Confusion Vulnerability: CVE-2024-54150
7 months 4 weeks ago
CVE-2013-4103 | Cryptocat up to 2.0.21 Regular Expression cross site scripting (EDB-38637 / OSVDB-95007)
7 months 4 weeks ago
A vulnerability, which was classified as critical, was found in Cryptocat up to 2.0.21. Affected is an unknown function of the component Regular Expression Handler. The manipulation leads to basic cross site scripting.
This vulnerability is traded as CVE-2013-4103. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2008-4907 | Dovecot 1.1.4/1.1.5 IMAP Client input validation (EDB-32551 / Nessus ID 37538)
7 months 4 weeks ago
A vulnerability was found in Dovecot 1.1.4/1.1.5. It has been rated as problematic. Affected by this issue is some unknown functionality of the component IMAP Client. The manipulation leads to improper input validation.
This vulnerability is handled as CVE-2008-4907. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Виновник атаки на Krispy Kreme найден
7 months 4 weeks ago
Хакеры не смогли устоять перед сладким ароматом пончиков.
Slow Autopsy Performance
7 months 4 weeks ago
CVE-2024-12635 | WP Docs Plugin up to 2.2.0 on WordPress dir_id sql injection
7 months 4 weeks ago
A vulnerability has been found in WP Docs Plugin up to 2.2.0 on WordPress and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument dir_id leads to sql injection.
This vulnerability is known as CVE-2024-12635. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-12066 | SMSA Shipping Plugin up to 2.2 on WordPress File file inclusion
7 months 4 weeks ago
A vulnerability was found in SMSA Shipping Plugin up to 2.2 on WordPress and classified as critical. Affected by this issue is some unknown functionality of the component File Handler. The manipulation leads to file inclusion.
This vulnerability is handled as CVE-2024-12066. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2010-4300 | Wireshark up to 1.4.1 packet-ldss.c dissect_ldss_transfer memory corruption (Bug 5318 / EDB-15676)
7 months 4 weeks ago
A vulnerability classified as critical has been found in Wireshark up to 1.4.1. This affects the function dissect_ldss_transfer of the file epan/dissectors/packet-ldss.c. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2010-4300. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
网络安全顶会——CCS 2024 论文清单与摘要(3)
7 months 4 weeks ago