Aggregator
Monti
10 months 2 weeks ago
cohenido
Monti
10 months 2 weeks ago
cohenido
Под маской пентестера: ботнет Aquabot нашел хитрый путь к корпоративным сетям
10 months 2 weeks ago
Потомок Mirai переродился в телефонных сетях Mitel.
Monti
10 months 2 weeks ago
cohenido
CVE-2025-23362 | Rodrigue EXIF Viewer Classic 2.3.2/2.4.0 EXIF Meta Data cross site scripting
10 months 2 weeks ago
A vulnerability has been found in Rodrigue EXIF Viewer Classic 2.3.2/2.4.0 and classified as problematic. This vulnerability affects unknown code of the component EXIF Meta Data Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-23362. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-11932 | Rockwell Automation DataMosaix Private Cloud 7.09 path traversal (icsa-25-028-05)
10 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Rockwell Automation DataMosaix Private Cloud 7.09. This affects an unknown part. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2024-11932. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-57519 | Open5GS 2.7.2 Subscription lib/dbi/subscription.c ogs_dbi_auth_info denial of service (Issue 3635)
10 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in Open5GS 2.7.2. Affected by this issue is the function ogs_dbi_auth_info of the file lib/dbi/subscription.c of the component Subscription Handler. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2024-57519. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-27068 | Sitecore Experience Platform up to 10.2 ValidationResult.aspx deserialization
10 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in Sitecore Experience Platform up to 10.2. This issue affects some unknown processing of the file ValidationResult.aspx. The manipulation leads to deserialization.
The identification of this vulnerability is CVE-2023-27068. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-26595 | Cybozu Garoon up to 5.9.2 Message denial of service
10 months 2 weeks ago
A vulnerability has been found in Cybozu Garoon up to 5.9.2 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Message Handler. The manipulation leads to denial of service.
This vulnerability is known as CVE-2023-26595. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-26267 | Liferay Portal/DXP Response Header Liferay-Portal insecure default initialization of resource
10 months 2 weeks ago
A vulnerability was found in Liferay Portal and DXP and classified as problematic. This issue affects some unknown processing of the component Response Header Handler. The manipulation of the argument Liferay-Portal leads to insecure default initialization of resource.
The identification of this vulnerability is CVE-2024-26267. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-26270 | Liferay Portal/DXP Account Settings Page insertion of sensitive information into sent data
10 months 2 weeks ago
A vulnerability was found in Liferay Portal and DXP. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Account Settings Page. The manipulation leads to insertion of sensitive information into sent data.
This vulnerability is known as CVE-2024-26270. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-26268 | Liferay Portal/DXP information exposure
10 months 2 weeks ago
A vulnerability was found in Liferay Portal and DXP. It has been classified as problematic. This affects an unknown part. The manipulation leads to information exposure through discrepancy.
This vulnerability is uniquely identified as CVE-2024-26268. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-26265 | Liferay Portal/DXP Image Uploader Module resource consumption
10 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Liferay Portal and DXP. Affected by this issue is some unknown functionality of the component Image Uploader Module. The manipulation leads to resource consumption.
This vulnerability is handled as CVE-2024-26265. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-12749 | Competition Form Plugin up to 2.0 on WordPress cross site scripting
10 months 2 weeks ago
A vulnerability classified as problematic was found in Competition Form Plugin up to 2.0 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-12749. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-0804 | flowdee ClickWhale up to 2.4.1 on WordPress Link Page cross site scripting
10 months 2 weeks ago
A vulnerability classified as problematic has been found in flowdee ClickWhale up to 2.4.1 on WordPress. Affected is an unknown function of the component Link Page. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-0804. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-56529 | Mailcow Session Identifier session fixiation (GHSA-23c8-4wwr-g3c6)
10 months 2 weeks ago
A vulnerability was found in Mailcow. It has been rated as critical. This issue affects some unknown processing of the component Session Identifier Handler. The manipulation leads to session fixiation.
The identification of this vulnerability is CVE-2024-56529. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2023-35017 | IBM Security Verify Governance 10.0.2 Identity Manager cleartext transmission
10 months 2 weeks ago
A vulnerability was found in IBM Security Verify Governance 10.0.2. It has been declared as problematic. This vulnerability affects unknown code of the component Identity Manager. The manipulation leads to cleartext transmission of sensitive information.
This vulnerability was named CVE-2023-35017. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-33838 | IBM Security Verify Governance 10.0.2 Identity Manager hash without salt
10 months 2 weeks ago
A vulnerability was found in IBM Security Verify Governance 10.0.2. It has been classified as problematic. This affects an unknown part of the component Identity Manager. The manipulation leads to one-way hash without salt.
This vulnerability is uniquely identified as CVE-2023-33838. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Facebook против Linux? Посты исчезают, аккаунты блокируются
10 months 2 weeks ago
Соцсеть ополчилась против свободного ПО.