US healthcare giant Ascension revealed that 5.6 million individuals have had their personal, medical and financial information breached in a ransomware attack
Two WordPress plugins required by the premium WordPress WPLMS theme, which has over 28,000 sales, are vulnerable to more than a dozen critical-severity vulnerabilities. [...]
A vulnerability was found in shuchkin simplexlsx 1.1.12. It has been rated as problematic. Affected by this issue is the function toHTMLEx. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-56364. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A U.S. federal judge has ruled that Israeli spyware maker NSO Group violated U.S. hacking laws by using WhatsApp zero-days to deploy Pegasus spyware on at least 1,400 devices. [...]
A vulnerability was found in rizinorg rizin up to 0.7.3. It has been declared as critical. Affected by this vulnerability is the function rz_core_cmdf of the file rizin.c of the component m Command Handler. The manipulation leads to os command injection.
This vulnerability is known as CVE-2024-53256. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Gogs up to 0.13.0. It has been classified as critical. Affected is an unknown function. The manipulation leads to path traversal.
This vulnerability is traded as CVE-2024-55947. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Gogs up to 0.13.0 and classified as critical. This issue affects some unknown processing. The manipulation leads to symlink following.
The identification of this vulnerability is CVE-2024-54148. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Apache Spark up to 3.3.3/3.4.1/3.5.0 and classified as problematic. This vulnerability affects unknown code of the component Signed Cookie Handler. The manipulation leads to information exposure through error message.
This vulnerability was named CVE-2024-23945. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in Apache Hive up to 3.x. This affects an unknown part of the component Signed Cookie Handler. The manipulation leads to information exposure through error message.
This vulnerability is uniquely identified as CVE-2024-23945. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Apache Traffic Control 8.0.0/8.0.1. Affected by this issue is some unknown functionality of the component PUT Request Handler. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2024-45387. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Pallets Jinja up to 3.1.4. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper neutralization of escape, meta, or control sequences.
This vulnerability is known as CVE-2024-56201. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in Pallets Jinja up to 3.1.4. Affected is the function str.format. The manipulation leads to improper neutralization of special elements used in a template engine.
This vulnerability is traded as CVE-2024-56326. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.