Aggregator
CVE-2024-0568 | Schneider Electric Harmony Control Relay RMNF22TB30 NFC improper authentication (SEVD-2024-044-02)
8 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Schneider Electric Harmony Control Relay RMNF22TB30 and Harmony Timer Relay RENF22R2MMW. Affected by this issue is some unknown functionality of the component NFC. The manipulation leads to improper authentication.
This vulnerability is handled as CVE-2024-0568. The attack can only be done within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-21722 | Joomla CMS up to 3.10.14/4.4.2/5.0.2 MFA Management session expiration
8 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Joomla CMS up to 3.10.14/4.4.2/5.0.2. Affected is an unknown function of the component MFA Management. The manipulation leads to session expiration.
This vulnerability is traded as CVE-2024-21722. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-2241 | Devolutions Workspace up to 2024.1.0 access control (DEVO-2024-0003)
8 months 3 weeks ago
A vulnerability was found in Devolutions Workspace up to 2024.1.0. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2024-2241. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2024-30807 | Axiomatic Bento4 1.6.0-641-2-g1529b83 Ap4Atom.cpp ~AP4_UnknownAtom denial of service (Issue 937)
8 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Axiomatic Bento4 1.6.0-641-2-g1529b83. This affects the function AP4_UnknownAtom::~AP4_UnknownAtom of the file Ap4Atom.cpp. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2024-30807. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2021-26387 | AMD EPYC 7001 Processors ASP Kernel access control
8 months 3 weeks ago
A vulnerability was found in AMD EPYC 7001 Processors, EPYC 7002 Processors, EPYC 7003 Processors, EPYC 9004 Processors, Ryzen 3000 Desktop Processors, Ryzen 5000 Desktop Processors, Ryzen 5000 Desktop Processor with Radeon Graphics, Ryzen 7000 Desktop Processors, Athlon 3000 Desktop Processors with Radeon Graphics, Ryzen 4000 Desktop Processors with Radeon Graphics, Ryzen Threadripper 3000 Processors, Ryzen Threadripper PRO 3000WX Processors, Ryzen Threadripper PRO 5000WX Processors, Athlon 3000 Mobile Processors with Radeon Graphics, Ryzen 3000 Mobile Processor with Radeon Graphics, Ryzen 4000 Mobile Processors with Radeon Graphics, Ryzen 5000 Mobile Processors with Radeon Graphics, Ryzen 6000 Processors with Radeon Graphics, Ryzen 7035 Processors with Radeon Graphics, Ryzen 5000 Processors with Radeon Graphics, Ryzen 3000 Processors with Radeon Graphics, EPYC Embedded 3000 Processors, EPYC Embedded 7002 Processors, EPYC Embedded 7003 Processors, EPYC Embedded 9003 Processors, Ryzen Embedded R1000 Processors, Ryzen Embedded R2000 Processors, Ryzen Embedded 5000 Processors, Ryzen Embedded V1000 Processors, Ryzen Embedded V2000 Processors and Ryzen Embedded V3000 Processors. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component ASP Kernel. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2021-26387. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8383 | Mozilla Firefox up to 129.x Scheme Allocation improper authorization in handler for custom url scheme (Nessus ID 207937)
8 months 3 weeks ago
A vulnerability classified as problematic was found in Mozilla Firefox up to 129.x. This vulnerability affects unknown code of the component Scheme Allocation Handler. The manipulation leads to improper authorization in handler for custom url scheme.
This vulnerability was named CVE-2024-8383. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8382 | Mozilla Firefox up to 129.x Internal Browser Event Interface information disclosure (Nessus ID 207937)
8 months 3 weeks ago
A vulnerability was found in Mozilla Firefox up to 129.x. It has been rated as problematic. This issue affects some unknown processing of the component Internal Browser Event Interface. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2024-8382. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8386 | Mozilla Firefox up to 129.x Popup Window ui layer (Nessus ID 207937)
8 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Mozilla Firefox up to 129.x. Affected by this issue is some unknown functionality of the component Popup Window Handler. The manipulation leads to improper restriction of rendered ui layers.
This vulnerability is handled as CVE-2024-8386. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8388 | Mozilla Firefox up to 129.x Notifications ui layer
8 months 3 weeks ago
A vulnerability has been found in Mozilla Firefox up to 129.x and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Notifications Handler. The manipulation leads to improper restriction of rendered ui layers.
This vulnerability is known as CVE-2024-8388. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Russia-linked Midnight Blizzard APT targeted 100+ organizations with a spear-phishing campaign using RDP files
8 months 3 weeks ago
Microsoft warns of a new phishing campaign by Russia-linked APT Midnight Blizzard targeting hundreds of organizations. Microsoft warns of a large-scale spear-phishing campaign by Russia-linked APT Midnight Blizzard (aka APT29, SVR group, BlueBravo, Cozy Bear, Nobelium, Midnight Blizzard, and The Dukes), targeting 1,000+ users across 100+ organizations for intelligence gathering. The Midnight Blizzard group along with APT28 cyber espionage group was involved in the Democratic National […]
Pierluigi Paganini
Microsoft Entra "security defaults" to make MFA setup mandatory
8 months 3 weeks ago
Microsoft says it will improve security across Entra tenants where security defaults are enabled by making multifactor authentication (MFA) registration mandatory. [...]
Sergiu Gatlan
The Open Source Initiative Announces Open Source AI Definition
8 months 3 weeks ago
CVE-2024-9700 | Forminator Forms Plugin up to 1.36.0 on WordPress resource injection
8 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Forminator Forms Plugin up to 1.36.0 on WordPress. This issue affects some unknown processing. The manipulation leads to improper control of resource identifiers.
The identification of this vulnerability is CVE-2024-9700. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-10392 | AI Power Plugin up to 1.8.89 on WordPress unrestricted upload
8 months 3 weeks ago
A vulnerability classified as critical was found in AI Power Plugin up to 1.8.89 on WordPress. This vulnerability affects unknown code. The manipulation leads to unrestricted upload.
This vulnerability was named CVE-2024-10392. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-48202 | IceCMS up to 3.4.7 FileUtils.java unrestricted upload
8 months 3 weeks ago
A vulnerability classified as critical has been found in IceCMS up to 3.4.7. This affects an unknown part of the file FileUtils.java. The manipulation leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2024-48202. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-46531 | PHPGurukul Vehicle Record Management System 1.0 /index.php searchinputdata sql injection
8 months 3 weeks ago
A vulnerability was found in PHPGurukul Vehicle Record Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument searchinputdata leads to sql injection.
This vulnerability is handled as CVE-2024-46531. The attack may be launched remotely. There is no exploit available.
vuldb.com
Business Email Compromise (BEC) Impersonation: The Weapon of Choice of Cybercriminals
8 months 3 weeks ago
CVE-2024-37573 | Talkatone com.talkatone.android 8.4.6 on Android permission
8 months 3 weeks ago
A vulnerability was found in Talkatone com.talkatone.android 8.4.6 on Android. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component com.talkatone.vedroid.ui.launcher.OutgoingCallInterceptor. The manipulation leads to permission issues.
This vulnerability is known as CVE-2024-37573. Attacking locally is a requirement. There is no exploit available.
vuldb.com
CVE-2024-48241 | radare2 up to 5.9.4 __bf_div denial of service (Issue 23317)
8 months 3 weeks ago
A vulnerability was found in radare2 up to 5.9.4. It has been classified as problematic. Affected is the function __bf_div. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2024-48241. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com