Aggregator
Sky ECC encrypted service distributors arrested in Spain, Netherlands
10 months ago
Four distributors of the encrypted communications service Sky ECC, used extensively by criminals, were arrested in Spain and the Netherlands. [...]
Bill Toulas
DEF CON 32 – Eradicating Hepatitis C with BioTerrorism
10 months ago
Authors/Presenters: Mixæl Swan Laufer
Our sincere appreciation to DEF CON, and the Authors/Presenters for publishing their erudite DEF CON 32 content. Originating from the conference’s events located at the Las Vegas Convention Center; and via the organizations YouTube channel.
The post DEF CON 32 – Eradicating Hepatitis C with BioTerrorism appeared first on Security Boulevard.
Marc Handelman
Newspaper Giant Lee Enterprises Reels From Cyberattack
10 months ago
The newspaper company expects the investigation to take some time, but said in an SEC filing that it has not yet identified any material impact.
Kristina Beek, Associate Editor, Dark Reading
CVE-2024-8550 | modelscope agentscope up to 0.0.4 /load-workflow filename exposure of sensitive system information to an unauthorized control sphere
10 months ago
A vulnerability classified as problematic was found in modelscope agentscope up to 0.0.4. Affected by this vulnerability is an unknown functionality of the file /load-workflow. The manipulation of the argument filename leads to exposure of sensitive system information to an unauthorized control sphere.
This vulnerability is known as CVE-2024-8550. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-10649 | wandb openui c945bb859979659add5f490a874140ad17c56a5d missing authentication
10 months ago
A vulnerability classified as critical has been found in wandb openui c945bb859979659add5f490a874140ad17c56a5d. Affected is an unknown function. The manipulation leads to missing authentication.
This vulnerability is traded as CVE-2024-10649. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-13010 | Chimpstudio WP Foodbakery Plugin up to 4.7 on WordPress search_type cross site scripting
10 months ago
A vulnerability was found in Chimpstudio WP Foodbakery Plugin up to 4.7 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation of the argument search_type leads to cross site scripting.
The identification of this vulnerability is CVE-2024-13010. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-46429 | Tenda W18E 16.01.0.8(1625) Web Management Portal hard-coded credentials
10 months ago
A vulnerability was found in Tenda W18E 16.01.0.8(1625). It has been declared as critical. This vulnerability affects unknown code of the component Web Management Portal. The manipulation leads to hard-coded credentials.
This vulnerability was named CVE-2024-46429. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-57178 | Stock-Forecaster up to 01-04-2020 portofolio stock-symbol sql injection
10 months ago
A vulnerability was found in Stock-Forecaster up to 01-04-2020. It has been classified as critical. This affects the function portofolio. The manipulation of the argument stock-symbol leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-57178. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-57177 | perfood couch-auth up to 0.21.2 Header Host injection
10 months ago
A vulnerability was found in perfood couch-auth up to 0.21.2 and classified as problematic. Affected by this issue is some unknown functionality of the component Header Handler. The manipulation of the argument Host leads to injection.
This vulnerability is handled as CVE-2024-57177. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-13059 | mintplex-labs anything-llm up to 1.3.0 Non-ASCII Filename path traversal
10 months ago
A vulnerability has been found in mintplex-labs anything-llm up to 1.3.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Non-ASCII Filename Handler. The manipulation leads to path traversal: '\..\filename'.
This vulnerability is known as CVE-2024-13059. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-13011 | Chimpstudio WP Foodbakery Plugin up to 4.7 on WordPress upload_publisher_profile_image unrestricted upload
10 months ago
A vulnerability, which was classified as critical, was found in Chimpstudio WP Foodbakery Plugin up to 4.7 on WordPress. Affected is the function upload_publisher_profile_image. The manipulation leads to unrestricted upload.
This vulnerability is traded as CVE-2024-13011. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-24016 | Wazuh up to 4.9.0 common.py as_wazuh_object deserialization
10 months ago
A vulnerability, which was classified as critical, has been found in Wazuh up to 4.9.0. This issue affects the function as_wazuh_object of the file framework/wazuh/core/cluster/common.py. The manipulation leads to deserialization.
The identification of this vulnerability is CVE-2025-24016. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Dell security advisory (AV25-069)
10 months ago
Canadian Centre for Cyber Security
CVE-2024-46436 | Tenda W18E 16.01.0.8(1625) Telnet Service hard-coded credentials
10 months ago
A vulnerability classified as very critical was found in Tenda W18E 16.01.0.8(1625). This vulnerability affects unknown code of the component Telnet Service. The manipulation leads to hard-coded credentials.
This vulnerability was named CVE-2024-46436. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-46431 | Tenda W18E 16.01.0.8(1625) Web Management Portal delWewifiPic buffer overflow
10 months ago
A vulnerability classified as critical has been found in Tenda W18E 16.01.0.8(1625). This affects the function delWewifiPic of the component Web Management Portal. The manipulation leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2024-46431. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-46432 | Tenda W18E 16.01.0.8(1625) HTTP POST Request setQuickCfgWifiAndLogin access control
10 months ago
A vulnerability was found in Tenda W18E 16.01.0.8(1625). It has been rated as critical. Affected by this issue is the function setQuickCfgWifiAndLogin of the component HTTP POST Request Handler. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2024-46432. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-46430 | Tenda W18E 16.01.0.8(1625) Web Management Portal setLoginPassword improper authentication
10 months ago
A vulnerability was found in Tenda W18E 16.01.0.8(1625). It has been declared as critical. Affected by this vulnerability is the function setLoginPassword of the component Web Management Portal. The manipulation leads to improper authentication.
This vulnerability is known as CVE-2024-46430. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-46435 | Tenda W18E 16.01.0.8(1625) Web Management Portal delFacebookPic denial of service
10 months ago
A vulnerability was found in Tenda W18E 16.01.0.8(1625). It has been classified as problematic. Affected is the function delFacebookPic of the component Web Management Portal. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2024-46435. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-46434 | Tenda W18E 16.01.0.8(1625) Web Management Portal improper authorization
10 months ago
A vulnerability was found in Tenda W18E 16.01.0.8(1625) and classified as critical. This issue affects some unknown processing of the component Web Management Portal. The manipulation leads to improper authorization.
The identification of this vulnerability is CVE-2024-46434. The attack may be initiated remotely. There is no exploit available.
vuldb.com