Aggregator
«Мы знаем все о вас»: рекламная корпорация похвасталась тотальной слежкой за потребителями
9 months ago
Корпорация утверждает, что прогнозирует поведение 91% пользователей сети.
CVE-2025-2340 | otale Tale Blog 2.0.5 Site Settings /options/save saveOptions Site Title cross site scripting
9 months ago
A vulnerability was found in otale Tale Blog 2.0.5. It has been declared as problematic. This vulnerability affects the function saveOptions of the file /options/save of the component Site Settings. The manipulation of the argument Site Title leads to cross site scripting. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability was named CVE-2025-2340. The attack can be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-2339 | otale Tale Blog 2.0.5 /%61dmin/api/logs improper authentication
9 months ago
A vulnerability was found in otale Tale Blog 2.0.5. It has been classified as problematic. This affects an unknown part of the file /%61dmin/api/logs. The manipulation leads to improper authentication. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is uniquely identified as CVE-2025-2339. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
Submit #514793: Tale Tale v2.0.5 Cross Site Scripting [Accepted]
9 months ago
Submit #514793 / VDB-299806
yitclara
Submit #511578: Tale Blog Tale v2.0.5 Exposure of Sensitive System Information to an Unauthorized Cont [Accepted]
9 months ago
Submit #511578 / VDB-299805
yitclara
BSides Exeter 2024 – Blue Track – DFIR – Ctrl+Alt+Defeat: Using Threat Intelligence To Navigate The Cyber Battlefield
9 months ago
Authors/Presenters: Sophia McCall
Our thanks to Bsides Exeter, and the Presenters/Authors for publishing their timely Bsides Exeter Conference content. All brought to you via the organizations YouTube channel.
The post BSides Exeter 2024 – Blue Track – DFIR – Ctrl+Alt+Defeat: Using Threat Intelligence To Navigate The Cyber Battlefield appeared first on Security Boulevard.
Marc Handelman
CVE-2025-1530 | tripetto Form Builder Plugin for Contact Forms, Surveys and Quizzes cross-site request forgery
9 months ago
A vulnerability was found in tripetto Form Builder Plugin for Contact Forms, Surveys and Quizzes up to 8.0.9 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2025-1530. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-2025 | GiveWP Plugin up to 3.22.0 on WordPress give_reports_earnings authorization
9 months ago
A vulnerability has been found in GiveWP Plugin up to 3.22.0 on WordPress and classified as problematic. Affected by this vulnerability is the function give_reports_earnings. The manipulation leads to missing authorization.
This vulnerability is known as CVE-2025-2025. The attack can be launched remotely. There is no exploit available.
vuldb.com
BidenCash Allegedly Breached – 40GB of Partial Credit Card Data Leaked on Cybercrime Forum
9 months ago
BidenCash Allegedly Breached – 40GB of Partial Credit Card Data Leaked on Cybercrime Forum
Dark Web Informer - Cyber Threat Intelligence
CVE-2025-2338 | tbeu matio 1.5.28 src/io.c strdup_vprintf heap-based overflow (Issue 269)
9 months ago
A vulnerability, which was classified as critical, was found in tbeu matio 1.5.28. Affected is the function strdup_vprintf of the file src/io.c. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2025-2338. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-2337 | tbeu matio 1.5.28 src/mat.c Mat_VarPrint heap-based overflow (Issue 267)
9 months ago
A vulnerability, which was classified as critical, has been found in tbeu matio 1.5.28. This issue affects the function Mat_VarPrint of the file src/mat.c. The manipulation leads to heap-based buffer overflow.
The identification of this vulnerability is CVE-2025-2337. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #510781: https://github.com/tbeu/matio matio 1.5.28 Heap-based Buffer Overflow [Accepted]
9 months ago
Submit #510781 / VDB-299802
Submit #510780: https://github.com/tbeu/matio matio 1.5.28 Heap-based Buffer Overflow [Duplicate]
9 months ago
Submit #510780 / VDB-299801
Submit #510779: https://github.com/tbeu/matio matio 1.5.28 Heap-based Buffer Overflow [Accepted]
9 months ago
Submit #510779 / VDB-299801
New Akira ransomware decryptor cracks encryptions keys using GPUs
9 months ago
Security researcher Yohanes Nugroho has released a decryptor for the Linux variant of Akira ransomware, which utilizes GPU power to retrieve the decryption key and unlock files for free. [...]
Bill Toulas
CVE-2024-41735 | SAP Commerce Backoffice 2205 cross site scripting
9 months ago
A vulnerability was found in SAP Commerce Backoffice 2205. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-41735. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-7590 | Brainstorm Force Spectra Plugin up to 2.14.1 on WordPress cross site scripting
9 months ago
A vulnerability classified as problematic has been found in Brainstorm Force Spectra Plugin up to 2.14.1 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-7590. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-43126 | Sender Plugin up to 2.6.14 on WordPress cross site scripting
9 months ago
A vulnerability classified as problematic was found in Sender Plugin up to 2.6.14 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-43126. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-43127 | WPFactory Products, Order & Customers Export for WooCommerce Plugin cross site scripting
9 months ago
A vulnerability, which was classified as problematic, has been found in WPFactory Products, Order & Customers Export for WooCommerce Plugin up to 2.0.11 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-43127. The attack may be launched remotely. There is no exploit available.
vuldb.com