Aggregator
A vulnerability was found in WP SMS Plugin up to 6.0.4 on WordPress and classified as problematic. Affected by this issue is some unknown functionality of the component REST API. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2023-27447. The attack may be launched remotely. There is no exploit available.
CVE-2023-32742 | VeronaLabs WP SMS Plugin up to 6.1.4 on WordPress cross site scripting
9 months ago
A vulnerability, which was classified as problematic, was found in VeronaLabs WP SMS Plugin up to 6.1.4 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2023-32742. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2023-6980 | WP SMS Plugin up to 6.5 on WordPress cross-site request forgery
9 months ago
A vulnerability classified as problematic was found in WP SMS Plugin up to 6.5 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2023-6980. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2023-6981 | WP SMS Plugin up to 6.5 on WordPress cross site scripting
9 months ago
A vulnerability, which was classified as problematic, has been found in WP SMS Plugin up to 6.5 on WordPress. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2023-6981. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-0007 | Palo Alto Networks PAN-OS/Prisma Access/Cloud NGFW Web Interface cross site scripting
9 months ago
A vulnerability classified as problematic has been found in Palo Alto Networks PAN-OS, Prisma Access and Cloud NGFW. Affected is an unknown function of the component Web Interface. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-0007. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-24758 | Undici Header Proxy-Authorization cross-domain policy
9 months ago
A vulnerability was found in Undici and classified as problematic. Affected by this issue is some unknown functionality of the component Header Handler. The manipulation of the argument Proxy-Authorization leads to permissive cross-domain policy with untrusted domains.
This vulnerability is handled as CVE-2024-24758. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-32344 | IBM Cognos Analytics 11.1.7/11.2.4/12.0.0 Form Action cross-site request forgery (XFDB-255898)
9 months ago
A vulnerability has been found in IBM Cognos Analytics 11.1.7/11.2.4/12.0.0 and classified as problematic. This vulnerability affects unknown code of the component Form Action Handler. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2023-32344. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-43051 | IBM Cognos Analytics 11.1.7/11.2.4/12.0.0 Web UI cross site scripting (XFDB-267451)
9 months ago
A vulnerability was found in IBM Cognos Analytics 11.1.7/11.2.4/12.0.0 and classified as problematic. This issue affects some unknown processing of the component Web UI. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2023-43051. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-38359 | IBM Cognos Analytics 11.1.7/11.2.4/12.0.0 Web UI cross site scripting (XFDB-260744)
9 months ago
A vulnerability was found in IBM Cognos Analytics 11.1.7/11.2.4/12.0.0. It has been classified as problematic. Affected is an unknown function of the component Web UI. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2023-38359. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-0114 | Oracle Retail Central Office up to 14.0 input validation (EDB-41690 / Nessus ID 73922)
9 months ago
A vulnerability, which was classified as critical, was found in Oracle Retail Central Office up to 14.0. Affected is an unknown function. The manipulation leads to improper input validation.
This vulnerability is traded as CVE-2014-0114. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
How to Assess Virtual Machines Prior to Deployment with Spectra Assure
9 months ago
Many software development shops deliver their product releases via virtual machine (VM) disk images. Whether deployed to a cloud environment, data center, or elsewhere, delivering safe and secure images is vital. If vulnerabilities, malware, or even unhardened binaries are present in a disk image delivered to customers, they are exposed to a significant degree of risk every time a VM is spun up using that image. If one of those customers ends up being compromised in a cyberattack due to the VM, both organizations may incur financial loss, as well as reputational damage.
The post How to Assess Virtual Machines Prior to Deployment with Spectra Assure appeared first on Security Boulevard.
Dave Ferguson
Компьютер, который пел о любви: как жуткая колыбельная IBM стала гимном новой эры
9 months ago
Эксперимент 1960-х, вдохновивший создателей космической одиссеи.
Gatito_FBI_NZ Claims to have Leaked the Data of Supreme Electoral Tribunal of Bolivia
9 months ago
Gatito_FBI_NZ Claims to have Leaked the Data of Supreme Electoral Tribunal of Bolivia
Dark Web Informer - Cyber Threat Intelligence
CISA Directs Federal Agencies to Secure Cloud Environments
9 months ago
Actions direct agencies to deploy specific security configurations to reduce cyber-risk.
Радиостанция Судного дня вышла на связь: 24 загадочных сообщения
9 months ago
Частота 4625 кГц вновь заставила гадать о своём назначении.
New critical Apache Struts flaw exploited to find vulnerable servers
9 months ago
A recently patched critical Apache Struts 2 vulnerability tracked as CVE-2024-53677 is actively exploited using public proof-of-concept exploits to find vulnerable devices. [...]
Bill Toulas
RansomHub
9 months ago
cohenido
RansomHub
9 months ago
cohenido
RansomHub
9 months ago
cohenido
Randall Munroe’s XKCD ‘METAR’
9 months ago
Marc Handelman