Aggregator
CVE-2024-9884 | T Countdown Plugin up to 2.4.8 on WordPress Shortcode cross site scripting
8 months 4 weeks ago
A vulnerability has been found in T Countdown Plugin up to 2.4.8 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-9884. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-9886 | WP Baidu Map Plugin up to 1.2.2 on WordPress Shortcode cross site scripting
8 months 4 weeks ago
A vulnerability, which was classified as problematic, was found in WP Baidu Map Plugin up to 1.2.2 on WordPress. Affected is an unknown function of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-9886. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-8627 | Ultimate TinyMCE Plugin up to 5.7 on WordPress cross site scripting
8 months 4 weeks ago
A vulnerability, which was classified as problematic, has been found in Ultimate TinyMCE Plugin up to 5.7 on WordPress. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-8627. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-9885 | Widget or Sidebar Shortcode Plugin up to 0.6.1 on WordPress cross site scripting
8 months 4 weeks ago
A vulnerability classified as problematic was found in Widget or Sidebar Shortcode Plugin up to 0.6.1 on WordPress. This vulnerability affects unknown code of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-9885. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-8792 | Subscribe to Comments Plugin up to 2.3 on WordPress cross site scripting
8 months 4 weeks ago
A vulnerability classified as problematic has been found in Subscribe to Comments Plugin up to 2.3 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-8792. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-9846 | Enable Shortcodes Inside Widget, Comments and Experts Plugin Shortcode Remote Code Execution
8 months 4 weeks ago
A vulnerability was found in Enable Shortcodes Inside Widget, Comments and Experts Plugin up to 1.0.0 on WordPress. It has been rated as critical. Affected by this issue is some unknown functionality of the component Shortcode Handler. The manipulation leads to Remote Code Execution.
This vulnerability is handled as CVE-2024-9846. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2023-5816 | Code Explorer Plugin up to 1.4.5 on WordPress information disclosure
8 months 4 weeks ago
A vulnerability was found in Code Explorer Plugin up to 1.4.5 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2023-5816. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-8923 | ServiceNow Now Platform improper authentication (KB1706070)
8 months 4 weeks ago
A vulnerability was found in ServiceNow Now Platform. It has been classified as very critical. Affected is an unknown function. The manipulation leads to improper authentication.
This vulnerability is traded as CVE-2024-8923. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-25566 | Ping Identity PingAM up to 7.5.0 Requests redirect
8 months 4 weeks ago
A vulnerability was found in Ping Identity PingAM up to 7.5.0 and classified as problematic. This issue affects some unknown processing of the component Requests Handler. The manipulation leads to open redirect.
The identification of this vulnerability is CVE-2024-25566. The attack may be initiated remotely. There is no exploit available.
vuldb.com
Fortinet 发现零日攻击中使用了新的严重 FortiManager 漏洞
8 months 4 weeks ago
只要攻击者获得了有效证书,将 FortiGate 设备连接到暴露的 FortiManager 服务器并不困难。
Chenlun’s Evolving Phishing Tactics Target Trusted Brands
8 months 4 weeks ago
The phishing campaign targeted users via texts impersonating Amazon, linked to the threat actor Chenlun
CVE-2002-1013 | Inktomi Traffic Server up to 5.2.2 -path memory corruption (EDB-21580 / XFDB-9465)
8 months 4 weeks ago
A vulnerability classified as critical has been found in Inktomi Traffic Server up to 5.2.2. This affects an unknown part. The manipulation of the argument -path leads to memory corruption.
This vulnerability is uniquely identified as CVE-2002-1013. Local access is required to approach this attack. Furthermore, there is an exploit available.
vuldb.com
网络黑产分析赛道 | 打击黄牛,请出拳!新型Black SEO,请挑战!(转发抽奖)
8 months 4 weeks ago
@网络黑产分析赛道参赛人
CVE-2022-24629 | AudioCodes Device Manager Express up to 7.8.20002.47752 File Upload BrowseFiles.php dir path traversal (EDB-51145)
8 months 4 weeks ago
A vulnerability was found in AudioCodes Device Manager Express up to 7.8.20002.47752. It has been rated as critical. Affected by this issue is some unknown functionality of the file BrowseFiles.php of the component File Upload Handler. The manipulation of the argument dir leads to path traversal.
This vulnerability is handled as CVE-2022-24629. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
US charges suspected Redline infostealer developer, admin
8 months 4 weeks ago
The identity of a suspected developer and administrator of the Redline malware-as-a-service operation has been revealed: Russian national Maxim Rudometov. Infrastructure takedown As promised on Monday when they announced the disruption of the Redline and Meta infostealer operations, law enforcement Operation Magnus has unveiled on Tuesday how the takedown played out. “Investigations into Redline and Meta started after victims came forward and a security company notified authorities about possible servers in the Netherlands linked to … More →
The post US charges suspected Redline infostealer developer, admin appeared first on Help Net Security.
Zeljka Zorz
《2024网安市场年报》数据中有意思的地方
8 months 4 weeks ago
《2024网安市场年报》数据中有意思的地方
8 months 4 weeks ago
《2024网安市场年报》数据中有意思的地方
8 months 4 weeks ago
《2024网安市场年报》数据中有意思的地方
8 months 4 weeks ago