Aggregator
CVE-2007-3526 | Buddy Zone video_gallery.php member_id sql injection (EDB-4128 / XFDB-35187)
9 months 1 week ago
A vulnerability was found in Buddy Zone. It has been rated as critical. This issue affects some unknown processing of the file video_gallery.php. The manipulation of the argument member_id leads to sql injection.
The identification of this vulnerability is CVE-2007-3526. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Black Suit
9 months 1 week ago
cohenido
Qilin
9 months 1 week ago
cohenido
CVE-2024-47222 | New Cloud MyOffice SDK Collaborative Editing Server up to 2.8 MS-WOPI Protocol server-side request forgery
9 months 1 week ago
A vulnerability classified as critical has been found in New Cloud MyOffice SDK Collaborative Editing Server up to 2.8. This affects an unknown part of the component MS-WOPI Protocol Handler. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2024-47222. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2024-43201 | Planet Fitness Workouts App prior 9.8.12 on iOS/Android TLS Certificate certificate validation
9 months 1 week ago
A vulnerability was found in Planet Fitness Workouts App on iOS/Android. It has been rated as problematic. Affected by this issue is some unknown functionality of the component TLS Certificate Handler. The manipulation leads to improper certificate validation.
This vulnerability is handled as CVE-2024-43201. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46639 | HelpDeskZ 2.0.2 Name cross site scripting
9 months 1 week ago
A vulnerability was found in HelpDeskZ 2.0.2. It has been classified as problematic. Affected is an unknown function. The manipulation of the argument Name leads to cross site scripting.
This vulnerability is traded as CVE-2024-46639. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-37779 | WoodWing Elvis DAM 6.98.1 Apache Ant Script code injection
9 months 1 week ago
A vulnerability was found in WoodWing Elvis DAM 6.98.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Apache Ant Script Handler. The manipulation leads to code injection.
This vulnerability is known as CVE-2024-37779. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2017-6340 | Trend Micro InterScan Web Security Virtual Appliance 6.5 name cross site scripting (CP 1746 / EDB-42013)
9 months 1 week ago
A vulnerability was found in Trend Micro InterScan Web Security Virtual Appliance 6.5. It has been rated as problematic. This issue affects some unknown processing. The manipulation of the argument name leads to cross site scripting.
The identification of this vulnerability is CVE-2017-6340. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Mastercard's Bet on Recorded Future a Win for Cyber-Threat Intel
9 months 1 week ago
The $2.65B buy validates the growing importance of threat intelligence to enterprise security strategies.
Jai Vijayan, Contributing Writer
Sui cercapersone esplosi in Libano
9 months 1 week ago
lunedì 23 settembre 2024 Sui cercapersone esplosi in LibanoI miei pos
Telegram now shares users’ IP and phone number on legal requests
9 months 1 week ago
Telegram will now share users' phone numbers and IP addresses with law enforcement if they are found to be violating the platform's rules following a valid legal request. [...]
Sergiu Gatlan
CVE-2006-6813 | Mxmania Mxmania File Upload Manager up to 1.0.6 detail.asp ID sql injection (EDB-2997 / BID-21754)
9 months 1 week ago
A vulnerability was found in Mxmania Mxmania File Upload Manager up to 1.0.6. It has been classified as critical. Affected is an unknown function of the file detail.asp of the component File Upload. The manipulation of the argument ID leads to sql injection.
This vulnerability is traded as CVE-2006-6813. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
PolyDrop - A BYOSI (Bring-Your-Own-Script-Interpreter) Rapid Payload Deployment Toolkit
9 months 1 week ago
- Bring-Your-Own-Script-Interpreter - Leveraging the abuse of trusted applications, one is
CVE-2008-5057 | Aspindir Dizi Portali film.asp film sql injection (EDB-32577 / XFDB-46522)
9 months 1 week ago
A vulnerability has been found in Aspindir Dizi Portali and classified as critical. This vulnerability affects unknown code of the file film.asp. The manipulation of the argument film leads to sql injection.
This vulnerability was named CVE-2008-5057. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
THN Cybersecurity Recap: Last Week's Top Threats and Trends (September 16-22)
9 months 1 week ago
Cybersecurity / Cyber ThreatHold on tight, folks, because last week's cybersecurity landscape was
CVE-2024-8662 | Koko Analytics Plugin up to 1.3.12 on WordPress cross site scripting
9 months 1 week ago
A vulnerability was found in Koko Analytics Plugin up to 1.3.12 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-8662. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-8628 | Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber Plugin cross site scripting
9 months 1 week ago
A vulnerability has been found in Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber Plugin up to 1.2.70.3 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-8628. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-8794 | BA Book Everything Plugin up to 1.6.20 on WordPress Password password recovery
9 months 1 week ago
A vulnerability, which was classified as problematic, was found in BA Book Everything Plugin up to 1.6.20 on WordPress. This affects an unknown part of the component Password Handler. The manipulation leads to weak password recovery.
This vulnerability is uniquely identified as CVE-2024-8794. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2022-2439 | Easy Digital Downloads Plugin up to 3.3.3 on WordPress Phar deserialization
9 months 1 week ago
A vulnerability, which was classified as problematic, has been found in Easy Digital Downloads Plugin up to 3.3.3 on WordPress. Affected by this issue is some unknown functionality of the component Phar Handler. The manipulation leads to deserialization.
This vulnerability is handled as CVE-2022-2439. The attack may be launched remotely. There is no exploit available.
vuldb.com