Aggregator
Маскируясь под VK: троян DCRat атакует русскоязычных пользователей
9 months 2 weeks ago
HTML Smuggling стал главным козырем хитроумных киберзлодеев.
CVE-2024-0232 | SQLite up to 3.43.1 sqlite3.c jsonParseAddNodeArray use after free
9 months 2 weeks ago
A vulnerability was found in SQLite up to 3.43.1. It has been classified as critical. Affected is the function jsonParseAddNodeArray of the file sqlite3.c. The manipulation leads to use after free.
This vulnerability is traded as CVE-2024-0232. The attack can only be done within the local network. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47049 | czim file-handling package up to 1.4.x/2.2.x makeFromUrl/makeFromAny server-side request forgery
9 months 2 weeks ago
A vulnerability was found in czim file-handling package up to 1.4.x/2.2.x. It has been classified as critical. This affects the function makeFromUrl/makeFromAny. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2024-47049. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45682 | Millbeck Communications Proroute H685t-w 3.2.334 command injection (icsa-24-261-02)
9 months 2 weeks ago
A vulnerability classified as critical was found in Millbeck Communications Proroute H685t-w 3.2.334. This vulnerability affects unknown code. The manipulation leads to command injection.
This vulnerability was named CVE-2024-45682. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-47047 | powermail Extension up to 7.5.0/8.5.0/10.9.0/12.4.0 on TYPO3 createAction resource injection
9 months 2 weeks ago
A vulnerability has been found in powermail Extension up to 7.5.0/8.5.0/10.9.0/12.4.0 on TYPO3 and classified as problematic. Affected by this vulnerability is the function createAction. The manipulation of the argument mail leads to improper control of resource identifiers.
This vulnerability is known as CVE-2024-47047. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8091 | Enhanced Search Box Plugin up to 0.6.1 on WordPress Setting cross-site request forgery
9 months 2 weeks ago
A vulnerability has been found in Enhanced Search Box Plugin up to 0.6.1 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Setting Handler. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2024-8091. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-8047 | Visual Sound Plugin up to 1.06 on WordPress Setting cross-site request forgery
9 months 2 weeks ago
A vulnerability classified as problematic has been found in Visual Sound Plugin up to 1.06 on WordPress. Affected is an unknown function of the component Setting Handler. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2024-8047. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-8052 | Review Ratings Plugin up to 1.6 on WordPress cross-site request forgery
9 months 2 weeks ago
A vulnerability classified as problematic was found in Review Ratings Plugin up to 1.6 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2024-8052. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2007-4005 | Mike Dubman Windows RSH daemon 1.7 memory corruption (EDB-4222 / SBV-40892)
9 months 2 weeks ago
A vulnerability was found in Mike Dubman Windows RSH daemon 1.7. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2007-4005. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Iranian hackers charged with hacking Trump campaign to ‘stoke discord’
9 months 2 weeks ago
The U.S. Department of Justice announced criminal charges against three hackers working for Iran’s
Incontro tra Musk e Meloni: impatti sulla sicurezza nazionale
9 months 2 weeks ago
Il 23 settembre 2024, Giorgia Meloni ha ricevuto il Global Citizen Award
CVE-2024-9320 | SourceCodester Online Timesheet App 1.0 Add Timesheet Form add-timesheet.php day/task cross site scripting
9 months 2 weeks ago
A vulnerability has been found in SourceCodester Online Timesheet App 1.0 and classified as problematic. This vulnerability affects unknown code of the file /endpoint/add-timesheet.php of the component Add Timesheet Form. The manipulation of the argument day/task leads to cross site scripting.
This vulnerability was named CVE-2024-9320. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-9319 | SourceCodester Online Timesheet App 1.0 delete-timesheet.php timesheet sql injection
9 months 2 weeks ago
A vulnerability, which was classified as critical, was found in SourceCodester Online Timesheet App 1.0. This affects an unknown part of the file /endpoint/delete-timesheet.php. The manipulation of the argument timesheet leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-9319. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #413331: SourceCodester Online Timesheet App 1.0 Cross Site Scripting [Accepted]
9 months 2 weeks ago
Submit #413331 / VDB-278824
zz0zz0
Submit #413329: SourceCodester Online Timesheet App 1.0 SQL Injection [Accepted]
9 months 2 weeks ago
Submit #413329 / VDB-278823
zz0zz0
CVE-2024-9318 | SourceCodester Advocate Office Management System 1.0 /control/activate.php id sql injection
9 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in SourceCodester Advocate Office Management System 1.0. Affected by this issue is some unknown functionality of the file /control/activate.php. The manipulation of the argument id leads to sql injection.
This vulnerability is handled as CVE-2024-9318. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
G2 Names INE 2024 Enterprise And Small Business Leader
9 months 2 weeks ago
CARY, North Carolina, September 27th, 2024/CyberNewsWire/--INE, a global leader in networking and cy
CVE-2024-9317 | SourceCodester Online Eyewear Shop 1.0 Master.php delete_category id sql injection
9 months 2 weeks ago
A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. Affected by this vulnerability is the function delete_category of the file /classes/Master.php?f=delete_category. The manipulation of the argument id leads to sql injection.
This vulnerability is known as CVE-2024-9317. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #412749: SourceCodester Advocate office management system 4/4 SQL Injection [Accepted]
9 months 2 weeks ago
Submit #412749 / VDB-278822
twcjw