Aggregator
Lynx
9 months 2 weeks ago
cohenido
Building Cyber Resilience Against Ransomware Attacks
9 months 2 weeks ago
Building Cyber Resilience Against Ransomware Attacks
社区速递 071 | 你没见过的社区文章、一周最热评、派友用什么背单词
9 months 2 weeks ago
社区速递 071 | 你没见过的社区文章、一周最热评、派友用什么背单词
CVE-2024-11093 | SG Helper Plugin up to 1.0 on WordPress SVG File Upload cross site scripting
9 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in SG Helper Plugin up to 1.0 on WordPress. This issue affects some unknown processing of the component SVG File Upload Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-11093. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-10952 | Authors List Plugin up to 2.0.4 on WordPress Shortcode update_authors_list_ajax code injection
9 months 2 weeks ago
A vulnerability classified as critical was found in Authors List Plugin up to 2.0.4 on WordPress. This vulnerability affects the function update_authors_list_ajax of the component Shortcode Handler. The manipulation leads to code injection.
This vulnerability was named CVE-2024-10952. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-12099 | Dollie Hub Plugin up to 6.2.0 on WordPress Post information disclosure
9 months 2 weeks ago
A vulnerability classified as problematic has been found in Dollie Hub Plugin up to 6.2.0 on WordPress. This affects an unknown part of the component Post Handler. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-12099. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
Veeam plugs serious holes in Service Provider Console (CVE-2024-42448, CVE-2024-42449)
9 months 2 weeks ago
Veeam has fixed two vulnerabilities in Veeam Service Provider Console (VSPC), one of which (CVE-2024-42448) may allow remote attackers to achieve code exection on the VSPC server machine. The vulnerabilities Veeam Service Provider Console is a cloud-enabled platform that allows enterprises to manage and monitor backup operations across their offices. It’s also used by service providers to deliver Backup-as-a-Service (BaaS) and Disaster Recovery-as-a-Service (DRaaS) services to customers. The solution uses management agents to interact with … More →
The post Veeam plugs serious holes in Service Provider Console (CVE-2024-42448, CVE-2024-42449) appeared first on Help Net Security.
Zeljka Zorz
CVE-2024-11897 | Contact Form, Survey & Form Builder Plugin up to 1.3.9 on WordPress cross site scripting
9 months 2 weeks ago
A vulnerability was found in Contact Form, Survey & Form Builder Plugin up to 1.3.9 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-11897. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-11807 | NPS Computy Plugin up to 2.8.0 on WordPress cross site scripting
9 months 2 weeks ago
A vulnerability was found in NPS Computy Plugin up to 2.8.0 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-11807. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-10885 | SearchIQ Plugin up to 4.6 on WordPress cross site scripting
9 months 2 weeks ago
A vulnerability was found in SearchIQ Plugin up to 4.6 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-10885. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-11813 | Pulsating Chat Button Plugin up to 1.3.6 on WordPress cross-site request forgery
9 months 2 weeks ago
A vulnerability was found in Pulsating Chat Button Plugin up to 1.3.6 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2024-11813. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-11747 | Responsive Videos Plugin up to 2.1 on WordPress cross site scripting
9 months 2 weeks ago
A vulnerability has been found in Responsive Videos Plugin up to 2.1 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-11747. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-10663 | Eleblog Plugin up to 1.8 on WordPress Deactivation authorization
9 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in Eleblog Plugin up to 1.8 on WordPress. This affects an unknown part of the component Deactivation Handler. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2024-10663. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-10832 | Posti Shipping Plugin up to 3.10.3 on WordPress generate_notices_html cross-site request forgery
9 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Posti Shipping Plugin up to 3.10.3 on WordPress. Affected by this issue is the function generate_notices_html. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2024-10832. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-10587 | Funnelforms Free Plugin up to 3.7.4.1 on WordPress code injection
9 months 2 weeks ago
A vulnerability classified as critical was found in Funnelforms Free Plugin up to 3.7.4.1 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to code injection.
This vulnerability is known as CVE-2024-10587. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-29404 | Razer Synapse 3.9.131.20813 Profiles export Local Privilege Escalation
9 months 2 weeks ago
A vulnerability classified as problematic has been found in Razer Synapse 3.9.131.20813. Affected is an unknown function of the component Profiles. The manipulation of the argument export leads to Local Privilege Escalation.
This vulnerability is traded as CVE-2024-29404. Attacking locally is a requirement. There is no exploit available.
vuldb.com
CVE-2024-53999 | MobSF Mobile-Security-Framework- up to 4.2.8 filename cross site scripting (GHSA-5jc6-h9w7-jm3p)
9 months 2 weeks ago
A vulnerability was found in MobSF Mobile-Security-Framework- up to 4.2.8. It has been rated as problematic. This issue affects some unknown processing. The manipulation of the argument filename leads to cross site scripting.
The identification of this vulnerability is CVE-2024-53999. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-54000 | MobSF Mobile-Security-Framework- up to 3.9.6 302 Redirect server-side request forgery (GHSA-m435-9v6r-v5f6)
9 months 2 weeks ago
A vulnerability was found in MobSF Mobile-Security-Framework- up to 3.9.6. It has been declared as critical. This vulnerability affects unknown code of the component 302 Redirect Handler. The manipulation leads to server-side request forgery.
This vulnerability was named CVE-2024-54000. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-25036 | IBM Cognos Controller 11.0.0/11.0.1 authentication bypass
9 months 2 weeks ago
A vulnerability was found in IBM Cognos Controller 11.0.0/11.0.1. It has been classified as critical. This affects an unknown part. The manipulation leads to authentication bypass using alternate channel.
This vulnerability is uniquely identified as CVE-2024-25036. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com