Aggregator
CVE-2024-49270 | HashThemes Smart Blocks Plugin up to 2.0 on WordPress cross site scripting
10 months 3 weeks ago
A vulnerability classified as problematic has been found in HashThemes Smart Blocks Plugin up to 2.0 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-49270. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-49252 | Teplitsa of Social Technologies Leyka Plugin up to 3.31.6 on WordPress exposure of sensitive system information to an unauthorized control sphere
10 months 3 weeks ago
A vulnerability was found in Teplitsa of Social Technologies Leyka Plugin up to 3.31.6 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to exposure of sensitive system information to an unauthorized control sphere.
This vulnerability is handled as CVE-2024-49252. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-49257 | Denis Azz Anonim Posting Plugin up to 0.9 on WordPress unrestricted upload
10 months 3 weeks ago
A vulnerability was found in Denis Azz Anonim Posting Plugin up to 0.9 on WordPress. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to unrestricted upload.
This vulnerability is known as CVE-2024-49257. The attack can be launched remotely. There is no exploit available.
vuldb.com
Coffee Lovers Warned of New Starbucks Phishing Scam
10 months 3 weeks ago
Phishing emails claiming to be from Starbucks are offering recipients a "free Coffee Lovers Box" in an attempt to steal personal or install malware on devices
CVE-2024-48042 | Supsystic Contact Form Plugin up to 1.7.28 on WordPress special elements used in a template engine
10 months 3 weeks ago
A vulnerability was found in Supsystic Contact Form Plugin up to 1.7.28 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation leads to improper neutralization of special elements used in a template engine.
This vulnerability is traded as CVE-2024-48042. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-49227 | Innovaweb Free Stock Photos Foter Plugin up to 1.5.4 on WordPress deserialization
10 months 3 weeks ago
A vulnerability was found in Innovaweb Free Stock Photos Foter Plugin up to 1.5.4 on WordPress and classified as critical. This issue affects some unknown processing. The manipulation leads to deserialization.
The identification of this vulnerability is CVE-2024-49227. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-22033 | SUSE Package Hub/openSUSE Leap/openSUSE Tumbleweed OBS Service os command injection
10 months 3 weeks ago
A vulnerability has been found in SUSE Package Hub, openSUSE Leap and openSUSE Tumbleweed and classified as critical. This vulnerability affects unknown code of the component OBS Service. The manipulation leads to os command injection.
This vulnerability was named CVE-2024-22033. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-49216 | Joshua Clayton Feed Comments Number Plugin up to 0.2.1 on WordPress unrestricted upload
10 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Joshua Clayton Feed Comments Number Plugin up to 0.2.1 on WordPress. This affects an unknown part. The manipulation leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2024-49216. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-49245 | Ahime Image Printer Plugin up to 1.0.0 on WordPress path traversal
10 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Ahime Image Printer Plugin up to 1.0.0 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to path traversal.
This vulnerability is handled as CVE-2024-49245. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-49251 | Maantheme Maan Addons For Elementor Plugin up to 1.0.1 on WordPress Include/Require filename control
10 months 3 weeks ago
A vulnerability classified as problematic was found in Maantheme Maan Addons For Elementor Plugin up to 1.0.1 on WordPress. Affected by this vulnerability is an unknown functionality of the component Include/Require. The manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is known as CVE-2024-49251. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-48034 | Fliperrr Team Creates 3D Flipbook Plugin/PDF Flipbook Plugin up to 1.2 on WordPress unrestricted upload
10 months 3 weeks ago
A vulnerability classified as critical has been found in Fliperrr Team Creates 3D Flipbook Plugin and PDF Flipbook Plugin up to 1.2 on WordPress. Affected is an unknown function. The manipulation leads to unrestricted upload.
This vulnerability is traded as CVE-2024-48034. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-49258 | Limb Gallery Plugin up to 1.5.7 on WordPress path traversal
10 months 3 weeks ago
A vulnerability was found in Limb Gallery Plugin up to 1.5.7 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to path traversal: '.../...//'.
The identification of this vulnerability is CVE-2024-49258. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-49271 | Unlimited Elements for Elementor Plugin up to 1.5.121 on WordPress special elements used in a template engine
10 months 3 weeks ago
A vulnerability was found in Unlimited Elements for Elementor Plugin up to 1.5.121 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to improper neutralization of special elements used in a template engine.
This vulnerability was named CVE-2024-49271. The attack can be initiated remotely. There is no exploit available.
vuldb.com
RansomHub
10 months 3 weeks ago
cohenido
RansomHub
10 months 3 weeks ago
cohenido
RansomHub
10 months 3 weeks ago
cohenido
Understand these seven password attacks and how to stop them
10 months 3 weeks ago
Hackers are always looking for new ways to crack passwords and gain access to your organization's data and systems. In this post, Specops Software discusses the seven most common password attacks and provide tips on how to defend against them. [...]
Sponsored by Specops Software
CVE-2024-49253 | James Park Analyse Uploads Plugin up to 0.5 on WordPress path traversal
10 months 3 weeks ago
A vulnerability was found in James Park Analyse Uploads Plugin up to 0.5 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to relative path traversal.
This vulnerability is uniquely identified as CVE-2024-49253. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-47637 | LiteSpeed Technologies LiteSpeed Cache Plugin up to 6.4.1 on WordPress path traversal
10 months 3 weeks ago
A vulnerability was found in LiteSpeed Technologies LiteSpeed Cache Plugin up to 6.4.1 on WordPress and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to relative path traversal.
This vulnerability is handled as CVE-2024-47637. The attack may be launched remotely. There is no exploit available.
vuldb.com