Aggregator
CVE-2024-26268 | Liferay Portal/DXP information exposure
CVE-2024-26265 | Liferay Portal/DXP Image Uploader Module resource consumption
CVE-2024-12749 | Competition Form Plugin up to 2.0 on WordPress cross site scripting
CVE-2025-0804 | flowdee ClickWhale up to 2.4.1 on WordPress Link Page cross site scripting
CVE-2024-56529 | Mailcow Session Identifier session fixiation (GHSA-23c8-4wwr-g3c6)
CVE-2023-35017 | IBM Security Verify Governance 10.0.2 Identity Manager cleartext transmission
CVE-2023-33838 | IBM Security Verify Governance 10.0.2 Identity Manager hash without salt
Facebook против Linux? Посты исчезают, аккаунты блокируются
Attackers exploit SimpleHelp RMM Software flaws for initial access
Attackers exploit SimpleHelp RMM Software flaws for initial access
CVE-2009-3270 | Apple iTunes up to 12.5 on Windows Expat resource management (HT207599 / EDB-12509)
TP-Link Router Web Interface XSS Vulnerability – PoC Exploit Released
A recently discovered Cross-site Scripting (XSS) vulnerability, CVE-2024-57514, affecting the TP-Link Archer A20 v3 Router has raised security concerns among users. The flaw CVE-2024-57514, identified in firmware version 1.0.6 Build 20231011 rel.85717(5553), allows attackers to execute arbitrary JavaScript code through the router’s web interface, potentially leading to malicious exploitation. Discovery of the Vulnerability The vulnerability stems […]
The post TP-Link Router Web Interface XSS Vulnerability – PoC Exploit Released appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2007-1649 | PHP 5.2.1 information disclosure (EDB-3559 / Nessus ID 17797)
CVE-2020-9467 | Piwigo 2.10.1 /ws.php pwgimagessetInfo file Stored cross site scripting (Issue 159191 / EDB-48814)
JVN: 複数のB&R製品における非推奨暗号アルゴリズムの使用の脆弱性
Threat Actors Exploit Government Website Vulnerabilities for Phishing Campaigns
Threat Actors Exploit Government Website Vulnerabilities for Phishing Campaigns
Cofense Intelligence has continually observed the abuse or usage of legitimate domain service exploitation. This report highlights observed phishing threat actor abuse of .gov top-level domains (TLDs) for different countries over two years from November 2022 to November 2024.
The post Threat Actors Exploit Government Website Vulnerabilities for Phishing Campaigns appeared first on Security Boulevard.