Aggregator
CVE-2024-46485 | dingfanzu CMS 1.0 doAdminAction.php cross-site request forgery
4 months ago
A vulnerability, which was classified as problematic, was found in dingfanzu CMS 1.0. This affects an unknown part of the file /admin/doAdminAction.php?act=addCate. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2024-46485. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-46600 | dingfanzu CMS 1.0 doAdminAction.php cross-site request forgery
4 months ago
A vulnerability, which was classified as problematic, has been found in dingfanzu CMS 1.0. Affected by this issue is some unknown functionality of the file /admin/doAdminAction.php?act=delCate&id=31. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2024-46600. The attack may be launched remotely. There is no exploit available.
vuldb.com
Medusa Blog
4 months ago
cohenido
Medusa Blog
4 months ago
cohenido
CVE-2023-25189 | Nokia BTS BTS Service Operation Detail information disclosure
4 months ago
A vulnerability classified as problematic was found in Nokia BTS. Affected by this vulnerability is an unknown functionality of the component BTS Service Operation Detail Handler. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2023-25189. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
Akira
4 months ago
cohenido
CVE-2024-43959 | Themepoints Testimonials Plugin up to 3.0.8 on WordPress cross site scripting
4 months ago
A vulnerability classified as problematic has been found in Themepoints Testimonials Plugin up to 3.0.8 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-43959. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
Akira
4 months ago
cohenido
CVE-2024-43990 | StylemixThemes Masterstudy LMS Starter Plugin up to 1.1.8 on WordPress log file
4 months ago
A vulnerability was found in StylemixThemes Masterstudy LMS Starter Plugin up to 1.1.8 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to sensitive information in log files.
The identification of this vulnerability is CVE-2024-43990. The attack may be initiated remotely. There is no exploit available.
vuldb.com
Timeshare Owner? The Mexican Drug Cartels Want You
4 months ago
The FBI is warning timeshare owners to be wary of a prevalent telemarketing scam involving a violent Mexican drug cartel that tries to trick elderly people into believing someone wants to buy their property. This is the story of a couple who recently lost more than $50,000 to an ongoing timeshare scam that spans at least two dozen phony escrow, title and realty firms.
BrianKrebs
Lockbit
4 months ago
cohenido
CVE-2024-22892 | OpenSlides 4.0.15 weak hash
4 months ago
A vulnerability was found in OpenSlides 4.0.15. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to use of weak hash.
This vulnerability was named CVE-2024-22892. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-7421 | Devolutions Remote Desktop Manager up to 2024.2.20.0 on Windows Command-Line Argument log file (DEVO-2024-0014)
4 months ago
A vulnerability was found in Devolutions Remote Desktop Manager up to 2024.2.20.0 on Windows. It has been classified as problematic. This affects an unknown part of the component Command-Line Argument Handler. The manipulation leads to sensitive information in log files.
This vulnerability is uniquely identified as CVE-2024-7421. The attack needs to be approached locally. There is no exploit available.
vuldb.com
CVE-2024-47078 | Meshtastic Firmware up to 2.5.0 MQTT improper authentication
4 months ago
A vulnerability was found in Meshtastic Firmware up to 2.5.0 and classified as critical. Affected by this issue is some unknown functionality of the component MQTT Handler. The manipulation leads to improper authentication.
This vulnerability is handled as CVE-2024-47078. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CISA: Hackers target industrial systems using “unsophisticated methods”
4 months ago
CISA warned today of threat actors trying to breach critical infrastructure networks by targeting Internet-exposed industrial devices using "unsophisticated" methods like brute force attacks and default credentials. [...]
Sergiu Gatlan
CVE-2024-30128 | HCL Nomad Server on Domino up to 1.0.12 Source IP Address access control (KB0115504)
4 months ago
A vulnerability has been found in HCL Nomad Server on Domino up to 1.0.12 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Source IP Address Handler. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2024-30128. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-46461 | VideoLAN VLC Media Player up to 3.0.20 Mms Stream heap-based overflow
4 months ago
A vulnerability, which was classified as critical, was found in VideoLAN VLC Media Player up to 3.0.20. Affected is an unknown function of the component Mms Stream Handler. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2024-46461. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-22893 | OpenSlides 4.0.15 Password weak password hash
4 months ago
A vulnerability, which was classified as problematic, has been found in OpenSlides 4.0.15. This issue affects some unknown processing of the component Password Handler. The manipulation leads to password hash with insufficient computational effort.
The identification of this vulnerability is CVE-2024-22893. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-43237 | TaxoPress Tag Cloud Plugin up to 2.0.3 on WordPress information disclosure
4 months ago
A vulnerability classified as problematic was found in TaxoPress Tag Cloud Plugin up to 2.0.3 on WordPress. This vulnerability affects unknown code. The manipulation leads to information disclosure.
This vulnerability was named CVE-2024-43237. The attack can be initiated remotely. There is no exploit available.
vuldb.com