Aggregator
CVE-2014-6965 | FAZ.NET 1.0.1 X.509 Certificate cryptographic issues (VU#582497)
4 months 1 week ago
A vulnerability was found in FAZ.NET 1.0.1. It has been declared as critical. This vulnerability affects unknown code of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability was named CVE-2014-6965. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
Qmulos at the Forefront of OSCAL: Empowering Federal Agencies to Achieve OMB M-24-15 with Modern Compliance Technology
4 months 1 week ago
M-24-15 builds on the FedRAMP Authorization Act of 2022 and introduces new requirements that push federal agencies to modernize their approach to cloud security.
The post Qmulos at the Forefront of OSCAL: Empowering Federal Agencies to Achieve OMB M-24-15 with Modern Compliance Technology first appeared on Qmulos.
The post Qmulos at the Forefront of OSCAL: Empowering Federal Agencies to Achieve OMB M-24-15 with Modern Compliance Technology appeared first on Security Boulevard.
Alison Underdown
CVE-2014-6964 | Hyonga Hanyang University Admissions 2.1.3 X.509 Certificate cryptographic issues (VU#582497)
4 months 1 week ago
A vulnerability was found in Hyonga Hanyang University Admissions 2.1.3. It has been classified as critical. This affects an unknown part of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is uniquely identified as CVE-2014-6964. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
D-Link risolve tre vulnerabilità critiche nei suoi router Wi-Fi
4 months 1 week ago
CVE-2007-3526 | Buddy Zone video_gallery.php member_id sql injection (EDB-4128 / XFDB-35187)
4 months 1 week ago
A vulnerability was found in Buddy Zone. It has been rated as critical. This issue affects some unknown processing of the file video_gallery.php. The manipulation of the argument member_id leads to sql injection.
The identification of this vulnerability is CVE-2007-3526. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Black Suit
4 months 1 week ago
cohenido
Qilin
4 months 1 week ago
cohenido
CVE-2024-47222 | New Cloud MyOffice SDK Collaborative Editing Server up to 2.8 MS-WOPI Protocol server-side request forgery
4 months 1 week ago
A vulnerability classified as critical has been found in New Cloud MyOffice SDK Collaborative Editing Server up to 2.8. This affects an unknown part of the component MS-WOPI Protocol Handler. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2024-47222. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2024-43201 | Planet Fitness Workouts App prior 9.8.12 on iOS/Android TLS Certificate certificate validation
4 months 1 week ago
A vulnerability was found in Planet Fitness Workouts App on iOS/Android. It has been rated as problematic. Affected by this issue is some unknown functionality of the component TLS Certificate Handler. The manipulation leads to improper certificate validation.
This vulnerability is handled as CVE-2024-43201. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46639 | HelpDeskZ 2.0.2 Name cross site scripting
4 months 1 week ago
A vulnerability was found in HelpDeskZ 2.0.2. It has been classified as problematic. Affected is an unknown function. The manipulation of the argument Name leads to cross site scripting.
This vulnerability is traded as CVE-2024-46639. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-37779 | WoodWing Elvis DAM 6.98.1 Apache Ant Script code injection
4 months 1 week ago
A vulnerability was found in WoodWing Elvis DAM 6.98.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Apache Ant Script Handler. The manipulation leads to code injection.
This vulnerability is known as CVE-2024-37779. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2017-6340 | Trend Micro InterScan Web Security Virtual Appliance 6.5 name cross site scripting (CP 1746 / EDB-42013)
4 months 1 week ago
A vulnerability was found in Trend Micro InterScan Web Security Virtual Appliance 6.5. It has been rated as problematic. This issue affects some unknown processing. The manipulation of the argument name leads to cross site scripting.
The identification of this vulnerability is CVE-2017-6340. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Mastercard's Bet on Recorded Future a Win for Cyber-Threat Intel
4 months 1 week ago
The $2.65B buy validates the growing importance of threat intelligence to enterprise security strategies.
Jai Vijayan, Contributing Writer
Sui cercapersone esplosi in Libano
4 months 1 week ago
lunedì 23 settembre 2024 Sui cercapersone esplosi in LibanoI miei pos
Telegram now shares users’ IP and phone number on legal requests
4 months 1 week ago
Telegram will now share users' phone numbers and IP addresses with law enforcement if they are found to be violating the platform's rules following a valid legal request. [...]
Sergiu Gatlan
CVE-2006-6813 | Mxmania Mxmania File Upload Manager up to 1.0.6 detail.asp ID sql injection (EDB-2997 / BID-21754)
4 months 1 week ago
A vulnerability was found in Mxmania Mxmania File Upload Manager up to 1.0.6. It has been classified as critical. Affected is an unknown function of the file detail.asp of the component File Upload. The manipulation of the argument ID leads to sql injection.
This vulnerability is traded as CVE-2006-6813. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
PolyDrop - A BYOSI (Bring-Your-Own-Script-Interpreter) Rapid Payload Deployment Toolkit
4 months 1 week ago
- Bring-Your-Own-Script-Interpreter - Leveraging the abuse of trusted applications, one is
CVE-2008-5057 | Aspindir Dizi Portali film.asp film sql injection (EDB-32577 / XFDB-46522)
4 months 1 week ago
A vulnerability has been found in Aspindir Dizi Portali and classified as critical. This vulnerability affects unknown code of the file film.asp. The manipulation of the argument film leads to sql injection.
This vulnerability was named CVE-2008-5057. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
THN Cybersecurity Recap: Last Week's Top Threats and Trends (September 16-22)
4 months 1 week ago
Cybersecurity / Cyber ThreatHold on tight, folks, because last week's cybersecurity landscape was