Aggregator
RansomHub
4 months 3 weeks ago
cohenido
威努特协同华新水泥荣获2024 IDC中国20大杰出安全项目
4 months 3 weeks ago
全球权威的第三方网络安全大奖。
10 лет тюрьмы за пост: как 43 страны наказывают за интернет-активность
4 months 3 weeks ago
Отчет собрал статистику от самых свободных стран до лидеров репрессий в интернете.
Arcserve UDP 10 accelerates disaster recovery processes
4 months 3 weeks ago
Arcserve launched Arcserve UDP 10, providing customers with an intuitive, flexible, and affordable way to address their critical data security and business continuity challenges. Arcserve UDP 10 is a unified data protection solution that offers backup, replication, high availability, and advanced ransomware detection. UDP 10 is easy to set up, as it seamlessly integrates with major cloud providers like AWS, Azure, Google Cloud, and Wasabi. With smart deduplication and powerful data compression, UDP 10 is … More →
The post Arcserve UDP 10 accelerates disaster recovery processes appeared first on Help Net Security.
Industry News
Sri Lankan Police Arrest Over 200 Chinese Scammers
4 months 3 weeks ago
Chinese Cybercrime Groups Ran Operations in Rented Hotels and Guest Houses
Sri Lankan authorities have arrested more than 200 Chinese nationals who they say overstayed their visitor visas and engaged in large-scale financial scam operations targeting victims across Asia. The Chinese Embassy in Colombo says it supports the law enforcement crackdown.
Sri Lankan authorities have arrested more than 200 Chinese nationals who they say overstayed their visitor visas and engaged in large-scale financial scam operations targeting victims across Asia. The Chinese Embassy in Colombo says it supports the law enforcement crackdown.
European Police Make Headway Against Darknet Drug Markets
4 months 3 weeks ago
Nordic Authorities Take Down Sipulitie, Dutch Police Arrest Alleged Bohemia Admins
October has been a good month for European police agencies shutting down darkweb marketplaces, with Dutch, Finnish and Swedish police announcing server seizures and suspect arrests. It's been more than a decade since Ross "Dread Pirate Roberts" Ulbricht initiated an era of online criminal bazaars.
October has been a good month for European police agencies shutting down darkweb marketplaces, with Dutch, Finnish and Swedish police announcing server seizures and suspect arrests. It's been more than a decade since Ross "Dread Pirate Roberts" Ulbricht initiated an era of online criminal bazaars.
Раздевающие боты в Telegram выходят из-под контроля
4 months 3 weeks ago
У кого искать поддержки человеку, который внезапно стал жертвой дипфейк-насилия?
CVE-2021-4445 | leap13 Premium Addons for Elementor Plugin up to 4.5.1 on WordPress Option Update pa_dismiss_admin_notice authorization
4 months 3 weeks ago
A vulnerability has been found in leap13 Premium Addons for Elementor Plugin up to 4.5.1 on WordPress and classified as problematic. Affected by this vulnerability is the function pa_dismiss_admin_notice of the component Option Update Handler. The manipulation leads to missing authorization.
This vulnerability is known as CVE-2021-4445. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2020-36838 | Facebook Chat Plugin up to 1.5 on WordPress wp_ajax_update_options access control
4 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Facebook Chat Plugin up to 1.5 on WordPress. Affected is the function wp_ajax_update_options. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2020-36838. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-36837 | ThemeGrill Demo Importer Plugin up to 1.6.1 on WordPress reset_wizard_actions authorization
4 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in ThemeGrill Demo Importer Plugin up to 1.6.1 on WordPress. This issue affects the function reset_wizard_actions. The manipulation leads to missing authorization.
The identification of this vulnerability is CVE-2020-36837. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-36836 | emrevona WP Fastest Cache Plugin up to 0.9.0.2 on WordPress Path Validation cross-site request forgery (ID 2235160)
4 months 3 weeks ago
A vulnerability classified as problematic was found in emrevona WP Fastest Cache Plugin up to 0.9.0.2 on WordPress. This vulnerability affects unknown code of the component Path Validation Handler. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2020-36836. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-36833 | wpindeed Indeed Membership Pro Plugin up to 8.6 on WordPress Setting authorization
4 months 3 weeks ago
A vulnerability classified as critical has been found in wpindeed Indeed Membership Pro Plugin up to 8.6 on WordPress. This affects an unknown part of the component Setting Handler. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2020-36833. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2019-25214 | andrewmrobbins ShopWP Plugin up to 2.0.4 on WordPress REST API authorization
4 months 3 weeks ago
A vulnerability was found in andrewmrobbins ShopWP Plugin up to 2.0.4 on WordPress. It has been rated as critical. Affected by this issue is some unknown functionality of the component REST API. The manipulation leads to missing authorization.
This vulnerability is handled as CVE-2019-25214. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2020-36832 | wpindeed Ultimate Membership Pro Plugin up to 8.6.0 on WordPress improper authentication
4 months 3 weeks ago
A vulnerability was found in wpindeed Ultimate Membership Pro Plugin up to 8.6.0 on WordPress. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper authentication.
This vulnerability is known as CVE-2020-36832. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-25215 | arisoft ARI Adminer Plugin up to 1.1.14 on WordPress authorization
4 months 3 weeks ago
A vulnerability was found in arisoft ARI Adminer Plugin up to 1.1.14 on WordPress and classified as critical. This issue affects some unknown processing. The manipulation leads to missing authorization.
The identification of this vulnerability is CVE-2019-25215. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2016-15042 | nmedia Frontend File Manager Plugin/Post Front-End Form on WordPress unrestricted upload
4 months 3 weeks ago
A vulnerability was found in nmedia Frontend File Manager Plugin and Post Front-End Form on WordPress. It has been classified as critical. Affected is the function nm_filemanager_upload_file/nm_postfront_upload_file. The manipulation leads to unrestricted upload.
This vulnerability is traded as CVE-2016-15042. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-36831 | nextscripts Social Networks Auto-Poster Plugin up to 4.3.17 on WordPress access control
4 months 3 weeks ago
A vulnerability has been found in nextscripts Social Networks Auto-Poster Plugin up to 4.3.17 on WordPress and classified as critical. This vulnerability affects unknown code. The manipulation leads to improper access controls.
This vulnerability was named CVE-2020-36831. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2016-15040 | Kento Post View Counter Plugin up to 2.8 on WordPress kento_pvc_geo sql injection
4 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Kento Post View Counter Plugin up to 2.8 on WordPress. This affects an unknown part. The manipulation of the argument kento_pvc_geo leads to sql injection.
This vulnerability is uniquely identified as CVE-2016-15040. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2021-4446 | wpdevteam Essential Addons for Elementor Plugin up to 4.6.4 on WordPress Setting authorization
4 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in wpdevteam Essential Addons for Elementor Plugin up to 4.6.4 on WordPress. Affected by this issue is some unknown functionality of the component Setting Handler. The manipulation leads to missing authorization.
This vulnerability is handled as CVE-2021-4446. The attack may be launched remotely. There is no exploit available.
vuldb.com