Aggregator
AI and Applied Security Dominate Nullcon Paper Submissions
5 months ago
CFP Board Members Discuss AI, Hardware Access and Emerging Trends for Nullcon 2025
Cybersecurity research submissions for the Nullcon 2025 CFP Review Board reflect prominent trends and challenges in the field. Nullcon CFP Review Board members Anant Shrivastava and Neelu Tripathi noted a growing focus on AI, supply chain and applied security.
Cybersecurity research submissions for the Nullcon 2025 CFP Review Board reflect prominent trends and challenges in the field. Nullcon CFP Review Board members Anant Shrivastava and Neelu Tripathi noted a growing focus on AI, supply chain and applied security.
Ransomware Leak Sites Suggest Attacks Reached Record High
5 months ago
RansomHub, Play and Akira Appear to Dominate; Numerous Newcomers Join the Fray
While ransomware groups' data-leak sites regularly lie, if taken at face value, in December 2024 they collectively listed the largest number of victims ever seen in a one-month period, dominated by RansomHub, Play and Akira operations, plus a bevy of newcomers, researchers report.
While ransomware groups' data-leak sites regularly lie, if taken at face value, in December 2024 they collectively listed the largest number of victims ever seen in a one-month period, dominated by RansomHub, Play and Akira operations, plus a bevy of newcomers, researchers report.
Randall Munroe’s XKCD ‘Chess Zoo’
5 months ago
via the comic humor & dry wit of Randall Munroe, creator of XKCD
The post Randall Munroe’s XKCD ‘Chess Zoo’ appeared first on Security Boulevard.
Marc Handelman
CVE-2024-11452 | Chamber Dashboard Business Directory Plugin up to 3.3.8 on WordPress cross site scripting
5 months ago
A vulnerability has been found in Chamber Dashboard Business Directory Plugin up to 3.3.8 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Chamber Dashboard. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-11452. The attack can be launched remotely. There is no exploit available.
vuldb.com
Offensive Linux Security
5 months ago
Offensive Linux Security
Dark Web Informer - Cyber Threat Intelligence
CVE-2024-10789 | WP User Profile Avatar up to 1.0.5 on WordPress Setting cross-site request forgery
5 months ago
A vulnerability, which was classified as problematic, was found in WP User Profile Avatar up to 1.0.5 on WordPress. Affected is an unknown function of the component Setting Handler. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2024-10789. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-0502 | Crafter CMS up to 4.0.7/4.1.5 transmission of private resources into a new sphere ('resource leak')
5 months ago
A vulnerability, which was classified as problematic, has been found in Crafter CMS up to 4.0.7/4.1.5. This issue affects some unknown processing. The manipulation leads to transmission of private resources into a new sphere ('resource leak').
The identification of this vulnerability is CVE-2025-0502. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-22798 | CHR Designer Responsive jQuery Slider Plugin up to 1.1.1 on WordPress cross site scripting
5 months ago
A vulnerability classified as problematic was found in CHR Designer Responsive jQuery Slider Plugin up to 1.1.1 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-22798. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-7085 | OpenText Solutions Business Manager up to 12.2.1 cross site scripting
5 months ago
A vulnerability was found in OpenText Solutions Business Manager up to 12.2.1. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-7085. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-22795 | Thorsten Krug Multilang Contact Form Plugin up to 1.5 on WordPress cross site scripting
5 months ago
A vulnerability classified as problematic has been found in Thorsten Krug Multilang Contact Form Plugin up to 1.5 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-22795. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-52783 | Xinje XDPPro up to 3.7.17c XNetSocketClient XDPPro.exe permission
5 months ago
A vulnerability was found in Xinje XDPPro up to 3.7.17c. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file XDPPro.exe of the component XNetSocketClient. The manipulation leads to permission issues.
This vulnerability is known as CVE-2024-52783. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2025-22784 | Johan Ström Background Control Plugin up to 1.0.5 on WordPress cross-site request forgery
5 months ago
A vulnerability was found in Johan Ström Background Control Plugin up to 1.0.5 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2025-22784. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-22793 | Bold Pagos en Linea Plugin up to 3.1.0 on WordPress cross site scripting
5 months ago
A vulnerability was found in Bold Pagos en Linea Plugin up to 3.1.0 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-22793. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-50953 | Xinje XL5E-16T 3.7.2a Modbus Message denial of service
5 months ago
A vulnerability, which was classified as problematic, was found in Xinje XL5E-16T 3.7.2a. This affects an unknown part of the component Modbus Message Handler. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2024-50953. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2025-22797 | Oğulcan Özügenç Gallery and Lightbox Plugin up to 1.0.14 on WordPress cross site scripting
5 months ago
A vulnerability has been found in Oğulcan Özügenç Gallery and Lightbox Plugin up to 1.0.14 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-22797. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-22781 | Nativery Developer Nativery Plugin up to 0.1.6 on WordPress cross site scripting
5 months ago
A vulnerability, which was classified as problematic, has been found in Nativery Developer Nativery Plugin up to 0.1.6 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-22781. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-22787 | bPlugins Button Block Plugin up to 1.1.5 on WordPress authorization
5 months ago
A vulnerability classified as problematic was found in bPlugins Button Block Plugin up to 1.1.5 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to missing authorization.
This vulnerability is known as CVE-2025-22787. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-52005 | Git up to 2.48.1 ANSI Escape Sequence escape output
5 months ago
A vulnerability classified as critical has been found in Git up to 2.48.1. Affected is an unknown function of the component ANSI Escape Sequence Handler. The manipulation leads to escaping of output.
This vulnerability is traded as CVE-2024-52005. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-57025 | TOTOLINK X5000R 9.1.0cu.2350_B20230313 setWiFiScheduleCfg desc os command injection
5 months ago
A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2350_B20230313. It has been declared as critical. This vulnerability affects the function setWiFiScheduleCfg. The manipulation of the argument desc leads to os command injection.
This vulnerability was named CVE-2024-57025. The attack can be initiated remotely. There is no exploit available.
vuldb.com