Aggregator
JVN: Rockwell Automation製品における複数の脆弱性
7 months 3 weeks ago
Rockwell Automationが提供する製品には、複数の脆弱性が存在します。
Backups & DRP in the ransomware era
7 months 3 weeks ago
In today’s digital landscape, the threat of ransomware has forced organi
Israel Ministry of National Security Hacked by Iranian Threat Group Handala
7 months 3 weeks ago
cohenido
The TechBeat: TikTok’s Uncertain Future: Why Creators Are Turning to a US-Based Alternative (1/29/2025)
7 months 3 weeks ago
Monti
7 months 3 weeks ago
cohenido
Monti
7 months 3 weeks ago
cohenido
Под маской пентестера: ботнет Aquabot нашел хитрый путь к корпоративным сетям
7 months 3 weeks ago
Потомок Mirai переродился в телефонных сетях Mitel.
Monti
7 months 3 weeks ago
cohenido
CVE-2025-23362 | Rodrigue EXIF Viewer Classic 2.3.2/2.4.0 EXIF Meta Data cross site scripting
7 months 3 weeks ago
A vulnerability has been found in Rodrigue EXIF Viewer Classic 2.3.2/2.4.0 and classified as problematic. This vulnerability affects unknown code of the component EXIF Meta Data Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-23362. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-11932 | Rockwell Automation DataMosaix Private Cloud 7.09 path traversal (icsa-25-028-05)
7 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Rockwell Automation DataMosaix Private Cloud 7.09. This affects an unknown part. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2024-11932. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-57519 | Open5GS 2.7.2 Subscription lib/dbi/subscription.c ogs_dbi_auth_info denial of service (Issue 3635)
7 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Open5GS 2.7.2. Affected by this issue is the function ogs_dbi_auth_info of the file lib/dbi/subscription.c of the component Subscription Handler. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2024-57519. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-27068 | Sitecore Experience Platform up to 10.2 ValidationResult.aspx deserialization
7 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Sitecore Experience Platform up to 10.2. This issue affects some unknown processing of the file ValidationResult.aspx. The manipulation leads to deserialization.
The identification of this vulnerability is CVE-2023-27068. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-26595 | Cybozu Garoon up to 5.9.2 Message denial of service
7 months 3 weeks ago
A vulnerability has been found in Cybozu Garoon up to 5.9.2 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Message Handler. The manipulation leads to denial of service.
This vulnerability is known as CVE-2023-26595. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-26267 | Liferay Portal/DXP Response Header Liferay-Portal insecure default initialization of resource
7 months 3 weeks ago
A vulnerability was found in Liferay Portal and DXP and classified as problematic. This issue affects some unknown processing of the component Response Header Handler. The manipulation of the argument Liferay-Portal leads to insecure default initialization of resource.
The identification of this vulnerability is CVE-2024-26267. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-26270 | Liferay Portal/DXP Account Settings Page insertion of sensitive information into sent data
7 months 3 weeks ago
A vulnerability was found in Liferay Portal and DXP. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Account Settings Page. The manipulation leads to insertion of sensitive information into sent data.
This vulnerability is known as CVE-2024-26270. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-26268 | Liferay Portal/DXP information exposure
7 months 3 weeks ago
A vulnerability was found in Liferay Portal and DXP. It has been classified as problematic. This affects an unknown part. The manipulation leads to information exposure through discrepancy.
This vulnerability is uniquely identified as CVE-2024-26268. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-26265 | Liferay Portal/DXP Image Uploader Module resource consumption
7 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Liferay Portal and DXP. Affected by this issue is some unknown functionality of the component Image Uploader Module. The manipulation leads to resource consumption.
This vulnerability is handled as CVE-2024-26265. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-12749 | Competition Form Plugin up to 2.0 on WordPress cross site scripting
7 months 3 weeks ago
A vulnerability classified as problematic was found in Competition Form Plugin up to 2.0 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-12749. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-0804 | flowdee ClickWhale up to 2.4.1 on WordPress Link Page cross site scripting
7 months 3 weeks ago
A vulnerability classified as problematic has been found in flowdee ClickWhale up to 2.4.1 on WordPress. Affected is an unknown function of the component Link Page. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-0804. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com