Aggregator
Play
7 months 3 weeks ago
cohenido
CVE-2023-32467 | Dell PowerSwitch Z9664F-ON BIOS prior 1.05.10 initialization (dsa-2023-225)
7 months 3 weeks ago
A vulnerability was found in Dell PowerSwitch Z9664F-ON BIOS and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improper initialization.
This vulnerability is handled as CVE-2023-32467. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-39907 | 1Panel 1.10.9-tls/1.10.10-tls/1.10.11-tls sql injection (GHSA-5grx-v727-qmq6)
7 months 3 weeks ago
A vulnerability classified as critical was found in 1Panel 1.10.9-tls/1.10.10-tls/1.10.11-tls. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection.
This vulnerability is known as CVE-2024-39907. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-39911 | 1Panel up to 1.10.11-lts sql injection (GHSA-7m53-pwp6-v3f5)
7 months 3 weeks ago
A vulnerability, which was classified as critical, was found in 1Panel up to 1.10.11-lts. This affects an unknown part. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-39911. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-40629 | JumpServer up to 3.10.11 path traversal (GHSA-3wgp-q8m7-v33v)
7 months 3 weeks ago
A vulnerability, which was classified as very critical, has been found in JumpServer up to 3.10.11. This issue affects some unknown processing. The manipulation leads to path traversal.
The identification of this vulnerability is CVE-2024-40629. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-40628 | JumpServer up to 3.10.11 path traversal (GHSA-rpf7-g4xh-84v9)
7 months 3 weeks ago
A vulnerability has been found in JumpServer up to 3.10.11 and classified as very critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to path traversal.
This vulnerability is known as CVE-2024-40628. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6898 | SourceCodester Record Management System 1.0 index.php UserName sql injection
7 months 3 weeks ago
A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as critical. This affects an unknown part of the file index.php. The manipulation of the argument UserName leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-6898. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-6940 | DedeCMS 5.7.114 article_template_rand.php code injection
7 months 3 weeks ago
A vulnerability was found in DedeCMS 5.7.114. It has been classified as critical. This affects an unknown part of the file article_template_rand.php. The manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2024-6940. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2023-48362 | Apache Drill up to 1.21.1 XML Format Plugin xml external entity reference (DRILL-8461)
7 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Apache Drill up to 1.21.1. Affected is an unknown function of the component XML Format Plugin. The manipulation leads to xml external entity reference.
This vulnerability is traded as CVE-2023-48362. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41039 | Linux Kernel up to 6.1.99/6.6.40/6.9.9 cs_dsp buffer overflow
7 months 3 weeks ago
A vulnerability classified as critical was found in Linux Kernel up to 6.1.99/6.6.40/6.9.9. Affected by this vulnerability is an unknown functionality of the component cs_dsp. The manipulation leads to buffer overflow.
This vulnerability is known as CVE-2024-41039. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Manufacturing, Industrial Sectors Are Under Siege
7 months 3 weeks ago
Manufacturing and industrial sectors are becoming bigger cyber-targets, and many of the intrusions are coming from China. Those are among the sobering takeaways from a report Tuesday by Ontinue’s Advanced Threat Operations team in its biannual Threat Intelligence Report. The two sectors endured a 105% increase in attacks during the first half of 2024, highlighting..
The post Manufacturing, Industrial Sectors Are Under Siege appeared first on Security Boulevard.
Jon Swartz
Quad7 botnet evolves to more stealthy tactics to evade detection
7 months 3 weeks ago
The Quad7 botnet evolves and targets new SOHO devices, including Axentra media servers, Ruckus wireless routers and Zyxel VPN appliances. The Sekoia TDR team identified additional implants associated with the Quad7 botnet operation. The botnet operators are targeting multiple SOHO devices and VPN appliances, including TP-LINK, Zyxel, Asus, D-Link, and Netgear, exploiting both known and […]
Pierluigi Paganini
CVE-2021-33990 | Liferay Portal 6.2.5 ommand=FileUpload&Type=File&CurrentFolder= absolute path traversal (Exploit 171701 / EDB-51244)
7 months 3 weeks ago
A vulnerability was found in Liferay Portal 6.2.5. It has been declared as problematic. This vulnerability affects unknown code of the file Command=FileUpload&Type=File&CurrentFolder=/. The manipulation leads to path traversal: '/absolute/pathname/here'.
This vulnerability was named CVE-2021-33990. The attack can only be done within the local network. Furthermore, there is an exploit available.
vuldb.com
CVE-2023-32472 | Dell PowerSwitch Z9664F-ON BIOS prior 1.05.10 System Management Mode out-of-bounds (dsa-2023-225)
7 months 3 weeks ago
A vulnerability was found in Dell PowerSwitch Z9664F-ON BIOS. It has been classified as problematic. This affects an unknown part of the component System Management Mode. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2023-32472. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-21993 | NetApp SnapCenter up to 5.0 cleartext storage (ntap-20240705-0007)
7 months 3 weeks ago
A vulnerability was found in NetApp SnapCenter up to 5.0. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cleartext storage of sensitive information.
The identification of this vulnerability is CVE-2024-21993. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-41093 | Silicon Labs Simplicity SDK up to 8.0.0 on 32-bit ARM use after free
7 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Silicon Labs Simplicity SDK up to 8.0.0 on 32-bit ARM. This issue affects some unknown processing. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2023-41093. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2024-31947 | StoneFly Storage Concentrator prior 8.0.4.26 path path traversal
7 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in StoneFly Storage Concentrator. Affected is an unknown function. The manipulation of the argument path leads to path traversal.
This vulnerability is traded as CVE-2024-31947. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-38493 | Broadcom Symantec Privileged Access Management up to 3.4.6/4.1.7 PAM UI Web Interface cross site scripting
7 months 3 weeks ago
A vulnerability classified as problematic was found in Broadcom Symantec Privileged Access Management up to 3.4.6/4.1.7. This vulnerability affects unknown code of the component PAM UI Web Interface. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-38493. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-6325 | Rockwell Automation FactoryTalk System Services 6.40 Policy Manager privileges management
7 months 3 weeks ago
A vulnerability classified as problematic was found in Rockwell Automation FactoryTalk System Services and FactoryTalk Policy Manager 6.40. Affected by this vulnerability is an unknown functionality of the component Policy Manager. The manipulation leads to improper privilege management.
This vulnerability is known as CVE-2024-6325. The attack needs to be approached locally. There is no exploit available.
vuldb.com