Aggregator
NIS2 Compliance Puts Strain on Business Budgets
10 months 3 weeks ago
A Veeam report found that businesses are prioritizing NIS2 compliance, with 95% of applicable firms diverting funds from other areas of the business
Researchers Uncover Vulnerabilities in Open-Source AI and ML Models
10 months 3 weeks ago
A little over three dozen security vulnerabilities have been disclosed in various open-source artificial intelligence (AI) and machine learning (ML) models, some of which could lead to remote code execution and information theft.
The flaws, identified in tools like ChuanhuChatGPT, Lunary, and LocalAI, have been reported as part of Protect AI's Huntr bug bounty platform.
The most severe of the
The Hacker News
CVE-2024-49646 | ioannup Code Generate Plugin up to 1.0 on WordPress cross site scripting
10 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in ioannup Code Generate Plugin up to 1.0 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-49646. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-49648 | rafasashi SVG Captcha Plugin up to 1.0.11 on WordPress cross site scripting
10 months 3 weeks ago
A vulnerability classified as problematic was found in rafasashi SVG Captcha Plugin up to 1.0.11 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-49648. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-49650 | xarbo BuddyPress Greeting Message Plugin up to 1.0.3 on WordPress cross site scripting
10 months 3 weeks ago
A vulnerability classified as problematic has been found in xarbo BuddyPress Greeting Message Plugin up to 1.0.3 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-49650. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-49647 | Carl Alberto Simple Custom Admin Plugin up to 1.2 on WordPress cross site scripting
10 months 3 weeks ago
A vulnerability was found in Carl Alberto Simple Custom Admin Plugin up to 1.2 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-49647. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-49645 | Ilias Gomatos Affiliate Platform Plugin up to 1.4.8 on WordPress cross site scripting
10 months 3 weeks ago
A vulnerability was found in Ilias Gomatos Affiliate Platform Plugin up to 1.4.8 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-49645. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-49643 | Abdullah Irfan Whitelist Plugin up to 3.5 on WordPress cross site scripting
10 months 3 weeks ago
A vulnerability was found in Abdullah Irfan Whitelist Plugin up to 3.5 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-49643. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-49641 | Tidaweb Tida URL Screenshot Plugin up to 1.0 on WordPress cross site scripting
10 months 3 weeks ago
A vulnerability was found in Tidaweb Tida URL Screenshot Plugin up to 1.0 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-49641. The attack may be launched remotely. There is no exploit available.
vuldb.com
Turning an Elecrow Pi Terminal into a Standalone SDR Radio with an RTL-SDR Blog V4
10 months 3 weeks ago
October 29, 2024Over on
CVE-2024-10474 | Mozilla Focus up to 131 on iOS access control
10 months 3 weeks ago
A vulnerability has been found in Mozilla Focus up to 131 on iOS and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2024-10474. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-10468 | Mozilla Firefox up to 131 IndexedDB race condition
10 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Mozilla Firefox up to 131. This issue affects some unknown processing of the component IndexedDB. The manipulation leads to race condition.
The identification of this vulnerability is CVE-2024-10468. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-10468 | Mozilla Thunderbird up to 131 IndexedDB race condition
10 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Mozilla Thunderbird up to 131. Affected is an unknown function of the component IndexedDB. The manipulation leads to race condition.
This vulnerability is traded as CVE-2024-10468. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-49678 | Jinwen js paper Plugin up to 2.5.7 on WordPress cross site scripting
10 months 3 weeks ago
A vulnerability classified as problematic was found in Jinwen js paper Plugin up to 2.5.7 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-49678. The attack can be initiated remotely. There is no exploit available.
vuldb.com
Phishers reach targets via Eventbrite services
10 months 3 weeks ago
Crooks are leveraging the event management and ticketing website Eventbrite to deliver their phishing emails to potential targets. “Since July, these attacks have increased 25% week over week, resulting in a total growth rate of 900%,” Perception Point researchers say. The phishing emails impersonate legitimate companies The phishing emails look like they are coming from Eventbrite because they are, but their content is crafted to impersonate legitimate businesses such as NLB Group (financial institution), EnergyAustralia … More →
The post Phishers reach targets via Eventbrite services appeared first on Help Net Security.
Zeljka Zorz
CVE-2024-49660 | Campus Explorer Widget Plugin up to 1.4 on WordPress cross site scripting
10 months 3 weeks ago
A vulnerability classified as problematic has been found in Campus Explorer Widget Plugin up to 1.4 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-49660. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-49672 | Gifford Cheung, Brian Watanabe, Chongsun Ahn Google Docs RSVP Plugin up to 2.0.1 on WordPress cross-site request forgery
10 months 3 weeks ago
A vulnerability was found in Gifford Cheung, Brian Watanabe, Chongsun Ahn Google Docs RSVP Plugin up to 2.0.1 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2024-49672. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-49662 | Webgensis Simple Load More Plugin up to 1.0 on WordPress cross site scripting
10 months 3 weeks ago
A vulnerability was found in Webgensis Simple Load More Plugin up to 1.0 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-49662. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-49656 | Abdullah Irfan DocumentPress Plugin up to 2.1 on WordPress cross site scripting
10 months 3 weeks ago
A vulnerability was found in Abdullah Irfan DocumentPress Plugin up to 2.1 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-49656. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com