Aggregator
CVE-2024-37940 | Seraphinite Accelerator Full Plugin/Accelerator Premium Plugin cross-site request forgery
1 year 1 month ago
A vulnerability was found in Seraphinite Accelerator Full Plugin and Accelerator Premium Plugin up to 2.21.13 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2024-37940. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-37939 | VolThemes Patricia Lite Plugin up to 1.2.3 on WordPress cross-site request forgery
1 year 1 month ago
A vulnerability, which was classified as problematic, has been found in VolThemes Patricia Lite Plugin up to 1.2.3 on WordPress. This issue affects some unknown processing. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2024-37939. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-37938 | MyThemeShop SociallyViral Plugin up to 1.0.10 on WordPress cross-site request forgery
1 year 1 month ago
A vulnerability has been found in MyThemeShop SociallyViral Plugin up to 1.0.10 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2024-37938. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-35773 | WPJohnny Comment Reply Email Plugin up to 1.3 on WordPress cross-site request forgery
1 year 1 month ago
A vulnerability was found in WPJohnny Comment Reply Email Plugin up to 1.3 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2024-35773. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-37213 | Ali2Woo Lite Plugin up to 3.3.9 on WordPress cross-site request forgery
1 year 1 month ago
A vulnerability was found in Ali2Woo Lite Plugin up to 3.3.9 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2024-37213. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-37941 | Internal Link Juicer Plugin up to 2.24.3 on WordPress cross-site request forgery
1 year 1 month ago
A vulnerability was found in Internal Link Juicer Plugin up to 2.24.3 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2024-37941. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-38717 | Booking Ultra Pro Plugin up to 1.1.13 on WordPress path traversal
1 year 1 month ago
A vulnerability was found in Booking Ultra Pro Plugin up to 1.1.13 on WordPress. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to path traversal.
This vulnerability is handled as CVE-2024-38717. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-40690 | IBM InfoSphere Server 11.7 Web UI intended cross site scripting (XFDB-297720)
1 year 1 month ago
A vulnerability was found in IBM InfoSphere Server 11.7. It has been declared as problematic. Affected by this vulnerability is the function intended of the component Web UI. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-40690. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Why States Will Need to Step Up Cyber Help for Healthcare
1 year 1 month ago
As uncertainty mounts about the range of cyber resources the federal government will continue to offer healthcare and other critical infrastructure sectors during the Trump administration, states will need to step up their support, said Mike Hamilton, field CISO of cybersecurity firm Lumifi Cyber.
Second GitHub Actions Supply Chain Attack Discovered
1 year 1 month ago
Malicious Code Injected in reviewdog Just Hours Before tj-actions Backdoored
Just days after researchers discovered an attack that subverted a widely used tool for software development platform GitHub, they discovered a second, prior attack, as part of what one expert said may be "a chain of supply chain attacks eventually leading to a specific high-value target."
Just days after researchers discovered an attack that subverted a widely used tool for software development platform GitHub, they discovered a second, prior attack, as part of what one expert said may be "a chain of supply chain attacks eventually leading to a specific high-value target."
Google Purchases Wiz in $32B Deal to Boost Cloud Security
1 year 1 month ago
Largest Security Deal Ever Aims to Boost AI-Driven Multi-Cloud Solutions
Google Cloud plans to acquire cloud security leader Wiz for $32 billion, integrating its AI-powered security capabilities to better protect companies across multiple cloud environments. The deal reinforces protections across multi-cloud environments, including AWS, Microsoft Azure and Google Cloud.
Google Cloud plans to acquire cloud security leader Wiz for $32 billion, integrating its AI-powered security capabilities to better protect companies across multiple cloud environments. The deal reinforces protections across multi-cloud environments, including AWS, Microsoft Azure and Google Cloud.
Medical Hallucinations Persist as Clinicians Integrate AI
1 year 1 month ago
Researchers Detail AI's Fabricated Facts in Healthcare, Discuss Solutions
Hallucinations in artificial intelligence foundation models are pushing healthcare professionals and technologists to rethink how practitioners can safely use AI. Hallucinated lab result or an erroneous diagnostic recommendation could lead to harmful interventions or missed treatments.
Hallucinations in artificial intelligence foundation models are pushing healthcare professionals and technologists to rethink how practitioners can safely use AI. Hallucinated lab result or an erroneous diagnostic recommendation could lead to harmful interventions or missed treatments.
UK Official Says Russian Disinfo Blocked in 2024 Election
1 year 1 month ago
Doppelganger Unsuccessfully Attempted to Distort Election, UK Minister Said
A Russian government-directed foreign influence campaign unsuccessfully attempted to disrupt the 2024 U.K. elections, a British security minister told a parliamentary committee. The government identified disinformation networks linked to Russian influence campaign widely tracked as Doppelganger.
A Russian government-directed foreign influence campaign unsuccessfully attempted to disrupt the 2024 U.K. elections, a British security minister told a parliamentary committee. The government identified disinformation networks linked to Russian influence campaign widely tracked as Doppelganger.
Why States Will Need to Step Up Cyber Help for Healthcare
1 year 1 month ago
As uncertainty mounts about the range of cyber resources the federal government will continue to offer healthcare and other critical infrastructure sectors during the Trump administration, states will need to step up their support, said Mike Hamilton, field CISO of cybersecurity firm Lumifi Cyber.
Second GitHub Actions Supply Chain Attack Discovered
1 year 1 month ago
Malicious Code Injected in reviewdog Just Hours Before tj-actions Backdoored
Just days after researchers discovered an attack that subverted a widely used tool for software development platform GitHub, they discovered a second, prior attack, as part of what one expert said may be "a chain of supply chain attacks eventually leading to a specific high-value target."
Just days after researchers discovered an attack that subverted a widely used tool for software development platform GitHub, they discovered a second, prior attack, as part of what one expert said may be "a chain of supply chain attacks eventually leading to a specific high-value target."
Google Purchases Wiz in $32B Deal to Boost Cloud Security
1 year 1 month ago
Largest Security Deal Ever Aims to Boost AI-Driven Multi-Cloud Solutions
Google Cloud plans to acquire cloud security leader Wiz for $32 billion, integrating its AI-powered security capabilities to better protect companies across multiple cloud environments. The deal reinforces protections across multi-cloud environments, including AWS, Microsoft Azure and Google Cloud.
Google Cloud plans to acquire cloud security leader Wiz for $32 billion, integrating its AI-powered security capabilities to better protect companies across multiple cloud environments. The deal reinforces protections across multi-cloud environments, including AWS, Microsoft Azure and Google Cloud.
Medical Hallucinations Persist as Clinicians Integrate AI
1 year 1 month ago
Researchers Detail AI's Fabricated Facts in Healthcare, Discuss Solutions
Hallucinations in artificial intelligence foundation models are pushing healthcare professionals and technologists to rethink how practitioners can safely use AI. Hallucinated lab result or an erroneous diagnostic recommendation could lead to harmful interventions or missed treatments.
Hallucinations in artificial intelligence foundation models are pushing healthcare professionals and technologists to rethink how practitioners can safely use AI. Hallucinated lab result or an erroneous diagnostic recommendation could lead to harmful interventions or missed treatments.
UK Official Says Russian Disinfo Blocked in 2024 Election
1 year 1 month ago
Doppelganger Unsuccessfully Attempted to Distort Election, UK Minister Said
A Russian government-directed foreign influence campaign unsuccessfully attempted to disrupt the 2024 U.K. elections, a British security minister told a parliamentary committee. The government identified disinformation networks linked to Russian influence campaign widely tracked as Doppelganger.
A Russian government-directed foreign influence campaign unsuccessfully attempted to disrupt the 2024 U.K. elections, a British security minister told a parliamentary committee. The government identified disinformation networks linked to Russian influence campaign widely tracked as Doppelganger.
Wireless Airspace Defense Firm Bastille Reveals Top Threats of 2025
1 year 1 month ago