Aggregator
NightSpire
17 hours 25 minutes ago
cohenido
CVE-2022-23409 | Logs Plugin up to 3.0.3 on Craft CMS Controller.php actionStream information disclosure (ID 165706 / EDB-52241)
17 hours 27 minutes ago
A vulnerability, which was classified as problematic, has been found in Logs Plugin up to 3.0.3 on Craft CMS. Affected by this issue is the function actionStream of the file Controller.php. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2022-23409. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-51683 | Scott Paterson Easy PayPal & Stripe Buy Now Button Plugin up to 1.8.1 on WordPress cross-site request forgery
17 hours 34 minutes ago
A vulnerability was found in Scott Paterson Easy PayPal & Stripe Buy Now Button Plugin up to 1.8.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2023-51683. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-52047 | DedeCMS 5.7.112 File Manager cross-site request forgery
17 hours 34 minutes ago
A vulnerability has been found in DedeCMS 5.7.112 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component File Manager. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2023-52047. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-1680 | Premium Addons for Elementor Plugin up to 4.10.21 on WordPress cross site scripting (ID 3041548)
17 hours 34 minutes ago
A vulnerability, which was classified as problematic, was found in Premium Addons for Elementor Plugin up to 4.10.21 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-1680. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-1847 | Dassault Systèmes eDrawings up to 2023/2024 File out-of-bounds write
17 hours 34 minutes ago
A vulnerability classified as critical has been found in Dassault Systèmes eDrawings up to 2023/2024. This affects an unknown part of the component File Handler. The manipulation leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2024-1847. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-27189 | WP Social Widget Plugin up to 2.2.5 on WordPress Shortcode cross site scripting
17 hours 34 minutes ago
A vulnerability has been found in WP Social Widget Plugin up to 2.2.5 on WordPress and classified as problematic. This vulnerability affects unknown code of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-27189. The attack can be initiated remotely. There is no exploit available.
vuldb.com
Unlock the Power of Financial Quantification of Cyber Risk
17 hours 37 minutes ago
In today's complex threat landscape, gut feelings and disparate risk scores are no longer sufficient for effective cyber risk management. Organizations need concrete, data-driven insights to make informed decisions, prioritize security investments, and ultimately, protect their bottom line. This is where cyber risk quantification (CRQ) steps in, offering a powerful lens through which to view and manage cyber threats. By translating cyber risks into financial terms, CRQ delivers invaluable cyber risk insights that resonate across all levels of an organization, from the security analyst to the boardroom.
The post Unlock the Power of Financial Quantification of Cyber Risk appeared first on Security Boulevard.
Maahnoor Siddiqui
Erlang/OTP SSH 高危漏洞 CVE-2025-32433:无需认证即可远程执行代码
17 hours 40 minutes ago
安全客
【长亭珂兰寺 伙伴5期结业报告】四个月磨一剑,探江湖再启程!
17 hours 40 minutes ago
又一期,结业啦
CVE-2024-0614 | Events Manager Plugin up to 6.4.6.4 on WordPress Setting cross site scripting (ID 3042128)
17 hours 43 minutes ago
A vulnerability was found in Events Manager Plugin up to 6.4.6.4 on WordPress and classified as problematic. This issue affects some unknown processing of the component Setting Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-0614. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-1977 | Restaurant Solutions Plugin 1.0.0 on WordPress cross site scripting
17 hours 43 minutes ago
A vulnerability was found in Restaurant Solutions Plugin 1.0.0 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-1977. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-1976 | Marketing Optimizer Plugin up to 20200925 on WordPress cross-site request forgery
17 hours 43 minutes ago
A vulnerability was found in Marketing Optimizer Plugin up to 20200925 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2024-1976. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-21798 | Elecom WRC-1167GS2-B cross site scripting
17 hours 43 minutes ago
A vulnerability, which was classified as problematic, has been found in Elecom WRC-1167GS2-B, WRC-1167GS2H-B, WRC-2533GS2-B, WRC-2533GS2-W and WRC-2533GS2V-B. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-21798. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-1938 | Google Chrome up to 122.0.6261.57 V8 type confusion (Issue 324596)
17 hours 43 minutes ago
A vulnerability, which was classified as critical, has been found in Google Chrome. This issue affects some unknown processing of the component V8. The manipulation leads to type confusion.
The identification of this vulnerability is CVE-2024-1938. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-1939 | Google Chrome up to 122.0.6261.57 V8 type confusion (Issue 323694)
17 hours 43 minutes ago
A vulnerability, which was classified as critical, was found in Google Chrome. Affected is an unknown function of the component V8. The manipulation leads to type confusion.
This vulnerability is traded as CVE-2024-1939. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2012-2910 | SiliSoftware phpThumb 1.7.11 Title cross site scripting (EDB-37207 / XFDB-75709)
17 hours 50 minutes ago
A vulnerability was found in SiliSoftware phpThumb 1.7.11. It has been classified as problematic. Affected is the function phpThumb. The manipulation of the argument Title leads to cross site scripting.
This vulnerability is traded as CVE-2012-2910. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
1 BTC за взлом: биткоин бросает вызов квантовым хакерам
17 hours 51 minutes ago
Необычный конкурс готовит людей ко Дню Q.
警惕!西门子 TeleControl Server Basic 66 个 SQL 注入漏洞,或致权限失控与数据危机
17 hours 52 minutes ago
安全客