Aggregator
Play
2 months 2 weeks ago
cohenido
Play
2 months 2 weeks ago
cohenido
Play
2 months 2 weeks ago
cohenido
Play
2 months 2 weeks ago
cohenido
Employee arrested for locking Windows admins out of 254 servers in extortion plot
2 months 2 weeks ago
A former core infrastructure engineer at an industrial company headquartered in Somerset County, New Jersey, was arrested after locking Windows admins out of 254 servers in a failed extortion plot targeting his employer. [...]
Sergiu Gatlan
US offers $2.5 million reward for hacker linked to Angler Exploit Kit
2 months 2 weeks ago
The U.S. Department of State and the Secret Service have announced a reward of $2,500,000 for information leading to Belarusian national Volodymyr Kadariya (Владимир Кадария) for cybercrime activities. [...]
Bill Toulas
U.S. CISA adds Google Chromium V8 bug to its Known Exploited Vulnerabilities catalog
2 months 2 weeks ago
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 bug to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Google Chromium V8 Inappropriate Implementation Vulnerability CVE-2024-38856 (CVSS score of 8.8) to its Known Exploited Vulnerabilities (KEV) catalog. This week Google released a security update to address the Chrome […]
Pierluigi Paganini
U.S. CISA adds Google Chromium V8 bug to its Known Exploited Vulnerabilities catalog
2 months 2 weeks ago
U.S. CISA adds Google Chromium V8 bug to its Known Exploited Vulnerabilities catalogU.S. Cyber
CCTV Zero-Day Exposes Critical Infrastructure to Mirai Botnet
2 months 2 weeks ago
CISA warned about the RCE zero-day vulnerability in AVTECH IP cameras in early August, and now vulnerable systems are being used to spread malware.
Becky Bracken, Senior Editor, Dark Reading
CVE-2024-42934 | openipmi IPMI Simulator improper authorization
2 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in openipmi. Affected by this issue is some unknown functionality of the component IPMI Simulator. The manipulation leads to improper authorization.
This vulnerability is handled as CVE-2024-42934. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2024-45048 | PHPOffice PhpSpreadsheet up to 2.2.0 xml external entity reference
2 months 2 weeks ago
A vulnerability classified as problematic was found in PHPOffice PhpSpreadsheet up to 2.2.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to xml external entity reference.
This vulnerability is known as CVE-2024-45048. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45046 | PHPOffice PhpSpreadsheet up to 2.0.x cross site scripting
2 months 2 weeks ago
A vulnerability classified as problematic has been found in PHPOffice PhpSpreadsheet up to 2.0.x. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-45046. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-44761 | EQ Enterprise Management System up to 1.x Requests path traversal
2 months 2 weeks ago
A vulnerability was found in EQ Enterprise Management System up to 1.x. It has been rated as critical. This issue affects some unknown processing of the component Requests Handler. The manipulation leads to path traversal.
The identification of this vulnerability is CVE-2024-44761. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42793 | Kashipara Music Management System 1.0 ajax.php cross-site request forgery
2 months 2 weeks ago
A vulnerability was found in Kashipara Music Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /music/ajax.php?action=save_user. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2024-42793. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-43805 | Jupyterlab cross site scripting (GHSA-9q39-rmj3-p4r2)
2 months 2 weeks ago
A vulnerability was found in Jupyterlab. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-43805. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45054 | Hwameistor up to 0.14.5 information disclosure (ID 1457)
2 months 2 weeks ago
A vulnerability was found in Hwameistor up to 0.14.5 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2024-45054. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45059 | portabilis i-educar up to 2.9 GET Parameter sql injection
2 months 2 weeks ago
A vulnerability has been found in portabilis i-educar up to 2.9 and classified as critical. Affected by this vulnerability is an unknown functionality of the component GET Parameter Handler. The manipulation leads to sql injection.
This vulnerability is known as CVE-2024-45059. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-34195 | TOTOLINK AC1200 A3002R 1.1.1-B20200824 Boa Server formWlanRedirect buffer overflow
2 months 2 weeks ago
A vulnerability, which was classified as critical, was found in TOTOLINK AC1200 A3002R 1.1.1-B20200824. Affected is the function formWlanRedirect of the component Boa Server. The manipulation leads to buffer overflow.
This vulnerability is traded as CVE-2024-34195. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-44760 | Shenzhou News Union Enterprise Management System up to 5.0/18.8 /servlet/SnoopServlet information disclosure
2 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Shenzhou News Union Enterprise Management System up to 5.0/18.8. This issue affects some unknown processing of the file /servlet/SnoopServlet. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2024-44760. The attack needs to be done within the local network. There is no exploit available.
vuldb.com