Aggregator
2024hvv | 16套.NET系统漏洞威胁情报(08.02更新)
3 months ago
推荐 | 红蓝对抗必备的6个宝藏知识库
3 months ago
Cybersecurity Compass: An Integrated Cyber Defense Strategy
3 months ago
Explore how the Cybersecurity Compass can guide various security professionals' and stakeholders' decision-making before, during, and after a breach.
Juan Pablo Castro
Attacks on Bytecode Interpreters Conceal Malicious Injection Activity
3 months ago
By injecting malicious bytecode into interpreters for VBScript, Python, and Lua, researchers found they can circumvent malicious code detection.
Robert Lemos, Contributing Writer
More Legal Records Stolen in 2023 Than Previous 5 Years Combined
3 months ago
Law firms make the perfect target for extortion, so it's no wonder that ransomware attackers target them and demand multimillion dollar ransoms.
Nate Nelson, Contributing Writer
'Sitting Ducks' Attacks Create Hijacking Threat for Domain Name Owners
3 months ago
Researchers say the attacks are easy to perform, difficult to contact, nearly unrecognizable, and "entirely preventable."
Dark Reading Staff
Twilio kills off Authy for desktop, forcibly logs out all users
3 months ago
Twilio has finally killed off its Authy for Desktop application, forcibly logging users out of the desktop application. [...]
Lawrence Abrams
Protect your mini-me—How to prevent child identity theft
3 months ago
Most parents work hard thinking about their little one’s future ahead—imagining it bright and full of possibilities, while doing all they can to protect it. But there may be identity thieves snooping around, looking to target your child and mess with that future before they even know what a credit score is.
The post Protect your mini-me—How to prevent child identity theft appeared first on Security Boulevard.
Avast Blog
CVE-2024-7029 | AVTECH AVM1203 up to FullImg-1023-1007-1011-1009 command injection (icsa-24-214-07)
3 months ago
A vulnerability classified as very critical was found in AVTECH AVM1203 up to FullImg-1023-1007-1011-1009. This vulnerability affects unknown code. The manipulation leads to command injection.
This vulnerability was named CVE-2024-7029. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-4353 | Concrete CMS up to 9.3.2 Generate Dashboard Board Name cross site scripting
3 months ago
A vulnerability classified as problematic has been found in Concrete CMS up to 9.3.2. This affects an unknown part of the component Generate Dashboard Board. The manipulation of the argument Name leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-4353. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-41259 | Navidrome 0.52.3 Gravatar Service weak hash
3 months ago
A vulnerability was found in Navidrome 0.52.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Gravatar Service. The manipulation leads to use of weak hash.
This vulnerability is handled as CVE-2024-41259. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-7211 | 1E Platform 8.4.1.229/23.7.1.80/23.11.1.15/24.7 redirect
3 months ago
A vulnerability was found in 1E Platform 8.4.1.229/23.7.1.80/23.11.1.15/24.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to open redirect.
This vulnerability is known as CVE-2024-7211. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-41260 | netbird 0.28.4 Initialization encrypt predictable state
3 months ago
A vulnerability was found in netbird 0.28.4. It has been classified as problematic. Affected is the function encrypt of the component Initialization Handler. The manipulation leads to predictable from observable state.
This vulnerability is traded as CVE-2024-41260. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-39633 | IdeaBox PowerPack for Beaver Builder Plugin up to 2.33.0 on WordPress privileges management
3 months ago
A vulnerability was found in IdeaBox PowerPack for Beaver Builder Plugin up to 2.33.0 on WordPress and classified as critical. This issue affects some unknown processing. The manipulation leads to improper privilege management.
The identification of this vulnerability is CVE-2024-39633. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-6040 | parisneo lollms-webui up to 9.8 lollms_binding_infos client_id cross-site request forgery
3 months ago
A vulnerability has been found in parisneo lollms-webui up to 9.8 and classified as problematic. This vulnerability affects the function lollms_binding_infos. The manipulation of the argument client_id leads to cross-site request forgery.
This vulnerability was named CVE-2024-6040. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-41264 | Casdoor 1.636.0 ssh.InsecureIgnoreHostKey information disclosure
3 months ago
A vulnerability, which was classified as problematic, was found in Casdoor 1.636.0. This affects the function ssh.InsecureIgnoreHostKey. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-41264. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2024-41265 | Cortex 0.42.1 TLS Certificate Verification makeOperatorRequest information disclosure
3 months ago
A vulnerability, which was classified as problematic, has been found in Cortex 0.42.1. Affected by this issue is the function makeOperatorRequest of the component TLS Certificate Verification. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2024-41265. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2024-41962 | Yonle bostr up to 3.0.9 authorized_keys improper authorization (GHSA-5cf7-cxrf-mq73)
3 months ago
A vulnerability classified as critical was found in Yonle bostr up to 3.0.9. Affected by this vulnerability is an unknown functionality. The manipulation of the argument authorized_keys leads to improper authorization.
This vulnerability is known as CVE-2024-41962. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-23600 | Ping Identity OPENIDM up to 7.5.0 Query Search Result information disclosure
3 months ago
A vulnerability classified as problematic has been found in Ping Identity OPENIDM up to 7.5.0. Affected is an unknown function of the component Query Search Result Handler. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-23600. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com