Aggregator
Smashing Security podcast #401: Hacks on the high seas, and how your home can be stolen under your nose
4 months 3 weeks ago
Skip to content
Trend Micro and CISA Secure-By-Design Pledge
4 months 3 weeks ago
Trend’s support reaffirms dedication to safeguarding products and customers
派早报:微信开始测试「用系统电话接听」、微软全面推送 24H2 更新等
4 months 3 weeks ago
你可能错过的新鲜事微信开始测试「用系统电话接听」近期更新的 iOS 版微信 8.0.55 和 8.0.56 版本开始以更大范围测试「语音和视频通讯用系统电话接听」功能。开启该功能后,微信电话会以灵
Top 10 rankings shake up in November | Red Canary Threat Intelligence
4 months 3 weeks ago
Red Canary
Orange County USA Man Sentenced to Over Six Years for Drug Trafficking and Unlawful Firearm Sales on the Dark Web
4 months 3 weeks ago
Orange County USA Man Sentenced to Over Six Years for Drug Trafficking and Unlawful Firearm Sales on the Dark Web
Dark Web Informer - Cyber Threat Intelligence
Doti AI Launches Platform to Securely Find Enterprise Data
4 months 3 weeks ago
The AI-powered work platform helps organizations securely identify and access internal enterprise data as part of business processes and workflows.
Fahmida Y. Rashid
Daily Dose of Dark Web Informer - January 22nd, 2025
4 months 3 weeks ago
This daily article is intended to make it easier for those who want to stay updated with my regular Dark Web Informer and X/Twitter posts.
Dark Web Informer - Cyber Threat Intelligence
CVE-2023-7072 | Post Grid Combo Plugin up to 2.2.68 on WordPress API Endpoint get_posts information disclosure
4 months 3 weeks ago
A vulnerability was found in Post Grid Combo Plugin up to 2.2.68 on WordPress. It has been classified as problematic. Affected is the function get_posts of the component API Endpoint. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2023-7072. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-2107 | Blossom Spa Plugin up to 1.3.4 on WordPress information disclosure
4 months 3 weeks ago
A vulnerability was found in Blossom Spa Plugin up to 1.3.4 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2024-2107. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-2406 | Gacjie Server up to 1.0 Upload.php index file unrestricted upload
4 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Gacjie Server up to 1.0. This affects the function index of the file /app/admin/controller/Upload.php. The manipulation of the argument file leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2024-2406. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2022-34321 | Apache Pulsar up to 2.10.5/2.11.2/3.0.1/3.1.0 /proxy-stats missing authentication
4 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Apache Pulsar up to 2.10.5/2.11.2/3.0.1/3.1.0. Affected is an unknown function of the file /proxy-stats. The manipulation leads to missing authentication.
This vulnerability is traded as CVE-2022-34321. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-27135 | Apache Pulsar up to 2.10.5/2.11.3/3.0.2/3.1.2/3.2.0 Function Worker dynamically-managed code resources
4 months 3 weeks ago
A vulnerability was found in Apache Pulsar up to 2.10.5/2.11.3/3.0.2/3.1.2/3.2.0 and classified as critical. Affected by this issue is some unknown functionality of the component Function Worker. The manipulation leads to dynamically-managed code resources.
This vulnerability is handled as CVE-2024-27135. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-24101 | code-projects Scholars Tracking System 1.0 Eligibility Information Update sql injection
4 months 3 weeks ago
A vulnerability classified as critical has been found in code-projects Scholars Tracking System 1.0. This affects an unknown part of the component Eligibility Information Update. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-24101. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2023-28517 | IBM Sterling Partner Engagement Manager 6.1.2/6.2.0/6.2.2 Web UI cross site scripting (XFDB-250421)
4 months 3 weeks ago
A vulnerability was found in IBM Sterling Partner Engagement Manager 6.1.2/6.2.0/6.2.2. It has been classified as problematic. This affects an unknown part of the component Web UI. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2023-28517. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-28369 | Brother iPrint&Scan up to 6.11.2 on Android access control
4 months 3 weeks ago
A vulnerability classified as critical has been found in Brother iPrint&Scan up to 6.11.2 on Android. Affected is an unknown function. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2023-28369. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-22084 | Oracle MySQL Server up to 5.7.43/8.0.34/8.1.0 InnoDB denial of service
4 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Oracle MySQL Server up to 5.7.43/8.0.34/8.1.0. Affected is an unknown function of the component InnoDB. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2023-22084. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-1390 | Paid Membership Subscriptions Plugin up to 2.11.1 on WordPress creating_pricing_table_page authorization
4 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Paid Membership Subscriptions Plugin up to 2.11.1 on WordPress. This affects the function creating_pricing_table_page. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2024-1390. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2022-42443 | IBM Trusteer iOS SDK/Trusteer Android SDK up to 5.6 unrestricted upload (XFDB-238535)
4 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in IBM Trusteer iOS SDK and Trusteer Android SDK up to 5.6. Affected by this issue is some unknown functionality. The manipulation leads to unrestricted upload.
This vulnerability is handled as CVE-2022-42443. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-6749 | zephyrproject-rtos Zephyr up to 3.5 Settings Shell stack-based overflow (GHSA-757h-rw37-66hw)
4 months 3 weeks ago
A vulnerability, which was classified as critical, was found in zephyrproject-rtos Zephyr up to 3.5. Affected is an unknown function of the component Settings Shell. The manipulation leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2023-6749. Local access is required to approach this attack. There is no exploit available.
vuldb.com