Aggregator
Live Webinar | AI in the Spotlight: Exploring the Future of AppSec Evolution
4 months 4 weeks ago
Cymulate Expands Exposure Management with Cync Secure Deal
4 months 4 weeks ago
Cync Acquisition Bolsters Exposure Validation Through Advanced Offensive Expertise
Cymulate’s acquisition of Cync Secure enhances its ability to bridge vulnerability identification and resolution. The deal integrates Cync offensive capabilities, creating a next-gen exposure prioritization platform to tackle vulnerabilities effectively and address unmet market demands.
Cymulate’s acquisition of Cync Secure enhances its ability to bridge vulnerability identification and resolution. The deal integrates Cync offensive capabilities, creating a next-gen exposure prioritization platform to tackle vulnerabilities effectively and address unmet market demands.
European Court Fines European Commission for Privacy Violation
4 months 4 weeks ago
Transfer of German Man's IP Address Wins Him 400 Euros
European privacy regulation - bane of American technology companies and a favorite cudgel of activists - came to haunt no less an organization than the European Commission, which must pay 400 euros to aggrieved German national Thomas Bindl, peeved that Facebook obtained his IP address.
European privacy regulation - bane of American technology companies and a favorite cudgel of activists - came to haunt no less an organization than the European Commission, which must pay 400 euros to aggrieved German national Thomas Bindl, peeved that Facebook obtained his IP address.
UN Cybercrime Treaty Faces Longs Odds to US Passage
4 months 4 weeks ago
US Senate Unlikely to Ratify Contentious Cybercrime Treaty Amid Mounting Concerns
Experts tell Information Security Media Group that a controversial United Nations cybercrime convention is unlikely to be ratified in the U.S. Senate due to mounting concerns from technology, human rights, and privacy advocates over its potential impact on internet security and privacy protections.
Experts tell Information Security Media Group that a controversial United Nations cybercrime convention is unlikely to be ratified in the U.S. Senate due to mounting concerns from technology, human rights, and privacy advocates over its potential impact on internet security and privacy protections.
White House Launches US Cyber Trust Mark for IoT Devices
4 months 4 weeks ago
Biden Administration Hopes Good Cybersecurity Is Also Good Marketing
The Biden administration Tuesday launched a cybersecurity labeling program for IoT devices aimed to help consumers choose smart devices that offer enhanced protections against hacking. Eligible products include wireless IoT devices such as fitness trackers, smart appliances and garage door openers.
The Biden administration Tuesday launched a cybersecurity labeling program for IoT devices aimed to help consumers choose smart devices that offer enhanced protections against hacking. Eligible products include wireless IoT devices such as fitness trackers, smart appliances and garage door openers.
Information Stealer Masquerades as LDAPNightmare (CVE-2024-49113) PoC Exploit
4 months 4 weeks ago
Our blog entry discusses a fake PoC exploit for LDAPNightmare (CVE-2024-49113) that is being used to distribute information-stealing malware.
Sarah Pearl Camiling
New Release: Tails 6.11
4 months 4 weeks ago
Critical security fixesThe vulnerabilities described below were identified during an externalsecur
Supercharge your vulnerability triage: Our investment in your efficiency
4 months 4 weeks ago
As we step into 2025, many of us are setting resolutions to improve, grow, and achieve more. At Inti
CVE-2024-0326 | Premium Addons for Elementor Plugin up to 4.10.18 on WordPress Event onClick cross site scripting
4 months 4 weeks ago
A vulnerability was found in Premium Addons for Elementor Plugin up to 4.10.18 on WordPress. It has been classified as problematic. This affects an unknown part of the component Event Handler. The manipulation of the argument onClick leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-0326. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-0385 | Categorify Plugin up to 1.0.7.4 on WordPress categorifyAjaxAddCategory authorization
4 months 4 weeks ago
A vulnerability has been found in Categorify Plugin up to 1.0.7.4 on WordPress and classified as critical. This vulnerability affects the function categorifyAjaxAddCategory. The manipulation leads to missing authorization.
This vulnerability was named CVE-2024-0385. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-1398 | Ultimate Bootstrap Elements for Elementor Plugin up to 1.3.6 on WordPress cross site scripting
4 months 4 weeks ago
A vulnerability was found in Ultimate Bootstrap Elements for Elementor Plugin up to 1.3.6 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-1398. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-2149 | CodeAstro Membership Management System 1.0 settings.php currency sql injection
4 months 4 weeks ago
A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file settings.php. The manipulation of the argument currency leads to sql injection.
This vulnerability was named CVE-2024-2149. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-28088 | LangChain up to 0.1.10 Configuration load_chain path path traversal
4 months 4 weeks ago
A vulnerability classified as critical was found in LangChain up to 0.1.10. This vulnerability affects the function load_chain of the component Configuration Handler. The manipulation of the argument path leads to path traversal.
This vulnerability was named CVE-2024-28088. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-0155 | Dell Digital Delivery 3.5.1/3.5.2013/3.5.2015/4.0.41/5.0.82.0 use after free (dsa-2024-033)
4 months 4 weeks ago
A vulnerability was found in Dell Digital Delivery 3.5.1/3.5.2013/3.5.2015/4.0.41/5.0.82.0 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to use after free.
This vulnerability is handled as CVE-2024-0155. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-1285 | Page Builder Sandwich Plugin up to 5.1.0 on WordPress Post authorization
4 months 4 weeks ago
A vulnerability classified as problematic was found in Page Builder Sandwich Plugin up to 5.1.0 on WordPress. Affected by this vulnerability is an unknown functionality of the component Post Handler. The manipulation leads to missing authorization.
This vulnerability is known as CVE-2024-1285. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-1095 | Build & Control Block Patterns Plugin up to 1.3.5.4 on WordPress authorization
4 months 4 weeks ago
A vulnerability, which was classified as critical, was found in Build & Control Block Patterns Plugin up to 1.3.5.4 on WordPress. This affects an unknown part. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2024-1095. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-1478 | Maintenance Mode Plugin up to 2.5.0 on WordPress information disclosure
4 months 4 weeks ago
A vulnerability has been found in Maintenance Mode Plugin up to 2.5.0 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to information disclosure.
This vulnerability was named CVE-2024-1478. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-1731 | Auto Refresh Single Page Plugin up to 1.1 on WordPress code injection
4 months 4 weeks ago
A vulnerability, which was classified as critical, has been found in Auto Refresh Single Page Plugin up to 1.1 on WordPress. This issue affects some unknown processing. The manipulation leads to code injection.
The identification of this vulnerability is CVE-2024-1731. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-1178 | SportsPress Plugin up to 2.7.17 on WordPress Event Permalink Update authorization
4 months 4 weeks ago
A vulnerability was found in SportsPress Plugin up to 2.7.17 on WordPress. It has been classified as problematic. This affects an unknown part of the component Event Permalink Update Handler. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2024-1178. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com