Aggregator
Safepay
9 months ago
cohenido
Behind The Scenes: Yarix Approach to Mobile Security
9 months ago
Behind The Scenes: Yarix Approach to Mobile Security
New Android spyware found on phone seized by Russian FSB
9 months ago
New Android spyware found on phone seized by Russian FSB
CVE-2024-10961 | Social Login Plugin up to 5.9.0 on WordPress improper authentication
9 months ago
A vulnerability was found in Social Login Plugin up to 5.9.0 on WordPress. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper authentication.
This vulnerability is known as CVE-2024-10961. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-51114 | Beijing Digital China Yunke Information Technology 7.2.6.120 customizable.php command injection
9 months ago
A vulnerability classified as critical was found in Beijing Digital China Yunke Information Technology 7.2.6.120. This vulnerability affects unknown code of the file code/function/dpi/web_auth/customizable.php. The manipulation leads to command injection.
This vulnerability was named CVE-2024-51114. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-40744 | tassos Convert Forms Component 1.0.0-4.4.7 on Joomla unrestricted upload
9 months ago
A vulnerability was found in tassos Convert Forms Component 1.0.0-4.4.7 on Joomla. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to unrestricted upload.
This vulnerability is handled as CVE-2024-40744. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-12149 | Devolutions Remote Desktop Manager up to 2024.3.19.0 on Windows Temporary Access Request default permission
9 months ago
A vulnerability was found in Devolutions Remote Desktop Manager up to 2024.3.19.0 on Windows. It has been rated as critical. Affected by this issue is some unknown functionality of the component Temporary Access Request Handler. The manipulation leads to incorrect default permissions.
This vulnerability is handled as CVE-2024-12149. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-12148 | Devolutions Server up to 2024.3.6.0 Reporting Endpoint authorization (DEVO-2024-0017)
9 months ago
A vulnerability classified as critical has been found in Devolutions Server up to 2024.3.6.0. This affects an unknown part of the component Reporting Endpoint. The manipulation leads to incorrect authorization.
This vulnerability is uniquely identified as CVE-2024-12148. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-52676 | itsourcecode Online Discussion Forum 1.0.0 home.php cross site scripting
9 months ago
A vulnerability has been found in itsourcecode Online Discussion Forum 1.0.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /bcc_forum/members/home.php. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-52676. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-11667 | Zyxel ATP/USG FLEX/USG FLEX 50(W)/USG20(W)-VPN up to 5.38 URL path traversal
9 months ago
A vulnerability was found in Zyxel ATP, USG FLEX, USG FLEX 50(W) and USG20(W)-VPN up to 5.38. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component URL Handler. The manipulation leads to path traversal.
This vulnerability is known as CVE-2024-11667. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
AI助力!明文密码泄漏无处遁形【大模型应用实践系列二】
9 months ago
AI助力!明文密码泄漏无处遁形【大模型应用实践系列二】
How did Andy Warhol make himself mysterious?
9 months ago
How did Andy Warhol make himself mysterious?
Deadline Extended: 2 Weeks Left to Compete for $2,500 in the AI Writing Contest
9 months ago
Deadline Extended: 2 Weeks Left to Compete for $2,500 in the AI Writing Contest
How AI and Bitcoin Will Shape the Future of Crypto Markets
9 months ago
How AI and Bitcoin Will Shape the Future of Crypto Markets
疑似俄罗斯APT组织针对他国APT组织的基础设施展开攻击,扩大攻击范围——每周威胁情报动态第203期(11.29-12.05)
9 months ago
APT组织Lazarus 在Rootkit(获取内核权限)攻击中使用了微软的0day漏洞;APT组织Kimsuky利用软件公司产品安装程序进行伪装展开攻击;NoName057(16)组织DDoSia项目持续更新;
Daily Dose of Dark Web Informer - December 5th, 2024
9 months ago
This daily article is intended to make it easier for those who want to stay updated with my regular Dark Web Informer and X/Twitter posts.
Dark Web Informer - Cyber Threat Intelligence
CVE-2024-21158 | Oracle PeopleSoft Enterprise PT PeopleTools 8.59/8.60/8.61 Portal Privilege Escalation
9 months ago
A vulnerability was found in Oracle PeopleSoft Enterprise PT PeopleTools 8.59/8.60/8.61 and classified as critical. Affected by this issue is some unknown functionality of the component Portal. The manipulation leads to Privilege Escalation.
This vulnerability is handled as CVE-2024-21158. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-21167 | Oracle Trading Community up to 12.2.13 Party Search UI improper authorization
9 months ago
A vulnerability was found in Oracle Trading Community up to 12.2.13. It has been classified as critical. Affected is an unknown function of the component Party Search UI. The manipulation leads to improper authorization.
This vulnerability is traded as CVE-2024-21167. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-21168 | Oracle JD Edwards EnterpriseOne Orchestrator up to 9.2.8.2 E1 IOT Orchestrator Security information disclosure
9 months ago
A vulnerability was found in Oracle JD Edwards EnterpriseOne Orchestrator up to 9.2.8.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component E1 IOT Orchestrator Security. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2024-21168. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com