Aggregator
CVE-2024-54216 | NotFound ARForms Plugin up to 6.4.1 on WordPress path traversal
1 year 4 months ago
A vulnerability was found in NotFound ARForms Plugin up to 6.4.1 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to path traversal: '.../...//'.
The identification of this vulnerability is CVE-2024-54216. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-54214 | NotFound Revy Plugin up to 1.18 on WordPress unrestricted upload
1 year 4 months ago
A vulnerability was found in NotFound Revy Plugin up to 1.18 on WordPress. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to unrestricted upload.
This vulnerability was named CVE-2024-54214. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-54212 | Noor Alam Magical Addons for Elementor Plugin up to 1.2.6 on WordPress cross site scripting
1 year 4 months ago
A vulnerability was found in Noor Alam Magical Addons for Elementor Plugin up to 1.2.6 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-54212. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-54205 | Paloma Widget Plugin up to 1.14 on WordPress cross-site request forgery
1 year 4 months ago
A vulnerability was found in Paloma Widget Plugin up to 1.14 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2024-54205. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-53809 | Kiboko Labs Namaste LMS Plugin up to 2.6.4.1 on WordPress cross-site request forgery
1 year 4 months ago
A vulnerability has been found in Kiboko Labs Namaste LMS Plugin up to 2.6.4.1 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2024-53809. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-54750 | Ubiquiti U6-LR 6.6.65 /etc/shadow hard-coded password
1 year 4 months ago
A vulnerability, which was classified as critical, has been found in Ubiquiti U6-LR 6.6.65. This issue affects some unknown processing of the file /etc/shadow. The manipulation leads to use of hard-coded password.
The identification of this vulnerability is CVE-2024-54750. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-54745 | Wavlink WN701AE M01AE_V240305 /etc/shadow hard-coded password
1 year 4 months ago
A vulnerability, which was classified as critical, was found in Wavlink WN701AE M01AE_V240305. Affected is an unknown function of the file /etc/shadow. The manipulation leads to use of hard-coded password.
This vulnerability is traded as CVE-2024-54745. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
每日安全动态推送(24/12/6)
1 year 4 months ago
每日安全动态推送(24/12/6)
SonicWall SMA100 SSLVPN 多个高危漏洞安全风险通告
1 year 4 months ago
SonicWall SMA100 SSLVPN 多个高危漏洞安全风险通告
CVE-2024-54209 | WPFactory Awesome Shortcodes Plugin up to 1.7.2 on WordPress cross site scripting
1 year 4 months ago
A vulnerability classified as problematic was found in WPFactory Awesome Shortcodes Plugin up to 1.7.2 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-54209. The attack can be initiated remotely. There is no exploit available.
vuldb.com
miyako Claims to have Leaked the Data of Akila
1 year 4 months ago
miyako Claims to have Leaked the Data of Akila
Dark Web Informer - Cyber Threat Intelligence
CVE-2024-54211 | Visualmodo Borderless Plugin up to 1.5.8 on WordPress cross site scripting
1 year 4 months ago
A vulnerability classified as problematic has been found in Visualmodo Borderless Plugin up to 1.5.8 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-54211. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-54210 | CodexShaper Advanced Element Bucket Addons for Elementor Plugin cross site scripting
1 year 4 months ago
A vulnerability was found in CodexShaper Advanced Element Bucket Addons for Elementor Plugin up to 1.0.2 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-54210. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-54208 | Joni Halabi Block Controller Plugin up to 1.4.2 on WordPress cross site scripting
1 year 4 months ago
A vulnerability was found in Joni Halabi Block Controller Plugin up to 1.4.2 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-54208. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-12254 | Python Software CPython up to 3.14.0a0 asyncio._SelectorSocketTransport.writelines resource consumption
1 year 4 months ago
A vulnerability was found in Python Software CPython up to 3.14.0a0. It has been classified as problematic. Affected is the function asyncio._SelectorSocketTransport.writelines. The manipulation leads to resource consumption.
This vulnerability is traded as CVE-2024-12254. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-54136 | MacWarrior clipbucket-v5 up to 5.5.1 Revision 199 upload/upload.php deserialization
1 year 4 months ago
A vulnerability was found in MacWarrior clipbucket-v5 up to 5.5.1 Revision 199 and classified as very critical. This issue affects some unknown processing of the file upload/upload.php. The manipulation leads to deserialization.
The identification of this vulnerability is CVE-2024-54136. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-54135 | MacWarrior clipbucket-v5 up to 5.5.1 Revision 199 upload/photo_upload.php decode_key deserialization
1 year 4 months ago
A vulnerability has been found in MacWarrior clipbucket-v5 up to 5.5.1 Revision 199 and classified as very critical. This vulnerability affects the function decode_key of the file upload/photo_upload.php. The manipulation leads to deserialization.
This vulnerability was named CVE-2024-54135. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
普通用户手机上发现间谍软件 Pegasus
1 year 4 months ago
移动安全公司 iVerify 在今年 5 月发布了一个工具,可用于扫描手机是否感染了以色列公司 NSO Group 开发的间谍软件 Pegasus。2,500 名用户扫描设备后发现了 7 起 Pegasus 感染事件。这意味着 Pegasus 的传播范围比以前认为的更为广泛。因为被感染的人是普通用户而不是特定目标。大部分感染都不是发生在近期,其中一次是 2023 年底的 iOS 16.6,另一次发生在 2022 年 11 月的 iOS 15,另外五次发生在 2021 年和 2022 年的 iOS 14 和 15 上。Pegasus 发动的是零点击攻击,感染设备不需要用户互动。
miyako Allegedly Leaked the Data of Beijing Jingsheng Century Technology
1 year 4 months ago
miyako Allegedly Leaked the Data of Beijing Jingsheng Century Technology
Dark Web Informer - Cyber Threat Intelligence