Aggregator
CVE-2024-50804 | Micro-star International MSI Center Pro 2.1.37.0 Device_DeviceID.dat.bak permission
1 year 4 months ago
A vulnerability has been found in Micro-star International MSI Center Pro 2.1.37.0 and classified as critical. This vulnerability affects unknown code of the file Device_DeviceID.dat.bak. The manipulation leads to permission issues.
This vulnerability was named CVE-2024-50804. Local access is required to approach this attack. There is no exploit available.
vuldb.com
CVE-2024-52506 | Graylog2 Server up to 6.1.1 Reporting information disclosure
1 year 4 months ago
A vulnerability, which was classified as problematic, was found in Graylog2 Server up to 6.1.1. This affects an unknown part of the component Reporting. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-52506. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52583 | DefinetlyNotAI WesHacks schedule.html code download (93dfb83)
1 year 4 months ago
A vulnerability, which was classified as problematic, has been found in DefinetlyNotAI WesHacks. Affected by this issue is some unknown functionality of the file schedule.html. The manipulation leads to download of code without integrity check.
This vulnerability is handled as CVE-2024-52583. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-48917 | PHPOffice PhpSpreadsheet up to 1.29.3/2.1.2/2.3.1/3.3.x xml external entity reference (GHSA-7cc9-j4mv-vcjp)
1 year 4 months ago
A vulnerability classified as critical was found in PHPOffice PhpSpreadsheet up to 1.29.3/2.1.2/2.3.1/3.3.x. Affected by this vulnerability is an unknown functionality. The manipulation leads to xml external entity reference.
This vulnerability is known as CVE-2024-48917. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52304 | aio-libs aiohttp up to 3.10.10 request smuggling
1 year 4 months ago
A vulnerability classified as problematic has been found in aio-libs aiohttp up to 3.10.10. Affected is an unknown function. The manipulation leads to http request smuggling.
This vulnerability is traded as CVE-2024-52304. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52303 | aio-libs aiohttp up to 3.10.10 release of resource (GHSA-27mf-ghqm-j3j8)
1 year 4 months ago
A vulnerability was found in aio-libs aiohttp up to 3.10.10. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to missing release of resource.
The identification of this vulnerability is CVE-2024-52303. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-51499 | MarkUsProject Markus up to 2.4.7 config/initializers/ update_files unrestricted upload (GHSA-j95p-7936-f75w)
1 year 4 months ago
A vulnerability was found in MarkUsProject Markus up to 2.4.7. It has been declared as critical. This vulnerability affects the function update_files of the file config/initializers/. The manipulation leads to unrestricted upload.
This vulnerability was named CVE-2024-51499. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-51743 | MarkUsProject Markus up to 2.4.7 unrestricted upload (GHSA-hwgg-qvjx-572x)
1 year 4 months ago
A vulnerability was found in MarkUsProject Markus up to 2.4.7. It has been classified as critical. This affects an unknown part. The manipulation leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2024-51743. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2018-18775 | Microstrategy Web 7 Login.asp Msg cross site scripting (ID 150059 / EDB-45755)
1 year 4 months ago
A vulnerability was found in Microstrategy Web 7. It has been declared as problematic. This vulnerability affects unknown code of the file Login.asp. The manipulation of the argument Msg as part of Parameter leads to cross site scripting.
This vulnerability was named CVE-2018-18775. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to replace the affected component with an alternative.
vuldb.com
US space tech giant Maxar discloses employee data breach
1 year 4 months ago
Hackers breached U.S. satellite maker Maxar Space Systems and accessed personal data belonging to its employees, the company informs in a notification to impacted individuals. [...]
Bill Toulas
ASPM vs. CSPM: Key Differences
1 year 4 months ago
With dozens of cybersecurity threats out there, maintaining your company’s security posture is more important than ever. And with so many types of technology to oversee—from cloud infrastructure to AI-generated code—there are just as many ways to manage your security practices.
The post ASPM vs. CSPM: Key Differences appeared first on Security Boulevard.
Legit Security
Palo Alto Networks patches two firewall zero-days used in attacks
1 year 4 months ago
Palo Alto Networks has finally released security updates for an actively exploited zero-day vulnerability in its Next-Generation Firewalls (NGFW). [...]
Sergiu Gatlan
A Threat Actor Likely Leaked the Data of MMI Connect
1 year 4 months ago
A Threat Actor Likely Leaked the Data of MMI Connect
Dark Web Informer
Compliance Automation: How to Get Started and Best Practices
1 year 4 months ago
Managing compliance manually is an uphill battle, especially when regulatory requirements are constantly changing.
The post Compliance Automation: How to Get Started and Best Practices appeared first on Security Boulevard.
Legit Security
Jen Easterly, CISA Director, to Step Down on Inauguration Day
1 year 4 months ago
Other Biden administration appointees at CISA will also submit their resignations on Jan. 20, as the cyber-defense agency prepares for President-elect Trump's new DHS director.
Dark Reading Staff
Recently disclosed VMware vCenter Server bugs are actively exploited in attacks
1 year 4 months ago
Threat actors are actively exploiting two VMware vCenter Server vulnerabilities tracked as CVE-2024-38812 and CVE-2024-38813, Broadcom warns. Broadcom warns that the two VMware vCenter Server vulnerabilities CVE-2024-38812 and CVE-2024-38813 are actively exploited in the wild. “Updated advisory to note that VMware by Broadcom confirmed that exploitation has occurred in the wild for CVE-2024-38812 and CVE-2024-38813.” […]
Pierluigi Paganini
Protecting your organization while using Wi-Fi (ITSAP.80.009)
1 year 4 months ago
Canadian Centre for Cyber Security
A Threat Actor is Allegedly Selling Data of USA Jewels
1 year 4 months ago
A Threat Actor is Allegedly Selling Data of USA Jewels
Dark Web Informer
KCI Aviation Has Been Claimed a Victim to BLACK SUIT Ransomware
1 year 4 months ago
KCI Aviation Has Been Claimed a Victim to BLACK SUIT Ransomware
Dark Web Informer