Aggregator
CVE-2016-4105 | Adobe Acrobat Reader up to 11.0.15/15.006 memory corruption (APSB16-14 / Nessus ID 91096)
1 year 5 months ago
A vulnerability classified as critical has been found in Adobe Acrobat Reader up to 11.0.15/15.006. Affected is an unknown function. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2016-4105. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
第106篇:深入分析自己曾经挖掘到的有趣的XSS漏洞
1 year 5 months ago
第106篇:深入分析自己曾经挖掘到的有趣的XSS漏洞
1 year 5 months ago
От телефонных мошенников - к цифровой тишине: РКН готовит реформу звонков через мессенджеры
1 year 5 months ago
Ведомство сможет ограничивать звонки в рамках борьбы с мошенничеством.
Lumma Stealer利用虚假验证码页面传播无文件恶意软件
1 year 5 months ago
安全客
CVE-2024-49668 | Admin Verbalize WP Plugin up to 1.0 on WordPress unrestricted upload
1 year 5 months ago
A vulnerability was found in Admin Verbalize WP Plugin up to 1.0 on WordPress and classified as critical. This issue affects some unknown processing. The manipulation leads to unrestricted upload.
The identification of this vulnerability is CVE-2024-49668. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-49669 | Alexander De Ridder INK Official Plugin up to 4.1.2 on WordPress unrestricted upload
1 year 5 months ago
A vulnerability has been found in Alexander De Ridder INK Official Plugin up to 4.1.2 on WordPress and classified as critical. This vulnerability affects unknown code. The manipulation leads to unrestricted upload.
This vulnerability was named CVE-2024-49669. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-49652 | ReneeCussack 3D Work In Progress Plugin up to 1.0.3 on WordPress unrestricted upload
1 year 5 months ago
A vulnerability, which was classified as critical, was found in ReneeCussack 3D Work In Progress Plugin up to 1.0.3 on WordPress. This affects an unknown part. The manipulation leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2024-49652. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-49653 | James Eggers Portfolleo Plugin up to 1.2 on WordPress unrestricted upload
1 year 5 months ago
A vulnerability, which was classified as critical, has been found in James Eggers Portfolleo Plugin up to 1.2 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to unrestricted upload.
This vulnerability is handled as CVE-2024-49653. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-49751 | press cross site scripting
1 year 5 months ago
A vulnerability classified as problematic has been found in press. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-49751. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-49658 | Ecomerciar Woocommerce Custom Profile Picture Plugin up to 1.0 on WordPress unrestricted upload
1 year 5 months ago
A vulnerability classified as critical was found in Ecomerciar Woocommerce Custom Profile Picture Plugin up to 1.0 on WordPress. Affected by this vulnerability is an unknown functionality of the component Profile Picture Handler. The manipulation leads to unrestricted upload.
This vulnerability is known as CVE-2024-49658. The attack can be launched remotely. There is no exploit available.
vuldb.com
Google to let businesses create curated Chrome Web Stores for extensions
1 year 5 months ago
Google has announced it will soon allow organizations to create their own curated "Enterprise Web Store" of company-sanctioned browser extensions for Chrome and ChromeOS, aimed at improving productivity, security, and management for businesses. [...]
Bill Toulas
New Malware WarmCookie Targets Users with Malicious Links
1 year 5 months ago
WarmCookie malware, aka BadSpace, spreads via malspam, malvertising and enables persistent access
构建精益安全体系:浅析4个攻击面管理技术
1 year 5 months ago
本文介绍了EASM、CAASM、DRPS、CTEM四种攻击面管理的技术的核心点和适用场景,并提出了基于资产视图的精益安全体系建设想法
报告显示:勒索软件攻击激增,你的数据安全了吗?
1 year 5 months ago
网络安全公司 Zscaler 披露,全球勒索软件事件增加了 18%,赎金支付和行业目标方面的发现令人震惊。
CVE-2010-4165 | Linux Kernel 2.6.16.9 do_tcp_setsockopt numeric error (EDB-16263 / Nessus ID 68414)
1 year 5 months ago
A vulnerability has been found in Linux Kernel 2.6.16.9 and classified as problematic. Affected by this vulnerability is the function do_tcp_setsockopt. The manipulation leads to numeric error.
This vulnerability is known as CVE-2010-4165. The attack needs to be approached locally. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
SecWiki News 2024-10-23 Review
1 year 5 months ago
使用测绘平台进行 C2 资产拓线 by ourren
谷堕大盗黑产组织最新攻击样本详细分析 by ourren
大模型安全 vs. 代码执行 by ourren
SecWiki周刊(第555期) by ourren
谈谈网络研究和工程方法 by ourren
探索Clang Static Analyzer:使用方法与源码解读 by ourren
什么是负责任的 Web 服务器扫描? by Avenger
更多最新文章,请访问SecWiki
谷堕大盗黑产组织最新攻击样本详细分析 by ourren
大模型安全 vs. 代码执行 by ourren
SecWiki周刊(第555期) by ourren
谈谈网络研究和工程方法 by ourren
探索Clang Static Analyzer:使用方法与源码解读 by ourren
什么是负责任的 Web 服务器扫描? by Avenger
更多最新文章,请访问SecWiki
CVE-2024-49701 | Theme Horse Mags Plugin up to 1.1.6 on WordPress filename control
1 year 5 months ago
A vulnerability was found in Theme Horse Mags Plugin up to 1.1.6 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
The identification of this vulnerability is CVE-2024-49701. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-49684 | Revmakx Backup and Staging by WP Time Capsule Plugin up to 1.22.21 on WordPress deserialization
1 year 5 months ago
A vulnerability was found in Revmakx Backup and Staging by WP Time Capsule Plugin up to 1.22.21 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to deserialization.
This vulnerability was named CVE-2024-49684. The attack can be initiated remotely. There is no exploit available.
vuldb.com