Aggregator
CVE-2024-9897 | StreamWeasels Twitch Integration Plugin up to 1.8.6 on WordPress Shortcode sw-twitch-embed cross site scripting
1 year 5 months ago
A vulnerability classified as problematic was found in StreamWeasels Twitch Integration Plugin up to 1.8.6 on WordPress. Affected by this vulnerability is the function sw-twitch-embed of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-9897. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-10131 | infiniflow ragflow up to 0.11.0 llm_app.py add_llm req['llm_factory']/req['llm_name'] command injection
1 year 5 months ago
A vulnerability classified as very critical has been found in infiniflow ragflow up to 0.11.0. Affected is the function add_llm of the file llm_app.py. The manipulation of the argument req['llm_factory']/req['llm_name'] leads to command injection.
This vulnerability is traded as CVE-2024-10131. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-29821 | Ivanti DSM 5.1 access control
1 year 5 months ago
A vulnerability was found in Ivanti DSM 5.1. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2024-29821. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CLOP
1 year 5 months ago
cohenido
CVE-2024-29213 | Ivanti DSM 5.1 access control
1 year 5 months ago
A vulnerability was found in Ivanti DSM 5.1. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to improper access controls.
This vulnerability was named CVE-2024-29213. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-37404 | Ivanti Connect Secure/Policy Secure crlf injection
1 year 5 months ago
A vulnerability was found in Ivanti Connect Secure and Policy Secure. It has been classified as critical. This affects an unknown part. The manipulation leads to crlf injection.
This vulnerability is uniquely identified as CVE-2024-37404. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43577 | Microsoft Edge up to 129.0.2792.52 (Nessus ID 209257)
1 year 5 months ago
A vulnerability was found in Microsoft Edge and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to an unknown weakness.
This vulnerability is handled as CVE-2024-43577. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
"Growing Businesses Gives Me a Sense of Purpose." says Flow Ninja Founder/CEO
1 year 5 months ago
HackerNoon: What is your company in 2–5 words?Uros Mikic: Full-service Webflow agency, one subscrip
Everest
1 year 5 months ago
cohenido
Kill
1 year 5 months ago
cohenido
CVE-2014-7795 | itp Harpers Bazaar Art X.509 Certificate cryptographic issues (VU#582497)
1 year 5 months ago
A vulnerability, which was classified as critical, was found in itp Harpers Bazaar Art. This affects an unknown part of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is uniquely identified as CVE-2014-7795. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
Iran-linked actors target critical infrastructure organizations
1 year 5 months ago
Iran-linked actors target critical infrastructure organizationsU.S. and allies warn of attacks
BianLian Ransomware Gang Claims Heist of Pediatric Data
1 year 5 months ago
Boston Children's Health Physicians Says Incident Involved Unnamed IT Vendor
Ransomware gang BianLian has listed Boston Children's Health Physicians - a pediatric group that practices in New York and Connecticut - on its dark web site, threatening to release stolen patient and employee data. The practice said the September incident involved an IT vendor.
Ransomware gang BianLian has listed Boston Children's Health Physicians - a pediatric group that practices in New York and Connecticut - on its dark web site, threatening to release stolen patient and employee data. The practice said the September incident involved an IT vendor.
Hacker Poses as Israeli Security Vendor to Deliver Wiper
1 year 5 months ago
Phishing Emails Impersonating Eset Target Cybersecurity Professionals With Malware
Cybercriminals posing as a top security firm in Israel have launched wiper attacks on local cybersecurity professionals after bypassing significant security measures, according to recent reports. Cybersecurity firm Eset said threat actors did not compromise its systems.
Cybercriminals posing as a top security firm in Israel have launched wiper attacks on local cybersecurity professionals after bypassing significant security measures, according to recent reports. Cybersecurity firm Eset said threat actors did not compromise its systems.
North Korean IT Scam Workers Shift to Extortion Tactics
1 year 5 months ago
Report Reveals North Korean Workers Expanding Into Intellectual Property Theft
North Korean threat actors posing as remote information technology workers are increasingly extorting ransom from Western companies after securing jobs under false pretenses, according to a new report from Secureworks' counter threat unit.
North Korean threat actors posing as remote information technology workers are increasingly extorting ransom from Western companies after securing jobs under false pretenses, according to a new report from Secureworks' counter threat unit.
BlackBerry Cuts Cylance Spend to Focus on Profitable Areas
1 year 5 months ago
Company Shifts Cyber Focus to QNX and Secure Communications as Key Growth Drivers
As Cylance continues to incur significant losses, BlackBerry is reallocating resources toward its more promising QNX and secure communications teams. The company expects its cybersecurity unit to stabilize and become profitable by the end of the fiscal year, thanks to strategic bets and cost cuts.
As Cylance continues to incur significant losses, BlackBerry is reallocating resources toward its more promising QNX and secure communications teams. The company expects its cybersecurity unit to stabilize and become profitable by the end of the fiscal year, thanks to strategic bets and cost cuts.
CVE-2016-7003 | Adobe Acrobat Reader up to 11.0.17/15.006.30201/15.017.20053 memory corruption (APSB16-33 / Nessus ID 94074)
1 year 5 months ago
A vulnerability, which was classified as critical, has been found in Adobe Acrobat Reader up to 11.0.17/15.006.30201/15.017.20053. Affected by this issue is some unknown functionality. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2016-7003. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
$KERORO Hits Solana With A Seismic Shift Expected
1 year 5 months ago
NEWCASTLE UPON TYNE, United Kingdom, October 18th, 2024/Chainwire/--Today marks the official launch
Ape On Launches Innovative Token Locking For Secure Project Launches On Solana
1 year 5 months ago
MAJURO, Marshall Island, October 18th, 2024/Chainwire/--Ape On, the most secure and efficient token