Aggregator
CVE-2024-6770 | Lifetime Free Drag & Drop Contact Form Builder for VForm Plugin cross site scripting
1 year 8 months ago
A vulnerability was found in Lifetime Free Drag & Drop Contact Form Builder for VForm Plugin up to 2.1.5 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-6770. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-7208 | HostGator Hosted Services authentication spoofing
1 year 8 months ago
A vulnerability was found in HostGator. It has been classified as critical. This affects an unknown part of the component Hosted Services. The manipulation leads to authentication bypass by spoofing.
This vulnerability is uniquely identified as CVE-2024-7208. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-41944 | xibosignage xibo-cms up to 3.3.11/4.0.13 proofofplayReport sortBy sql injection (GHSA-v6q4-h869-gm3r)
1 year 8 months ago
A vulnerability was found in xibosignage xibo-cms up to 3.3.11/4.0.13 and classified as critical. Affected by this issue is some unknown functionality of the file report/data/proofofplayReport. The manipulation of the argument sortBy leads to sql injection.
This vulnerability is handled as CVE-2024-41944. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41804 | xibosignage xibo-cms up to 3.3.11/4.0.13 sql injection (GHSA-4pp3-4mw7-qfwr)
1 year 8 months ago
A vulnerability has been found in xibosignage xibo-cms up to 3.3.11/4.0.13 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection.
This vulnerability is known as CVE-2024-41804. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41803 | xibosignage xibo-cms up to 3.3.11/4.0.13 sql injection (GHSA-hpc5-mxfq-44hv)
1 year 8 months ago
A vulnerability, which was classified as critical, was found in xibosignage xibo-cms up to 3.3.11/4.0.13. Affected is an unknown function. The manipulation leads to sql injection.
This vulnerability is traded as CVE-2024-41803. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41802 | xibosignage xibo-cms up to 3.3.11/4.0.13 API Route sql injection (GHSA-x4qm-vvhp-g7c2)
1 year 8 months ago
A vulnerability, which was classified as critical, has been found in xibosignage xibo-cms up to 3.3.11/4.0.13. This issue affects some unknown processing of the component API Route. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2024-41802. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-5486 | HPE ClearPass Policy Manager up to 6.11.8/6.12.1 information disclosure
1 year 8 months ago
A vulnerability classified as problematic was found in HPE ClearPass Policy Manager up to 6.11.8/6.12.1. This vulnerability affects unknown code. The manipulation leads to information disclosure.
This vulnerability was named CVE-2024-5486. The attack can be initiated remotely. There is no exploit available.
vuldb.com
HPE security advisory (AV24-429)
1 year 8 months ago
Canadian Centre for Cyber Security
CVE-2024-41916 | HPE ClearPass Policy Manager up to 6.11.8/6.12.1 information disclosure
1 year 8 months ago
A vulnerability classified as problematic has been found in HPE ClearPass Policy Manager up to 6.11.8/6.12.1. This affects an unknown part. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-41916. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-7209 | NetWin/Bird Fastmail SPF Record authentication spoofing
1 year 8 months ago
A vulnerability was found in NetWin and Bird Fastmail. It has been rated as critical. Affected by this issue is some unknown functionality of the component SPF Record Handler. The manipulation leads to authentication bypass by spoofing.
This vulnerability is handled as CVE-2024-7209. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-41943 | mkucej i-librarian-free up to 5.11.0 Item Summary Page cross site scripting
1 year 8 months ago
A vulnerability was found in mkucej i-librarian-free up to 5.11.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Item Summary Page. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-41943. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41915 | HPE ClearPass Policy Manager up to 6.11.8/6.12.1 Web-based Management Interface sql injection
1 year 8 months ago
A vulnerability was found in HPE ClearPass Policy Manager up to 6.11.8/6.12.1. It has been classified as critical. Affected is an unknown function of the component Web-based Management Interface. The manipulation leads to sql injection.
This vulnerability is traded as CVE-2024-41915. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-7297 | Langflow up to 1.0.12 /api/v1/users dynamically-managed code resources
1 year 8 months ago
A vulnerability was found in Langflow up to 1.0.12 and classified as very critical. This issue affects some unknown processing of the file /api/v1/users. The manipulation leads to dynamically-managed code resources.
The identification of this vulnerability is CVE-2024-7297. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-26289 | IBM Aspera Orchestrator 4.0.1 http headers for scripting syntax (XFDB-248478)
1 year 8 months ago
A vulnerability has been found in IBM Aspera Orchestrator 4.0.1 and classified as critical. This vulnerability affects unknown code. The manipulation leads to improper neutralization of http headers for scripting syntax.
This vulnerability was named CVE-2023-26289. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-38001 | IBM Aspera Orchestrator 4.0.1 cross-site request forgery (XFDB-260206)
1 year 8 months ago
A vulnerability, which was classified as problematic, was found in IBM Aspera Orchestrator 4.0.1. This affects an unknown part. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2023-38001. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-26288 | IBM Aspera Orchestrator 4.0.1 Password Change session expiration (XFDB-248477)
1 year 8 months ago
A vulnerability, which was classified as critical, has been found in IBM Aspera Orchestrator 4.0.1. Affected by this issue is some unknown functionality of the component Password Change Handler. The manipulation leads to session expiration.
This vulnerability is handled as CVE-2023-26288. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-33167 | IBM Security Directory Integrator cookie httponly flag (XFDB-228587)
1 year 8 months ago
A vulnerability classified as problematic was found in IBM Security Directory Integrator and Security Verify Directory Integrator. Affected by this vulnerability is an unknown functionality. The manipulation leads to cookie without 'httponly' flag.
This vulnerability is known as CVE-2022-33167. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
DigiCert массово отзывает SSL/TLS сертификаты
1 year 8 months ago
Следующие сутки станут судьбоносными для миллиона веб-сайтов.
News Alert: Adaptive Shield to showcase new ITDR platform for SaaS at Black Hat USA
1 year 8 months ago
Las Vegas, Nev., July 30, 2024, CyberNewsWire — Amid rising breaches including Snowflake, the platform helps security teams proactively detect and respond to identity-centric threats in business-critical SaaS applications.
Adaptive Shield, a leader in SaaS Security, today announced its … (more…)
The post News Alert: Adaptive Shield to showcase new ITDR platform for SaaS at Black Hat USA first appeared on The Last Watchdog.
The post News Alert: Adaptive Shield to showcase new ITDR platform for SaaS at Black Hat USA appeared first on Security Boulevard.
cybernewswire