Aggregator
CVE-2017-6052 | Hyundai Blue Link 3.9.4/3.9.5 access control (BID-98033)
2 weeks 1 day ago
A vulnerability was found in Hyundai Blue Link 3.9.4/3.9.5. It has been rated as critical. Impacted is an unknown function. Performing a manipulation results in improper access controls.
This vulnerability is identified as CVE-2017-6052. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2017-6054 | Hyundai Blue Link 3.9.4/3.9.5 Key hard-coded credentials (BID-98033)
2 weeks 1 day ago
A vulnerability categorized as critical has been discovered in Hyundai Blue Link 3.9.4/3.9.5. The affected element is an unknown function of the component Key. Executing a manipulation can lead to hard-coded credentials.
This vulnerability is tracked as CVE-2017-6054. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2024-29792 | Unlimited Elements for Elementor Plugin up to 1.5.93 on WordPress cross site scripting
2 weeks 1 day ago
A vulnerability marked as problematic has been reported in Unlimited Elements for Elementor Plugin up to 1.5.93 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-29792. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2024-30182 | HasThemes HT Mega Plugin up to 2.4.3 on WordPress cross site scripting
2 weeks 1 day ago
A vulnerability was found in HasThemes HT Mega Plugin up to 2.4.3 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. Such manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2024-30182. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2024-29777 | WPMU DEV Forminator Plugin up to 1.29.0 on WordPress cross site scripting
2 weeks 1 day ago
A vulnerability labeled as problematic has been found in WPMU DEV Forminator Plugin up to 1.29.0 on WordPress. Affected is an unknown function. Executing a manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2024-29777. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2024-30238 | Contest Gallery Plugin up to 21.3.2 on WordPress sql injection
2 weeks 1 day ago
A vulnerability, which was classified as critical, was found in Contest Gallery Plugin up to 21.3.2 on WordPress. This affects an unknown function. The manipulation results in sql injection.
This vulnerability was named CVE-2024-30238. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2024-30244 | Andy Moyle Church Admin Plugin up to 4.0.27 on WordPress sql injection (EUVD-2024-28175)
2 weeks 1 day ago
A vulnerability was found in Andy Moyle Church Admin Plugin up to 4.0.27 on WordPress and classified as critical. This impacts an unknown function. Executing a manipulation can lead to sql injection.
This vulnerability appears as CVE-2024-30244. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2024-30221 | WP Sunshine Sunshine Photo Cart Plugin up to 3.1.1 on WordPress deserialization
2 weeks 1 day ago
A vulnerability has been found in WP Sunshine Sunshine Photo Cart Plugin up to 3.1.1 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to deserialization.
This vulnerability is documented as CVE-2024-30221. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2024-30229 | GiveWP Plugin up to 3.4.2 on WordPress deserialization
2 weeks 1 day ago
A vulnerability was found in GiveWP Plugin up to 3.4.2 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation results in deserialization.
This vulnerability is reported as CVE-2024-30229. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2024-30236 | Contest Gallery Plugin up to 21.3.4 on WordPress sql injection
2 weeks 1 day ago
A vulnerability was found in Contest Gallery Plugin up to 21.3.4 on WordPress. It has been classified as critical. This affects an unknown part. This manipulation causes sql injection.
This vulnerability appears as CVE-2024-30236. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2024-30245 | DecaLog Plugin up to 3.9.0 on WordPress sql injection
2 weeks 1 day ago
A vulnerability marked as critical has been reported in DecaLog Plugin up to 3.9.0 on WordPress. This affects an unknown function. This manipulation causes sql injection.
The identification of this vulnerability is CVE-2024-30245. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-25599 | Castos Seriously Simple Podcasting Plugin up to 3.0.2 on WordPress cross site scripting
2 weeks 1 day ago
A vulnerability classified as problematic was found in Castos Seriously Simple Podcasting Plugin up to 3.0.2 on WordPress. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to cross site scripting.
This vulnerability is tracked as CVE-2024-25599. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2024-23500 | Kadence WP Gutenberg Blocks Plugin up to 3.2.19 on WordPress server-side request forgery
2 weeks 1 day ago
A vulnerability identified as critical has been detected in Kadence WP Gutenberg Blocks Plugin up to 3.2.19 on WordPress. This impacts an unknown function. This manipulation causes server-side request forgery.
This vulnerability is handled as CVE-2024-23500. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2024-30422 | WPVibes Elementor Addon Elements Plugin up to 1.13.1 on WordPress cross site scripting
2 weeks 1 day ago
A vulnerability classified as problematic was found in WPVibes Elementor Addon Elements Plugin up to 1.13.1 on WordPress. This vulnerability affects unknown code. The manipulation results in cross site scripting.
This vulnerability is identified as CVE-2024-30422. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2026-5370 | krayin laravel-crm up to 2.2 Activities Module/Notes inbox.spec.ts composeMail cross site scripting (Issue 2419)
2 weeks 1 day ago
A vulnerability identified as problematic has been detected in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2026-5370. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
To fix this issue, it is recommended to deploy a patch.
vuldb.com
LatAm's Self-Taught Cyber Talent Overlooked Amid Cyberattack Glut
2 weeks 1 day ago
A newly released study exclusively shared with Dark Reading details the unique circumstances that make up Latin America's labor pool, and why organizations may want to expand their talent search.
Alexander Culafi
Mercor confirms security incident tied to LiteLLM supply chain attack
2 weeks 1 day ago
Although the LiteLLM attack was reportedly tied to a group called TeamPCP, the hacking gang Lapsus$ claimed on its website that it obtained hundreds of gigabytes of Mercor’s data.
Submit #781666: Krayin Laravel CRM <= 2.1 (before patch in PR #2466) Cross Site Scripting (Stored XSS) – CWE-79 [Accepted]
2 weeks 1 day ago
Submit #781666 / VDB-354756
DineshrajanSv
CVE-2026-25833 | mbed TLS up to 3.6.5 x509_inet_pton_ipv6 buffer overflow
2 weeks 1 day ago
A vulnerability categorized as critical has been discovered in mbed TLS up to 3.6.5. This issue affects the function x509_inet_pton_ipv6. Executing a manipulation can lead to buffer overflow.
The identification of this vulnerability is CVE-2026-25833. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com