Aggregator
第三方旅行服务API漏洞导致数百万航空用户账户被接管的风险
4 months 2 weeks ago
A vulnerability in a third-party travel service API has exposed millions
CVE-2024-7695 | Moxa PT-7728/PT-7828/PT-G503/PT-G510/PT-G7728/PT-G7828 out-of-bounds write
4 months 2 weeks ago
A vulnerability was found in Moxa PT-7728, PT-7828, PT-G503, PT-G510, PT-G7728 and PT-G7828. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to out-of-bounds write.
This vulnerability is known as CVE-2024-7695. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-7695 | Moxa PT-7728/PT-7828/PT-G503/PT-G510/PT-G7728/PT-G7828 out-of-bounds write
4 months 2 weeks ago
A vulnerability was found in Moxa PT-7728, PT-7828, PT-G503, PT-G510, PT-G7728 and PT-G7828. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to out-of-bounds write.
This vulnerability is known as CVE-2024-7695. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-13696 | wpdesk Flexible Wishlist for WooCommerce Plugin up to 1.2.25 on WordPress cross site scripting
4 months 2 weeks ago
A vulnerability was found in wpdesk Flexible Wishlist for WooCommerce Plugin up to 1.2.25 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-13696. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
Scientist Finds Equatorial Ocean Turbulence Is Surprisingly Ordinary
4 months 2 weeks ago
Author:(1) Hans van Haren.Table of LinksAbstract and 1. IntroductionTechnical details2.1
PowrToys v0.88.0 更新:集成老牌屏幕工具 ZoomIt
4 months 2 weeks ago
INC
4 months 2 weeks ago
cohenido
CVE-2024-27985 | PropertyHive Plugin up to 2.0.9 on WordPress deserialization
4 months 2 weeks ago
A vulnerability classified as problematic was found in PropertyHive Plugin up to 2.0.9 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to deserialization.
This vulnerability is known as CVE-2024-27985. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-2210 | Plus Addons for Elementor Plugin up to 5.4.1 on WordPress Team Member Listing file inclusion (ID 3056776)
4 months 2 weeks ago
A vulnerability was found in Plus Addons for Elementor Plugin up to 5.4.1 on WordPress. It has been classified as problematic. This affects an unknown part of the component Team Member Listing. The manipulation leads to file inclusion.
This vulnerability is uniquely identified as CVE-2024-2210. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2024-29913 | Themeum Tutor LMS Elementor Addons Plugin up to 2.1.3 on WordPress cross site scripting
4 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in Themeum Tutor LMS Elementor Addons Plugin up to 2.1.3 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-29913. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-29911 | Jewel Theme Master Addons for Elementor Plugin up to 2.0.5.4.1 on WordPress cross site scripting
4 months 2 weeks ago
A vulnerability was found in Jewel Theme Master Addons for Elementor Plugin up to 2.0.5.4.1 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-29911. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-25962 | Dell InsightIQ 5.0.0 access control (dsa-2024-134)
4 months 2 weeks ago
A vulnerability was found in Dell InsightIQ 5.0.0. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2024-25962. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-3214 | Relevanssi Plugin up to 4.22.1 on WordPress csv injection (ID 3064304)
4 months 2 weeks ago
A vulnerability was found in Relevanssi Plugin up to 4.22.1 on WordPress. It has been classified as critical. Affected is an unknown function. The manipulation leads to csv injection.
This vulnerability is traded as CVE-2024-3214. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-1042 | WP Radio Plugin up to 3.1.9 on WordPress Ajax Action authorization
4 months 2 weeks ago
A vulnerability was found in WP Radio Plugin up to 3.1.9 on WordPress. It has been rated as critical. Affected by this issue is some unknown functionality of the component Ajax Action Handler. The manipulation leads to missing authorization.
This vulnerability is handled as CVE-2024-1042. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-31871 | IBM Security Verify Access Appliance up to 10.0.7 certificate validation (XFDB-287306)
4 months 2 weeks ago
A vulnerability classified as problematic was found in IBM Security Verify Access Appliance up to 10.0.7. This vulnerability affects unknown code. The manipulation leads to improper certificate validation.
This vulnerability was named CVE-2024-31871. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-31873 | IBM Security Verify Access Appliance up to 10.0.7 hard-coded credentials (XFDB-287317)
4 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in IBM Security Verify Access Appliance up to 10.0.7. This issue affects some unknown processing. The manipulation leads to hard-coded credentials.
The identification of this vulnerability is CVE-2024-31873. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-31872 | IBM Security Verify Access Appliance up to 10.0.7 Open Source Script missing validation of openssl certificate (XFDB-287316)
4 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in IBM Security Verify Access Appliance up to 10.0.7. Affected is an unknown function of the component Open Source Script Handler. The manipulation leads to missing validation of openssl certificate.
This vulnerability is traded as CVE-2024-31872. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
INC Ransom: киберпреступная элита, которая держит весь мир на крючке
4 months 2 weeks ago
Какой загадочный «пакет доказательств» скрывает атака на CNN Indonesia?
Qilin
4 months 2 weeks ago
cohenido