A vulnerability has been found in mobile-app-builder-by-wappress 1.05 on WordPress and classified as critical. Impacted is an unknown function of the component Invedion CMS. Performing manipulation results in unrestricted upload (Unlicensed).
This vulnerability was named CVE-2017-1002001. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability was found in webapp-builder 2.0 on WordPress and classified as critical. The affected element is an unknown function of the component Invedion CMS. Executing manipulation can lead to unrestricted upload (Unlicensed).
The identification of this vulnerability is CVE-2017-1002002. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability was found in Moodle 2.x/3.x. It has been classified as critical. Affected is an unknown function of the component User Preferences. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2017-2641. The attack is possible to be carried out remotely. Moreover, an exploit is present.
Upgrading the affected component is recommended.
A vulnerability was found in wp2android-turn-wp-site-into-android-app 1.1.4 on WordPress. It has been classified as critical. The impacted element is an unknown function of the component Invedion CMS. The manipulation leads to unrestricted upload (Unlicensed).
This vulnerability is referenced as CVE-2017-1002003. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability marked as critical has been reported in MLM Forex Market Plan Script 2.0.4. Affected by this issue is some unknown functionality of the file news_detail.php. The manipulation of the argument newid as part of Parameter leads to sql injection.
This vulnerability is traded as CVE-2017-17635. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability described as critical has been identified in MLM Forced Matrix 2.0.9. This affects an unknown part of the file news-detail.php. The manipulation of the argument newid as part of Parameter results in sql injection.
This vulnerability is known as CVE-2017-17636. It is possible to launch the attack remotely. Furthermore, an exploit is available.
Announcement Provokes Skepticism in Cyber Community A band of adolescent hackers behind attacks against airliners, insurers and casinos in the United Kingdom and the United States on Friday said they are shutting down their operations. Scattered Lapsus$ Hunters posted a semi-coherent screed announcing a decision to "go dark."
Vastaamo Hacker Aleksanteri Kivimäki Is Free, For Now A Helsinki court ordered the release of Finland's most notorious hacker pending the resolution of his appeal of a conviction stemming from the theft of psychotherapy records of 33,000 individuals. Aleksanteri Kivimäki was convicted last year for hacking into now-defunct psychotherapy chain Vastaamo.
A vulnerability classified as critical was found in Oracle Application Testing Suite 12.5.0.1/12.5.0.2/12.5.0.3. Affected by this issue is some unknown functionality of the component Load Testing for Web Apps. Such manipulation leads to cryptographic issues.
This vulnerability is listed as CVE-2015-7940. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability, which was classified as critical, has been found in Oracle PeopleSoft Enterprise PeopleTools 8.54/8.55. This affects an unknown part of the component Bouncy Castle Java. Performing manipulation results in cryptographic issues.
This vulnerability is cataloged as CVE-2015-7940. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Oracle Virtual Desktop Infrastructure up to 3.5.2. This vulnerability affects unknown code of the component Bouncy Castle Java. Executing manipulation can lead to cryptographic issues.
This vulnerability is registered as CVE-2015-7940. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
A vulnerability described as critical has been identified in Oracle Enterprise Manager 12.1.0.5/13.1/13.2. This affects an unknown function. Such manipulation leads to information disclosure.
This vulnerability is documented as CVE-2015-7940. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability classified as critical has been found in Oracle Enterprise Manager 12.1.4/12.2.2. Affected by this vulnerability is an unknown functionality of the component Ops Center. This manipulation causes cryptographic issues.
This vulnerability is tracked as CVE-2015-7940. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Bouncy Castle Java Library up to 1.50. Affected is an unknown function of the component Diffie-Hellman Key Exchange. Such manipulation leads to cryptographic issues.
This vulnerability is referenced as CVE-2015-7940. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
A vulnerability classified as critical has been found in Honeywell PM43 on 32-bit ARM. Affected is an unknown function. This manipulation causes session fixiation.
This vulnerability appears as CVE-2023-3711. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic was found in Honeywell PM43 on 32-bit ARM. Affected by this vulnerability is an unknown functionality. Such manipulation leads to files or directories accessible.
This vulnerability is traded as CVE-2023-3712. An attack has to be approached locally. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability classified as critical has been found in Wavlink WL-WN578W2 221110. This affects the function sub_401C5C of the file firewall.cgi. This manipulation of the argument pingFrmWANFilterEnabled/blockSynFloodEnabled/blockPortScanEnabled/remoteManagementEnabled causes command injection.
The identification of this vulnerability is CVE-2025-10324. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is advisable to implement restrictive firewalling.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Squid Web Proxy up to 6.3. It has been rated as critical. This vulnerability affects unknown code of the component HTTP Response Cache Handler. The manipulation leads to improper handling of structural elements.
This vulnerability is traded as CVE-2023-5824. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability was found in Dogtag CA and classified as critical. The impacted element is an unknown function of the component dogtag-pki/pki-core. The manipulation results in ldap injection.
This vulnerability was named CVE-2023-4727. The attack needs to be approached within the local network. There is no available exploit.