Aggregator
原创 Paper | 本地化 AI 审计工具落地小试牛刀
9 months 3 weeks ago
CVE-2025-0805 | mlcalc Mortgage Calculator and Loan Calculator Plugin up to 1.5.19 on WordPress Shortcode cross site scripting
9 months 3 weeks ago
A vulnerability classified as problematic has been found in mlcalc Mortgage Calculator and Loan Calculator Plugin up to 1.5.19 on WordPress. This affects an unknown part of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-0805. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-13848 | jakob42 Reaction Buttons Plugin up to 2.1.6 on WordPress Setting cross site scripting
9 months 3 weeks ago
A vulnerability was found in jakob42 Reaction Buttons Plugin up to 2.1.6 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-13848. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-13741 | metagauss ProfileGrid Plugin up to 5.9.4.1 on WordPress server-side request forgery
9 months 3 weeks ago
A vulnerability classified as critical was found in metagauss ProfileGrid Plugin up to 5.9.4.1 on WordPress. This vulnerability affects unknown code. The manipulation leads to server-side request forgery.
This vulnerability was named CVE-2024-13741. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-0805 | mlcalc Mortgage Calculator and Loan Calculator Plugin up to 1.5.19 on WordPress Shortcode cross site scripting
9 months 3 weeks ago
A vulnerability classified as problematic has been found in mlcalc Mortgage Calculator and Loan Calculator Plugin up to 1.5.19 on WordPress. This affects an unknown part of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-0805. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-13848 | jakob42 Reaction Buttons Plugin up to 2.1.6 on WordPress Setting cross site scripting
9 months 3 weeks ago
A vulnerability was found in jakob42 Reaction Buttons Plugin up to 2.1.6 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-13848. The attack may be launched remotely. There is no exploit available.
vuldb.com
WinRAR 7.10 Latest Version Released – What’s New!
9 months 3 weeks ago
The popular file compression and archiving tool, WinRAR 7.10, has released with new features, interface enhancements, and improved performance. WinRAR 7.10 represents a landmark update that modernizes core components while addressing evolving user needs in data management and system security. With over 500 million users worldwide, WinRAR is the leading compression tool for efficient and […]
The post WinRAR 7.10 Latest Version Released – What’s New! appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Balaji
New Xerox Printer Flaws Could Let Attackers Capture Windows Active Directory Credentials
9 months 3 weeks ago
Security vulnerabilities have been disclosed in Xerox VersaLink C7025 Multifunction printers (MFPs) that could allow attackers to capture authentication credentials via pass-back attacks via Lightweight Directory Access Protocol (LDAP) and SMB/FTP services.
"This pass-back style attack leverages a vulnerability that allows a malicious actor to alter the MFP's configuration and cause the MFP
The Hacker News
美国会拟立法:将太空系统作为关基设施进行保护
9 months 3 weeks ago
《太空基础设施法案》
新一轮勒索潮来了?超级勒索软件组织宣布攻陷47家企业
9 months 3 weeks ago
该团伙曾犯下多起影响面超大的数据泄露事件
CVE-2024-13438 | SpeedSize Image & Video AI-Optimizer Plugin up to 1.5.1 on WordPress cross-site request forgery
9 months 3 weeks ago
A vulnerability was found in SpeedSize Image & Video AI-Optimizer Plugin up to 1.5.1 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2024-13438. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-13588 | kenkwasnicki Simplebooklet PDF Viewer and Embedder Plugin up to 1.1.0 on WordPress Shortcode cross site scripting
9 months 3 weeks ago
A vulnerability was found in kenkwasnicki Simplebooklet PDF Viewer and Embedder Plugin up to 1.1.0 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-13588. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-13438 | SpeedSize Image & Video AI-Optimizer Plugin up to 1.5.1 on WordPress cross-site request forgery
9 months 3 weeks ago
A vulnerability was found in SpeedSize Image & Video AI-Optimizer Plugin up to 1.5.1 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2024-13438. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-13587 | softdiscover Zigaform Plugin up to 7.4.2 on WordPress Shortcode cross site scripting
9 months 3 weeks ago
A vulnerability was found in softdiscover Zigaform Plugin up to 7.4.2 on WordPress and classified as problematic. This issue affects some unknown processing of the component Shortcode Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-13587. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-13582 | labibahmed42 Simple Pricing Tables for WPBakery Page Builder Plugin cross site scripting
9 months 3 weeks ago
A vulnerability has been found in labibahmed42 Simple Pricing Tables for WPBakery Page Builder Plugin up to 1.0 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-13582. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-13579 | platcom WP-Asambleas Plugin up to 2.85.0 on WordPress Shortcode cross site scripting
9 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in platcom WP-Asambleas Plugin up to 2.85.0 on WordPress. This affects an unknown part of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-13579. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-13578 | zjhzxhz WP-BibTeX Plugin up to 3.0.1 on WordPress Shortcode cross site scripting
9 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in zjhzxhz WP-BibTeX Plugin up to 3.0.1 on WordPress. Affected by this issue is some unknown functionality of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-13578. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-13576 | adityapatadia Gumlet Video Plugin up to 1.0.3 on WordPress Shortcode cross site scripting
9 months 3 weeks ago
A vulnerability classified as problematic was found in adityapatadia Gumlet Video Plugin up to 1.0.3 on WordPress. Affected by this vulnerability is an unknown functionality of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-13576. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-13573 | softdiscover Zigaform Plugin up to 7.4.2 on WordPress Shortcode cross site scripting
9 months 3 weeks ago
A vulnerability classified as problematic has been found in softdiscover Zigaform Plugin up to 7.4.2 on WordPress. Affected is an unknown function of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-13573. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com