Aggregator
CVE-2013-4665 | SPBAS Business Automation Software 2012 /customers/index.php cross-site request forgery (EDB-26244 / OSVDB-94325)
9 months 3 weeks ago
A vulnerability was found in SPBAS Business Automation Software 2012 and classified as problematic. Affected by this issue is some unknown functionality of the file /customers/index.php. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2013-4665. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2000-0014 | Michael Lamont Savant WebServer 2.0 URL Null Character denial of service (EDB-19695 / XFDB-3762)
9 months 3 weeks ago
A vulnerability was found in Michael Lamont Savant WebServer 2.0 and classified as problematic. This issue affects some unknown processing of the component URL Handler. The manipulation as part of Null Character leads to denial of service.
The identification of this vulnerability is CVE-2000-0014. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2006-2502 | Cyrus IMAPD 2.3.2 stack-based overflow (EDB-16836 / XFDB-26578)
9 months 3 weeks ago
A vulnerability was found in Cyrus IMAPD 2.3.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to stack-based buffer overflow.
This vulnerability is known as CVE-2006-2502. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-56014 | Markyis Cool Olivia Plugin up to 0.9.5 on WordPress cross site scripting
9 months 3 weeks ago
A vulnerability classified as problematic has been found in Markyis Cool Olivia Plugin up to 0.9.5 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-56014. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-38753 | Labib Ahmed Animated Rotating Words Plugin up to 5.6 on WordPress cross-site request forgery
9 months 3 weeks ago
A vulnerability classified as problematic was found in Labib Ahmed Animated Rotating Words Plugin up to 5.6 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2024-38753. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-37413 | Rara Theme Preschool and Kindergarten Plugin up to 1.2.1 on WordPress cross-site request forgery
9 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Rara Theme Preschool and Kindergarten Plugin up to 1.2.1 on WordPress. Affected is an unknown function. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2024-37413. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-56257 | CoolPlugins Coins MarketCap Plugin up to 5.5.8 on WordPress cross site scripting
9 months 3 weeks ago
A vulnerability has been found in CoolPlugins Coins MarketCap Plugin up to 5.5.8 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-56257. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-56268 | WP Hait Post Grid Elementor Addon Plugin up to 2.0.18 on WordPress cross site scripting
9 months 3 weeks ago
A vulnerability was found in WP Hait Post Grid Elementor Addon Plugin up to 2.0.18 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-56268. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-38789 | Marco Milesi Telegram Bot & Channel Plugin up to 3.8.2 on WordPress cross-site request forgery
9 months 3 weeks ago
A vulnerability was found in Marco Milesi Telegram Bot & Channel Plugin up to 3.8.2 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2024-38789. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-37508 | Rara Theme Construction Landing Page Plugin up to 1.3.5 on WordPress cross-site request forgery
9 months 3 weeks ago
A vulnerability was found in Rara Theme Construction Landing Page Plugin up to 1.3.5 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2024-37508. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-38790 | Smartsupp Plugin up to 3.6 on WordPress cross-site request forgery
9 months 3 weeks ago
A vulnerability was found in Smartsupp Plugin up to 3.6 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2024-38790. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2005-2713 | Apple Mac OS X Local Privilege Escalation (EDB-1545 / Nessus ID 20990)
9 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Apple Mac OS X. Affected is an unknown function. The manipulation leads to Local Privilege Escalation.
This vulnerability is traded as CVE-2005-2713. Attacking locally is a requirement. Furthermore, there is an exploit available.
vuldb.com
CVE-2015-4064 | Landing Pages Plugin up to 1.8.4 on WordPress module.ab-testing.php post sql injection (ID 132037 / EDB-37108)
9 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Landing Pages Plugin up to 1.8.4 on WordPress. Affected is an unknown function of the file modules/module.ab-testing.php. The manipulation of the argument post leads to sql injection.
This vulnerability is traded as CVE-2015-4064. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
SonicWall Firewall Authentication Bypass Vulnerability Exploited in Wild Following PoC Release
9 months 3 weeks ago
A critical authentication bypass vulnerability in SonicWall firewalls, tracked as CVE-2024-53704, is now being actively exploited in the wild, cybersecurity firms warn. The surge in attacks follows the public release of proof-of-concept (PoC) exploit code on February 10, 2025, by researchers at Bishop Fox, amplifying risks for organizations with unpatched devices. CVE-2024-53704, rated 9.3 on […]
The post SonicWall Firewall Authentication Bypass Vulnerability Exploited in Wild Following PoC Release appeared first on Cyber Security News.
Guru Baran
bshare分享插件被黑?百万级网站被劫持事件
9 months 3 weeks ago
近日我们发现所有直接或间接使用了bshare分析插件的网页都会受到影响。根据评估,恐怕会影响百万级别的网页。奇安信威胁情报中心在此提醒目前仍在使用bshare插件的用户,需要尽快更换或者停用bshare分享插件。
bshare分享插件被黑?百万级网站被劫持事件
9 months 3 weeks ago
近日我们发现所有直接或间接使用了bshare分析插件的网页都会受到影响。根据评估,恐怕会影响百万级别的网页。奇安信威胁情报中心在此提醒目前仍在使用bshare插件的用户,需要尽快更换或者停用bshare分享插件。
CVE-2012-4234 | Phorum up to 5.2.18 control.php group cross site scripting (EDB-37683 / XFDB-78124)
9 months 3 weeks ago
A vulnerability classified as problematic was found in Phorum up to 5.2.18. This vulnerability affects unknown code of the file control.php. The manipulation of the argument group leads to cross site scripting.
This vulnerability was named CVE-2012-4234. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2008-2703 | Novell GroupWise Messenger prior 2.0 memory corruption (EDB-31889 / Nessus ID 33141)
9 months 3 weeks ago
A vulnerability, which was classified as very critical, has been found in Novell GroupWise Messenger. Affected by this issue is some unknown functionality. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2008-2703. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43927 | Till Krüss Email Address Encoder Plugin up to 1.0.23 on WordPress cross-site request forgery
9 months 3 weeks ago
A vulnerability classified as problematic has been found in Till Krüss Email Address Encoder Plugin up to 1.0.23 on WordPress. Affected is an unknown function. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2024-43927. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com