A vulnerability classified as critical has been found in Zoho ManageEngine ADManager Plus up to 7203. Affected is an unknown function of the component Modify Computers Option. The manipulation leads to improper privilege management.
This vulnerability is traded as CVE-2024-24409. It is possible to launch the attack remotely. There is no exploit available.
Cybersecurity researchers have flagged a new malware campaign that infects Windows systems with a Linux virtual instance containing a backdoor capable of establishing remote access to the compromised hosts.
The "intriguing" campaign, codenamed CRON#TRAP, starts with a malicious Windows shortcut (LNK) file likely distributed in the form of a ZIP archive via a phishing email.
"What makes the CRON#
A vulnerability was found in myCred Plugin up to 2.7.4 on WordPress. It has been rated as problematic. This issue affects the function mycred_link of the component Shortcode Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-10187. The attack may be initiated remotely. There is no exploit available.
A vulnerability was found in Elementor Header & Footer Builder Plugin up to 1.6.45 on WordPress. It has been declared as problematic. This vulnerability affects unknown code of the component SVG File Upload Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-10325. The attack can be initiated remotely. There is no exploit available.
A vulnerability was found in Registrations for the Events Calendar Plugin up to 2.12.3 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-7982. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 5.10.227/5.15.168/6.1.113/6.6.57/6.11.4 and classified as problematic. Affected by this issue is the function unuse_pud_range of the component HugeTLB Page. The manipulation leads to allocation of resources.
This vulnerability is handled as CVE-2024-50199. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.