Aggregator
CVE-2018-19949 | QNAP QTS prior 4.4.2.1231 command injection
CVE-2018-19953 | QNAP QTS prior 4.4.2.1231 cross site scripting
CVE-2020-17530 | Apache Struts up to 2.5.25 OGNL Evaluation expression language injection
CVE-2020-17530 | Oracle Hospitality OPERA 5 5.6 Login code injection
CVE-2020-17530 | Oracle MySQL Enterprise Monitor up to 8.0.23 General code injection
CVE-2020-17530 | Oracle Communications Pricing Design Center 12.0.0.3.0 Apache Struts code injection
CVE-2020-17530 | Oracle Communications Policy Management 12.5.0 Apache Struts2 expression language injection
U.S. CISA adds Microsoft Outlook, Sophos XG Firewall, and other flaws to its Known Exploited Vulnerabilities catalog
7AI Streamlines Security Operations With Autonomous AI Agents
CVE-2018-11784 | Oracle Retail Order Broker 5.1/5.2/15.0 Upgrade Install redirect (EDB-50118 / ID 13390)
CVE-2017-13847 | Apple iOS up to 11.1.2 IOKit memory corruption (HT208334 / EDB-43326)
CVE-2017-2522 | Apple watchOS up to 3.2.1 CoreFoundation memory corruption (EDB-42049 / BID-98588)
CVE-2024-13512 | edigermatthew Wonder FontAwesome Plugin up to 0.8 on WordPress Setting cross-site request forgery
CVE-2024-13549 | areoimiles All Bootstrap Blocks Plugin up to 1.3.26 on WordPress cross site scripting
CVE-2024-12451 | proxymis HTML5 chat Plugin up to 1.04 on WordPress Shortcode HTML5CHAT cross site scripting
CVE-2024-13349 | stockdio Stockdio Historical Chart Plugin up to 2.8.18 on WordPress Shortcode stockdio-historical-chart cross site scripting
CVE-2024-13720 | filipmedia WP Image Uploader Plugin up to 1.0.1 on WordPress wp-config.php gky_image_uploader_main_function cross-site request forgery
BTS #45 – Understanding Firmware Vulnerabilities in Network Appliances
In this episode, Paul, Vlad, and Chase discuss the security challenges associated with Palo Alto devices and network appliances. They explore the vulnerabilities present in these devices, the importance of best practices in device management, and the need for automatic updates. The conversation highlights the evolving nature of firmware vulnerabilities and the necessity for compensating […]
The post BTS #45 - Understanding Firmware Vulnerabilities in Network Appliances appeared first on Eclypsium | Supply Chain Security for the Modern Enterprise.
The post BTS #45 – Understanding Firmware Vulnerabilities in Network Appliances appeared first on Security Boulevard.
Critical Microsoft Outlook Vulnerability (CVE-2024-21413) Actively Exploited in Attacks – CISA Warns
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to federal agencies regarding active exploitation of a critical Microsoft Outlook vulnerability, tracked as CVE-2024-21413. This remote code execution (RCE) flaw, discovered by Check Point researcher Haifei Li, is caused by improper input validation when processing emails containing malicious links. “Successful exploitation […]
The post Critical Microsoft Outlook Vulnerability (CVE-2024-21413) Actively Exploited in Attacks – CISA Warns appeared first on Cyber Security News.