Aggregator
Play
1 year 3 months ago
cohenido
Play
1 year 3 months ago
cohenido
Play
1 year 3 months ago
cohenido
Play
1 year 3 months ago
cohenido
Play
1 year 3 months ago
cohenido
CVE-2024-43959 | Themepoints Testimonials Plugin up to 3.0.8 on WordPress cross site scripting
1 year 3 months ago
A vulnerability classified as problematic has been found in Themepoints Testimonials Plugin up to 3.0.8 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-43959. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-46461 | VideoLAN VLC Media Player up to 3.0.20 Mms Stream heap-based overflow
1 year 3 months ago
A vulnerability, which was classified as critical, was found in VideoLAN VLC Media Player up to 3.0.20. Affected is an unknown function of the component Mms Stream Handler. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2024-46461. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-20475 | Cisco Catalyst SD-WAN Manager up to 20.14.1_LI_Images Web-based Management Interface cross site scripting (cisco-sa-sdwan-xss-zQ4KPvYd / Nessus ID 207764)
1 year 3 months ago
A vulnerability was found in Cisco Catalyst SD-WAN Manager. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Web-based Management Interface. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-20475. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-20437 | Cisco IOS XE up to 17.12.1y Web UI cross-site request forgery (cisco-sa-webui-csrf-ycUYxkKO / Nessus ID 211956)
1 year 3 months ago
A vulnerability was found in Cisco IOS XE. It has been declared as problematic. This vulnerability affects unknown code of the component Web UI. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2024-20437. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-20414 | Cisco IOS/IOS XE up to 15.2(8)E5 Web UI cross-site request forgery (cisco-sa-ios-webui-HfwnRgk / Nessus ID 207787)
1 year 3 months ago
A vulnerability was found in Cisco IOS and IOS XE. It has been rated as problematic. This issue affects some unknown processing of the component Web UI. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2024-20414. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-51157 | ZKTeco WDMS 5.1.3 Emp Name cross site scripting
1 year 3 months ago
A vulnerability was found in ZKTeco WDMS 5.1.3. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument Emp Name leads to cross site scripting.
This vulnerability is handled as CVE-2023-51157. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-47082 | strawberry graphql up to 0.242.x Multipart File Upload cross-site request forgery (GHSA-79gp-q4wv-33fr)
1 year 3 months ago
A vulnerability classified as problematic was found in strawberry graphql up to 0.242.x. This vulnerability affects unknown code of the component Multipart File Upload Handler. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2024-47082. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46655 | Ellevo 6.2.0.38160 cross site scripting
1 year 3 months ago
A vulnerability, which was classified as problematic, has been found in Ellevo 6.2.0.38160. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-46655. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-47305 | Dnesscarkey Use Any Font Plugin up to 6.3.08 on WordPress cross-site request forgery
1 year 3 months ago
A vulnerability, which was classified as problematic, was found in Dnesscarkey Use Any Font Plugin up to 6.3.08 on WordPress. Affected is an unknown function. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2024-47305. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 36
1 year 3 months ago
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape. Cellebrite zero-day exploit used to target phone of Serbian student activist One in Four Cyberattacks in 2024 Traced to Infostealers, Huntress Reports Uncovering .NET Malware Obfuscated by Encryption and Virtualization Black Basta and Cactus Ransomware Groups […]
Pierluigi Paganini
Алгоритмы голодания: ИИ отбирает хлеб у 76 миллионов фрилансеров
1 year 3 months ago
Глубокий анализ изменений в модели занятости демонстрирует серьезное перераспределение рисков.
CVE-2024-47315 | GiveWP Plugin up to 3.15.1 on WordPress cross-site request forgery
1 year 3 months ago
A vulnerability has been found in GiveWP Plugin up to 3.15.1 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2024-47315. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-8803 | Bulk NoIndex & NoFollow Toolkit Plugin up to 2.15 on WordPress cross site scripting
1 year 3 months ago
A vulnerability was found in Bulk NoIndex & NoFollow Toolkit Plugin up to 2.15 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-8803. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2022-4541 | Visitors Plugin up to 1.0 on WordPress HTTP Header cross site scripting
1 year 3 months ago
A vulnerability, which was classified as problematic, was found in Visitors Plugin up to 1.0 on WordPress. This affects an unknown part of the component HTTP Header Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2022-4541. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com