Aggregator
CVE-2006-2548 | Prodder 0.3/0.4 enc_url code injection (EDB-27902 / XFDB-26568)
1 year 3 months ago
A vulnerability classified as critical has been found in Prodder 0.3/0.4. Affected is an unknown function. The manipulation of the argument enc_url leads to code injection.
This vulnerability is traded as CVE-2006-2548. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-44037 | MagePeople Team Multipurpose Ticket Booking Manager Plugin up to 4.2.2 on WordPress cross site scripting
1 year 3 months ago
A vulnerability was found in MagePeople Team Multipurpose Ticket Booking Manager Plugin up to 4.2.2 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-44037. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-44039 | WP Travel Plugin up to 9.3.1 on WordPress cross site scripting
1 year 3 months ago
A vulnerability was found in WP Travel Plugin up to 9.3.1 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-44039. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-44040 | Plainware ShiftController Employee Shift Scheduling Plugin up to 4.9.64 on WordPress cross site scripting
1 year 3 months ago
A vulnerability was found in Plainware ShiftController Employee Shift Scheduling Plugin up to 4.9.64 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-44040. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-44042 | Fahad Mahmood WP Datepicker Plugin up to 2.1.1 on WordPress cross site scripting
1 year 3 months ago
A vulnerability has been found in Fahad Mahmood WP Datepicker Plugin up to 2.1.1 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-44042. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-44043 | 10Web Photo Gallery Plugin up to 1.8.27 on WordPress cross site scripting
1 year 3 months ago
A vulnerability was found in 10Web Photo Gallery Plugin up to 1.8.27 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-44043. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2004-1467 | Egroupware 1.0/1.0.1/1.0.3 Calendar Module Home cross site scripting (EDB-24403 / Nessus ID 14358)
1 year 3 months ago
A vulnerability has been found in Egroupware 1.0/1.0.1/1.0.3 and classified as problematic. This vulnerability affects unknown code of the component Calendar Module. The manipulation of the argument Home leads to basic cross site scripting.
This vulnerability was named CVE-2004-1467. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-44045 | Kevon Adonis WP Abstracts Plugin up to 2.6.5 on WordPress cross site scripting
1 year 3 months ago
A vulnerability was found in Kevon Adonis WP Abstracts Plugin up to 2.6.5 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-44045. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-45247 | Sonarr prior 4.0.9.2244 redirect
1 year 3 months ago
A vulnerability was found in Sonarr. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to open redirect.
This vulnerability is known as CVE-2024-45247. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47310 | ARI Soft ARI Fancy Lightbox Plugin up to 1.3.17 on WordPress cross site scripting
1 year 3 months ago
A vulnerability was found in ARI Soft ARI Fancy Lightbox Plugin up to 1.3.17 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-47310. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-47313 | Catch Themes Catch Base Plugin up to 3.4.6 on WordPress cross site scripting
1 year 3 months ago
A vulnerability classified as problematic has been found in Catch Themes Catch Base Plugin up to 3.4.6 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-47313. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-47320 | WS Form Lite Plugin up to 1.9.238 on WordPress cross site scripting
1 year 3 months ago
A vulnerability classified as problematic was found in WS Form Lite Plugin up to 1.9.238 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-47320. The attack can be initiated remotely. There is no exploit available.
vuldb.com
Cruel And Vindictive By Design
1 year 3 months ago
(This post originally published on 47 Watch) Recent administrative changes at the Social Security Administration (SSA) reveal a concerning pattern of decisions that disproportionately impact vulnerable populations while being implemented in ways that limit public awareness and oversight. Two specific policy reversals highlight this trend: the reinstatement of 100% benefit withholding for overpayments and the […]
The post Cruel And Vindictive By Design appeared first on rud.is.
The post Cruel And Vindictive By Design appeared first on Security Boulevard.
hrbrmstr
CVE-2025-25015
1 year 3 months ago
Currently trending CVE - Hype Score: 1 - Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests.
In Kibana versions >= 8.15.0 and < 8.17.1, this is exploitable by users with the Viewer role. In Kibana versions 8.17.1 and 8.17.2 , this is only ...
CVE-2025-27423
1 year 3 months ago
Currently trending CVE - Hype Score: 1 - Vim is an open source, command line text editor. Vim is distributed with the tar.vim plugin, that allows easy editing and viewing of (compressed or uncompressed) tar files. Starting with 9.1.0858, the tar.vim plugin uses the ":read" ex command line to append below the cursor ...
CVE-2024-7014
1 year 3 months ago
Currently trending CVE - Hype Score: 1 - EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android application affecting
versions 10.14.4 and older.
也来聊聊威胁情报(一)
1 year 3 months ago
都在讲威胁情报,到底啥是威胁情报?希望本文能解开你心中的疑惑
也来聊聊威胁情报(一)
1 year 3 months ago
都在讲威胁情报,到底啥是威胁情报?希望本文能解开你心中的疑惑
也来聊聊威胁情报(一)
1 year 3 months ago
都在讲威胁情报,到底啥是威胁情报?希望本文能解开你心中的疑惑