Aggregator
CVE-2021-20553 | IBM Sterling B2B Integrator up to 5.2.6.5/6.0.0.6/6.0.3.4/6.1.0.2 Web UI cross site scripting
CVE-2024-39623 | CridioStudio ListingPro Plugin up to 2.9.4 on WordPress cross-site request forgery
CVE-2024-53208 | Linux Kernel up to 6.1.119/6.6.63/6.11.10/6.12.1 Bluetooth set_powered_sync use after free (Nessus ID 216493)
CVE-2024-56225 | Leap13 Premium Addons for Elementor Plugin up to 4.10.56 on WordPress ACL authorization
CVE-2024-53244 | Splunk Enterprise/Cloud Platform Saved Search /en-US/app/search/report s information disclosure (SVD-2024-1202 / Nessus ID 212218)
CVE-2024-53245 | Splunk Enterprise/Cloud Platform Username information disclosure (SVD-2024-1203 / Nessus ID 212217)
CVE-2024-7150 | 10web Slider Plugin up to 1.2.57 on WordPress id sql injection
CVE-2024-48040 | Tainacan Plugin up to 0.21.8 on WordPress sql injection
CVE-2024-9888 | ElementInvader Addons for Elementor Plugin up to 1.2.8 on WordPress cross site scripting
CVE-2021-4445 | leap13 Premium Addons for Elementor Plugin up to 4.5.1 on WordPress Option Update pa_dismiss_admin_notice authorization
CVE-2024-53796 | Themesflat Addons for Elementor Plugin up to 2.2.2 on WordPress cross site scripting
CVE-2024-54253 | Xpro Elementor Addons Plugin up to 1.4.6.1 on WordPress cross site scripting
CVE-2024-50150 | Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5 typec use after free (Nessus ID 212921)
Intel Maps New vPro Chips to MITRE's ATT&CK Framework
New infosec products of the week: March 7, 2025
Here’s a look at the most interesting products from the past week, featuring releases from Outpost24, Palo Alto Networks, Red Canary, and Sonatype. Outpost24 introduces CyberFlex to streamline attack surface management and pen testing Outpost24 has launched Outpost24 CyberFlex, a comprehensive application security solution that combines Attack Surface Management (ASM) and Penetration Testing as a Service (PTaaS) to manage and secure an organization’s external-facing applications, and deliver enhanced visibility in a flexible and agile way. … More →
The post New infosec products of the week: March 7, 2025 appeared first on Help Net Security.
艾普拉斯急聘汽车网络安全高级工程师,职等你来展身手!!
Cisco Secure Client for Windows Let Attackers Execute Arbitrary Code With SYSTEM Privileges
A newly identified vulnerability in the Cisco Secure Client for Windows could allow attackers to execute arbitrary code with SYSTEM privileges. The vulnerability lies within the interprocess communication (IPC) channel and can be exploited by an authenticated, local attacker to perform a DLL hijacking attack. This vulnerability is present only when the Secure Firewall Posture […]
The post Cisco Secure Client for Windows Let Attackers Execute Arbitrary Code With SYSTEM Privileges appeared first on Cyber Security News.