Gayfemboy, a Mirai botnet variant, has been exploiting a flaw in Four-Faith industrial routers to launch DDoS attacks since November 2024. The Gayfemboy botnet was first identified in February 2024, it borrows the code from the basic Mirai variant and now integrates N-day and 0-day exploits. By November 2024, Gayfemboy exploited 0-day vulnerabilities in Four-Faith […]
A vulnerability classified as problematic has been found in Get Your Number Plugin up to 1.1.3 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2023-2634. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability, which was classified as critical, was found in Red Hat Advanced Cluster Management for Kubernetes. This affects an unknown part of the component grc-policy-propagator. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2023-3027. The attack needs to be done within the local network. There is no exploit available.
A vulnerability was found in MitraStar GPT-2741GNAC AR_g5.8_110WVN0b7_2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Ping Handler. The manipulation leads to command injection.
This vulnerability is known as CVE-2023-33381. Access to the local network is required for this attack to succeed. There is no exploit available.
Hackers are trying to exploit CVE-2024-52875, a critical CRLF injection vulnerability that leads to 1-click remote code execution (RCE) attacks in GFI KerioControl firewall product. [...]
A vulnerability was found in xml-rs Crate up to 0.8.13 on Rust/Crab. It has been classified as problematic. This affects an unknown part of the component XML Document Handler. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2023-34411. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Stop Spammers Security Plugin 2022.6 on WordPress. It has been declared as problematic. This vulnerability affects unknown code of the component Admin Dashboard. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2023-2488. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Pricing Table Builder Plugin up to 1.1.6 on WordPress. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2023-0900. Access to the local network is required for this attack to succeed. There is no exploit available.
A vulnerability classified as problematic has been found in Hostel Plugin 1.1.4 on WordPress. Affected is an unknown function of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2023-0545. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.