Aggregator
CVE-2023-27195 | Trimble TM4Web 22.2.0 Registration tm_ajax.msw?func=UserfromUUID&uuid= access control
1 year 4 months ago
A vulnerability was found in Trimble TM4Web 22.2.0. It has been classified as critical. Affected is an unknown function of the file /inc/tm_ajax.msw?func=UserfromUUID&uuid= of the component Registration. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2023-27195. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-49702 | myCred Elementor Plugin up to 1.2.6 on WordPress cross site scripting
1 year 4 months ago
A vulnerability classified as problematic was found in myCred Elementor Plugin up to 1.2.6 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-49702. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-22066 | ZTE ZXR10 1800-2S 3.00.40 information disclosure
1 year 4 months ago
A vulnerability was found in ZTE ZXR10 1800-2S 3.00.40. It has been classified as problematic. This affects an unknown part. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-22066. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-10621 | Simple Shortcode for Google Maps Plugin up to 1.5.4 on WordPress cross site scripting
1 year 4 months ago
A vulnerability classified as problematic was found in Simple Shortcode for Google Maps Plugin up to 1.5.4 on WordPress. Affected by this vulnerability is an unknown functionality of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-10621. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-50173 | Linux Kernel up to 6.10.13/6.11.2 panthor drm/ tick_ctx_cleanup uninitialized pointer (ac2ca5e5148a/3bde05794497/282864cc5d3f)
1 year 4 months ago
A vulnerability was found in Linux Kernel up to 6.10.13/6.11.2. It has been rated as problematic. Affected by this issue is the function tick_ctx_cleanup of the file drm/ of the component panthor. The manipulation leads to uninitialized pointer.
This vulnerability is handled as CVE-2024-50173. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
研究发现,AI 生成的面孔激增,成为对 X 进行政治操纵的工具
1 year 4 months ago
安全客
黑客在加密勒索软件攻击中索要价值 12.5 万美元的法国面包
1 year 4 months ago
安全客
新型 SteelFox 恶意软件冒充流行软件窃取浏览器数据
1 year 4 months ago
安全客
CVE-2024-11026 | Intelligent Apps Freenow App 12.10.0 on Android Keystore SSL.java DEFAULT_KEYSTORE_PASSWORD hard-coded password
1 year 4 months ago
A vulnerability was found in Intelligent Apps Freenow App 12.10.0 on Android. It has been rated as problematic. Affected by this issue is some unknown functionality of the file ch/qos/logback/core/net/ssl/SSL.java of the component Keystore Handler. The manipulation of the argument DEFAULT_KEYSTORE_PASSWORD with the input changeit leads to use of hard-coded password.
This vulnerability is handled as CVE-2024-11026. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
APT73
1 year 4 months ago
cohenido
Apache ZooKeeper 安全警报:影响 Admin Server 的重要缺陷 (CVE-2024-51504)
1 year 4 months ago
安全客
CVE-2015-0569 | Google Android Qualcomm Wi-Fi Driver memory corruption (EDB-39308 / BID-77691)
1 year 4 months ago
A vulnerability was found in Google Android. It has been classified as critical. Affected is an unknown function of the component Qualcomm Wi-Fi Driver. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2015-0569. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Submit #434538: Intelligent Apps GmbH FREENOW (ex Beat app) 12.10.0 Use of Hard-coded, Security-relevant Constants [Accepted]
1 year 4 months ago
Submit #434538 / VDB-283544
secuserx
小心 Python 开发人员: 恶意 “fabrice ”软件包从 37,000 多次下载中窃取 AWS 凭据
1 year 4 months ago
安全客
CVE-2024-50592 | Hasomed Elefant prior 1.4.2.1811 Update Service PostESUUpdate.exe toctou
1 year 4 months ago
A vulnerability was found in Hasomed Elefant. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file PostESUUpdate.exe of the component Update Service. The manipulation leads to time-of-check time-of-use.
This vulnerability is known as CVE-2024-50592. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CISA 扩展了 KEV 目录,增加了四个被积极利用的漏洞
1 year 4 months ago
安全客
CVE-2024-40715 | Veeam Enterprise Manager up to 12.2 channel accessible (kb4682)
1 year 4 months ago
A vulnerability was found in Veeam Enterprise Manager up to 12.2. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to channel accessible by non-endpoint.
This vulnerability was named CVE-2024-40715. The attack can be initiated remotely. There is no exploit available.
vuldb.com
Veeam security advisory (AV24-637)
1 year 4 months ago
Canadian Centre for Cyber Security
Xlight FTP Server整数溢出漏洞(CVE-2024-46483)分析与复现
1 year 4 months ago
Xlight FTP Server整数溢出漏洞(CVE-2024-46483)分析与复现