Aggregator
engineer is Allegedly Selling API Access of BatchSkipTracing
1 year 4 months ago
engineer is Allegedly Selling API Access of BatchSkipTracing
Dark Web Informer
Schneider Electric Confirms Ransom Hack — Hellcat Demands French Bread as ‘Joke’
1 year 4 months ago
That’s a lot of pain: $125,000 ransom seems small—but why do the scrotes want it paid in baguettes?
The post Schneider Electric Confirms Ransom Hack — Hellcat Demands French Bread as ‘Joke’ appeared first on Security Boulevard.
Richi Jennings
CVE-2024-20504 | Cisco Secure Email Web-based Management Interface cross site scripting (cisco-sa-esa-wsa-sma-xss-zYm3f49n)
1 year 4 months ago
A vulnerability was found in Cisco Secure Email, Secure Email and Web Manager and Secure Web Appliance. It has been declared as problematic. This vulnerability affects unknown code of the component Web-based Management Interface. The manipulation leads to basic cross site scripting.
This vulnerability was named CVE-2024-20504. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-20487 | Cisco Identity Services Engine Software 2.7.0 p8 up to 3.3 Patch 3 Web-based Management Interface cross site scripting (cisco-sa-ise-multi-vulns-AF544ED5)
1 year 4 months ago
A vulnerability was found in Cisco Identity Services Engine Software. It has been classified as problematic. This affects an unknown part of the component Web-based Management Interface. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-20487. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-20507 | Cisco Meeting Management up to 3.9.0 Web-based Management Interface information disclosure (cisco-sa-cmm-info-disc-9ZEMAhGA)
1 year 4 months ago
A vulnerability was found in Cisco Meeting Management up to 3.9.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Web-based Management Interface. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2024-20507. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-20476 | Cisco Identity Services Engine Software 2.7.0 p8 up to 3.3 Patch 3 Web-based Management Interface client-side enforcement of server-side security (cisco-sa-ise-multi-vulns-AF544ED5)
1 year 4 months ago
A vulnerability has been found in Cisco Identity Services Engine Software and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Web-based Management Interface. The manipulation leads to client-side enforcement of server-side security.
This vulnerability is known as CVE-2024-20476. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Washington courts' systems offline following weekend cyberattack
1 year 4 months ago
Court systems across Washington state have been down since Sunday when officials said "unauthorized activity" was detected on their networks. [...]
Sergiu Gatlan
CVE-2024-20484 | Cisco Enterprise Chat and Email up to 12.6_ES3_ET2 External Agent Assignment Service denial of service (cisco-sa-ece-dos-Oqb9uFEv)
1 year 4 months ago
A vulnerability, which was classified as critical, was found in Cisco Enterprise Chat and Email. Affected is an unknown function of the component External Agent Assignment Service. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2024-20484. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-20418 | Cisco IOS XE Controller Web-based Management Interface command injection (cisco-sa-backhaul-ap-cmdinj-R7E28Ecs)
1 year 4 months ago
A vulnerability, which was classified as very critical, has been found in Cisco IOS XE Controller. This issue affects some unknown processing of the component Web-based Management Interface. The manipulation leads to command injection.
The identification of this vulnerability is CVE-2024-20418. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
雷军透露考虑办驾校;特斯拉否认任命品牌大使;Meta AR 眼镜前负责人加入 OpenAI | 极客早知道
1 year 4 months ago
超越苹果,英伟达再度登顶「全球第一」!11 月 6 日消息,截至周二美股收盘,「AI 总龙头」英伟达再度超越苹果公司成为全球市值最高公司,凸显出投资者们对人工智能(AI)的长期前景正变得愈发乐观。美东
CVE-2024-50637 | UnoPim up to 0.1.3 Create User cross site scripting
1 year 4 months ago
A vulnerability classified as problematic was found in UnoPim up to 0.1.3. This vulnerability affects unknown code of the component Create User Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-50637. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-10318 | F5 NGINX OpenID Connect session fixiation (K000148232)
1 year 4 months ago
A vulnerability classified as critical has been found in F5 NGINX OpenID Connect, NGINX Instance Manager, NGINX API Connectivity Manager and NGINX Ingress Controller. This affects an unknown part. The manipulation leads to session fixiation.
This vulnerability is uniquely identified as CVE-2024-10318. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-20534 | Cisco Video Phone 8875 up to 12.0.5SR1 Web UI cross site scripting (cisco-sa-mpp-xss-8tAV2TvF)
1 year 4 months ago
A vulnerability was found in Cisco Desk Phone 9800, IP Phone 6800, IP Phone 7800, IP Phone 8800 and Video Phone 8875. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Web UI. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-20534. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-20514 | Cisco Evolved Programmable Network Manager Web-based Management Interface cross site scripting (cisco-sa-epnmpi-sxss-yyf2zkXs)
1 year 4 months ago
A vulnerability was found in Cisco Evolved Programmable Network Manager and Prime Infrastructure. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Web-based Management Interface. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-20514. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-20533 | Cisco Video Phone 8875 up to 12.0.5SR1 Web UI cross site scripting (cisco-sa-mpp-xss-8tAV2TvF)
1 year 4 months ago
A vulnerability was found in Cisco Desk Phone 9800, IP Phone 6800, IP Phone 7800, IP Phone 8800 and Video Phone 8875. It has been classified as problematic. Affected is an unknown function of the component Web UI. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-20533. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-20531 | Cisco Identity Services Engine Software up to 3.4.0 API xml external entity reference (cisco-sa-ise-multi-vuln-DBQdWRy)
1 year 4 months ago
A vulnerability was found in Cisco Identity Services Engine Software and classified as problematic. This issue affects some unknown processing of the component API. The manipulation leads to xml external entity reference.
The identification of this vulnerability is CVE-2024-20531. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
ИИ заблудился в Нью-Йорке: что пошло не так?
1 year 4 months ago
Почему доверять «умным» навигаторам – все еще не лучшая идея.
CVE-2024-20530 | Cisco Identity Services Engine Software up to 3.4.0 Web-based Management Interface cross site scripting (cisco-sa-ise-multi-vuln-DBQdWRy)
1 year 4 months ago
A vulnerability, which was classified as problematic, was found in Cisco Identity Services Engine Software. This affects an unknown part of the component Web-based Management Interface. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-20530. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-20539 | Cisco Identity Services Engine Software up to 3.3.0 Web-based Management Interface cross site scripting (cisco-sa-ise-auth-bypass-BBRf7mkE)
1 year 4 months ago
A vulnerability has been found in Cisco Identity Services Engine Software and classified as problematic. This vulnerability affects unknown code of the component Web-based Management Interface. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-20539. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com