Aggregator
绿盟英雄帖|M01N战队研究员直聘,英雄请留步!
1 year 4 months ago
社招及实习招聘开启!
Updated FakeCall Malware Targets Mobile Devices with Vishing
1 year 4 months ago
The new FakeCall variant uses advanced vishing tactics, featuring Bluetooth for device monitoring
Vishing, Mishing Go Next-Level With FakeCall Android Malware
1 year 4 months ago
A new variant of the sophisticated attacker tool gives cybercriminals even more control over victim devices to conduct various malicious activities, including fraud and cyber espionage.
Elizabeth Montalbano, Contributing Writer
爱尔兰数据保护委员会因侵犯GDPR而对LinkedIn罚款3100万欧元
1 year 4 months ago
安全客
CVE-2022-38176 | YSoft SAFEQ 6/6.0.55 Installer access control
1 year 4 months ago
A vulnerability was found in YSoft SAFEQ 6/6.0.55 and classified as critical. This issue affects some unknown processing of the component Installer. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2022-38176. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-36228 | Nokelock Smart padlock O1 5.3.0 permission
1 year 4 months ago
A vulnerability was found in Nokelock Smart padlock O1 5.3.0. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to permission issues.
This vulnerability was named CVE-2022-36228. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-22455 | Dell Mobility E-Lab Navigator 3.1.9/3.2.0 Feedback Submission clickjacking (dsa-2024-073)
1 year 4 months ago
A vulnerability was found in Dell Mobility E-Lab Navigator 3.1.9/3.2.0. It has been rated as problematic. This issue affects some unknown processing of the component Feedback Submission Handler. The manipulation leads to clickjacking.
The identification of this vulnerability is CVE-2024-22455. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2022-29946 | NATS Server/Streaming Server Queue Subscription permission
1 year 4 months ago
A vulnerability was found in NATS Server and Streaming Server. It has been classified as critical. This affects an unknown part of the component Queue Subscription Handler. The manipulation leads to permission issues.
This vulnerability is uniquely identified as CVE-2022-29946. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-4872 | Hitachi Energy MicroSCADA SYS600 up to 10.5 sql injection
1 year 4 months ago
A vulnerability, which was classified as critical, has been found in Hitachi Energy MicroSCADA SYS600 up to 10.5. Affected by this issue is some unknown functionality. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2024-4872. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-7941 | Hitachi Energy MicroSCADA SYS600 up to 10.5 HTTP Parameter redirect
1 year 4 months ago
A vulnerability, which was classified as problematic, was found in Hitachi Energy MicroSCADA SYS600 up to 10.5. This affects an unknown part of the component HTTP Parameter Handler. The manipulation leads to open redirect.
This vulnerability is uniquely identified as CVE-2024-7941. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-6657 | Silabs EFR32 BLE SDK up to 7.1.1/8.0.0 incorrect synchronization
1 year 4 months ago
A vulnerability was found in Silabs EFR32 BLE SDK up to 7.1.1/8.0.0. It has been classified as problematic. This affects an unknown part. The manipulation leads to incorrect synchronization.
This vulnerability is uniquely identified as CVE-2024-6657. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-35495 | TP-Link Kasa KP125M/Tapo P125M 1.0.0 Telemetry information disclosure
1 year 4 months ago
A vulnerability classified as problematic has been found in TP-Link Kasa KP125M and Tapo P125M 1.0.0. Affected is an unknown function of the component Telemetry. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-35495. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
Shared Hosting vs Virtual Private Server (VPS) vs Dedicated Hosting
1 year 4 months ago
Shared Hosting vs Virtual Private Server (VPS) vs Dedicated Hosting
Dark Web Informer
Black Basta附属机构在最近的攻击中使用了Microsoft Teams
1 year 4 months ago
安全客
CVE-2024-50344 | mkucej i-librarian-free up to 5.11.1 cross site scripting
1 year 4 months ago
A vulnerability classified as problematic was found in mkucej i-librarian-free up to 5.11.1. This vulnerability affects unknown code. The manipulation leads to basic cross site scripting.
This vulnerability was named CVE-2024-50344. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
ATPC Cyber Forum to Focus on Next Generation Cybersecurity and Artificial Intelligence Issues
1 year 4 months ago
Atlanta, Georgia, 30th October 2024, CyberNewsWire
The post ATPC Cyber Forum to Focus on Next Generation Cybersecurity and Artificial Intelligence Issues appeared first on Security Boulevard.
cybernewswire
CVE-2024-9708 | Easy SVG Upload Plugin up to 1.0 on WordPress SVG File Upload cross site scripting
1 year 4 months ago
A vulnerability classified as problematic has been found in Easy SVG Upload Plugin up to 1.0 on WordPress. This affects an unknown part of the component SVG File Upload Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-9708. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-10544 | Woo Manage Fraud Orders Plugin up to 6.1.7 on WordPress Log File information disclosure
1 year 4 months ago
A vulnerability was found in Woo Manage Fraud Orders Plugin up to 6.1.7 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Log File Handler. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2024-10544. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-50419 | Wpsoul Greenshift Plugin up to 9.7 on WordPress authorization
1 year 4 months ago
A vulnerability was found in Wpsoul Greenshift Plugin up to 9.7 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to incorrect authorization.
This vulnerability is known as CVE-2024-50419. The attack can be launched remotely. There is no exploit available.
vuldb.com