On Thursday, K-12 school district Highline Public Schools confirmed that a ransomware attack forced it to shut down all schools in early September. [...]
Google removed Kaspersky ‘s Android security apps from the Play Store and suspended its developer accounts over the weekend. Over the weekend, all the Android products designed by the Russian cybersecurity firm Kaspersky were removed from the official Google Play in the United States and other countries. Google also disabled the developer accounts used by the cybersecurity […]
A vulnerability classified as critical was found in Tenda G3 15.03.05.05. Affected by this vulnerability is the function formSetUSBPartitionUmount. The manipulation of the argument usbPartitionName leads to os command injection.
This vulnerability is known as CVE-2024-46628. The attack can be launched remotely. There is no exploit available.
A vulnerability has been found in GitLab Enterprise Edition up to 17.2.7/17.3.3/17.4.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Private Project Handler. The manipulation leads to incorrect provision of specified functionality.
This vulnerability is known as CVE-2024-8974. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in AYS AI ChatBot with ChatGPT and Content Generator Plugin up to 2.0.x on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Open AI API Key Handler. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2024-7713. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Events Calendar Plugin up to 6.5.1.6 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-6931. The attack may be initiated remotely. There is no exploit available.
A vulnerability was found in Oceanic Software ValeApp up to 1.x. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2024-8607. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Oceanic Software ValeApp up to 1.x. Affected by this issue is some unknown functionality. The manipulation leads to session fixiation.
This vulnerability is handled as CVE-2024-8643. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in Oceanic Software ValeApp up to 1.x. This affects an unknown part. The manipulation leads to sensitive information in log files.
This vulnerability is uniquely identified as CVE-2024-8609. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Nobexrc Amnesia Groove 3.2.3. It has been classified as critical. This affects an unknown part of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is uniquely identified as CVE-2014-7389. The attack needs to be done within the local network. There is no exploit available.
CVE-2024-44204 is one of two new Apple iOS security vulnerabilities that showcase an unexpected coming together of privacy snafus and accessibility features.
A vulnerability, which was classified as critical, has been found in Strapi 4.24.4. This issue affects some unknown processing of the file /strapi.io/_next/image of the component GET Request Handler. The manipulation leads to server-side request forgery.
The identification of this vulnerability is CVE-2024-37818. The attack can only be done within the local network. There is no exploit available.
A vulnerability, which was classified as problematic, has been found in Hughes Network Systems WL3000 Fusion Software. Affected by this issue is some unknown functionality. The manipulation leads to insufficiently protected credentials.
This vulnerability is handled as CVE-2024-39278. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in goTenna Pro Series up to 1.6.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Message Handler. The manipulation leads to improper restriction of communication channel to intended endpoints.
This vulnerability is known as CVE-2024-47125. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in goTenna Pro Series up to 1.6.1. It has been declared as problematic. This vulnerability affects unknown code of the component Broadcast Key Name Handler. The manipulation leads to insertion of sensitive information into sent data.
This vulnerability was named CVE-2024-47128. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in goTenna Pro Series up to 1.6.1. It has been rated as problematic. This issue affects some unknown processing of the component Length Handler. The manipulation leads to observable response discrepancy.
The identification of this vulnerability is CVE-2024-47129. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in goTenna Pro Series up to 1.6.1. Affected is an unknown function of the component Local Public Key Handler. The manipulation leads to missing authentication.
This vulnerability is traded as CVE-2024-47130. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in Linux Kernel up to 6.10.4. Affected is an unknown function of the component btrfs. The manipulation leads to allocation of resources.
This vulnerability is traded as CVE-2024-44963. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A growing number of organizations are taking longer to get back on their feet after an attack, and they're paying high price tags to do so — up to $2M or more.
A vulnerability, which was classified as very critical, has been found in Adobe Flash Player. This issue affects some unknown processing. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2016-4244. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.