Aggregator
Cloak
1 year 5 months ago
cohenido
CVE-2014-7000 | Paul Alexander Campaign 4.5.8 X.509 Certificate cryptographic issues (VU#582497)
1 year 5 months ago
A vulnerability was found in Paul Alexander Campaign 4.5.8. It has been classified as critical. This affects an unknown part of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is uniquely identified as CVE-2014-7000. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
New Android banking trojan Octo2 targets European banks
1 year 5 months ago
A new version of the Android banking trojan Octo, called Octo2, supports improved features that allow to takeover infected devices. ThreatFabric researchers discovered a new version of the Android banking trojan Octo, called Octo2, that supports more advanced remote action capabilities needed for Device Takeover attacks. The new malware has already targeted users in European […]
Pierluigi Paganini
印度争论有毒工作文化
1 year 5 months ago
安永会计师事务所的一名 26 岁印度女会计师 Anna Sebastian Perayil 在入职 4 个月后去世,她的父母称巨大的工作压力影响了她的健康导致了她的死亡。安永否认了这一说法,称 Perayil 和其他员工一样分配工作,不相信工作压力导致了其死亡。她的去世在印度引发了有毒工作文化的争论,印度很多企业和创业公司所推崇的工作文化往往以牺牲员工福祉为代价。员工在这种压力下经常会导致倦怠和生活质量下降。她的母亲 Anita Augustine 表示,有毒工作文化美化了过度劳累的工作,忽略工作背后的人。安永印度 CEO Rajiv Memani 表示将确保将员工的福祉放在首位。
CVE-2024-7398 | Concrete CMS up to 8.5.18/9.3.3 Calendar Event Addition cross site scripting
1 year 5 months ago
A vulnerability, which was classified as problematic, was found in Concrete CMS up to 8.5.18/9.3.3. Affected is an unknown function of the component Calendar Event Addition Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-7398. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9069 | besnikac Graphicsly Plugin up to 1.0.2 on WordPress SVG File Upload cross site scripting
1 year 5 months ago
A vulnerability, which was classified as problematic, has been found in besnikac Graphicsly Plugin up to 1.0.2 on WordPress. This issue affects some unknown processing of the component SVG File Upload Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-9069. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-8741 | outtheboxthemes Beam me up Scotty Plugin up to 1.0.21 on WordPress add_query_arg cross site scripting
1 year 5 months ago
A vulnerability classified as problematic was found in outtheboxthemes Beam me up Scotty Plugin up to 1.0.21 on WordPress. This vulnerability affects the function add_query_arg. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-8741. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-8515 | themesflat Themesflat Addons For Elementor Plugin up to 2.2.1 on WordPress TF E Slider Widget/TF Video Widget/TF Team Widget cross site scripting
1 year 5 months ago
A vulnerability classified as problematic has been found in themesflat Themesflat Addons For Elementor Plugin up to 2.2.1 on WordPress. This affects an unknown part of the component TF E Slider Widget/TF Video Widget/TF Team Widget. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-8515. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-8668 | devitemsllc ShopLentor Plugin up to 2.9.7 on WordPress cross site scripting
1 year 5 months ago
A vulnerability was found in devitemsllc ShopLentor Plugin up to 2.9.7 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-8668. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-8275 | theeventscalendar Events Calendar Plugin up to 6.6.4 on WordPress tribe_has_next_event order sql injection
1 year 5 months ago
A vulnerability was found in theeventscalendar Events Calendar Plugin up to 6.6.4 on WordPress. It has been declared as critical. Affected by this vulnerability is the function tribe_has_next_event. The manipulation of the argument order leads to sql injection.
This vulnerability is known as CVE-2024-8275. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-8483 | farookibrahim MAS Static Content Plugin up to 1.0.8 on WordPress static_content information disclosure
1 year 5 months ago
A vulnerability was found in farookibrahim MAS Static Content Plugin up to 1.0.8 on WordPress. It has been classified as problematic. Affected is the function static_content. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-8483. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-8434 | themehunk Easy Mega Menu Plugin up to 1.0.9 on WordPress Setting authorization
1 year 5 months ago
A vulnerability was found in themehunk Easy Mega Menu Plugin up to 1.0.9 on WordPress and classified as problematic. This issue affects some unknown processing of the component Setting Handler. The manipulation leads to missing authorization.
The identification of this vulnerability is CVE-2024-8434. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-8658 | wpexpertsio myCred Plugin up to 2.7.3 on WordPress mycred_update_database authorization
1 year 5 months ago
A vulnerability has been found in wpexpertsio myCred Plugin up to 2.7.3 on WordPress and classified as problematic. This vulnerability affects the function mycred_update_database. The manipulation leads to missing authorization.
This vulnerability was named CVE-2024-8658. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-6590 | javmah Spreadsheet Integration Plugin up to 3.7.9 on WordPress authorization
1 year 5 months ago
A vulnerability, which was classified as critical, has been found in javmah Spreadsheet Integration Plugin up to 3.7.9 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to missing authorization.
This vulnerability is handled as CVE-2024-6590. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-8516 | Themesflat Addons for Elementor Plugin up to 2.2.1 on WordPress render information disclosure
1 year 5 months ago
A vulnerability, which was classified as problematic, was found in Themesflat Addons for Elementor Plugin up to 2.2.1 on WordPress. This affects the function render. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-8516. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-8514 | Prisna GWT Plugin up to 1.4.11 on WordPress prisna_import deserialization
1 year 5 months ago
A vulnerability classified as problematic was found in Prisna GWT Plugin up to 1.4.11 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation of the argument prisna_import leads to deserialization.
This vulnerability is known as CVE-2024-8514. The attack can be launched remotely. There is no exploit available.
vuldb.com
CISA Flags Critical Ivanti vTM Vulnerability Amid Active Exploitation Concerns
1 year 5 months ago
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a critical security flaw impacting Ivanti Virtual Traffic Manager (vTM) to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.
The vulnerability in question is CVE-2024-7593 (CVSS score: 9.8), which could be exploited by a remote unauthenticated attacker to bypass the
The Hacker News
CVE-2016-6318 | CrackLib lib/fascist.c FascistGecosUser GECOS memory corruption (DLA 2220-1 / Nessus ID 93301)
1 year 5 months ago
A vulnerability was found in CrackLib. It has been declared as critical. This vulnerability affects the function FascistGecosUser in the library lib/fascist.c. The manipulation of the argument GECOS leads to memory corruption.
This vulnerability was named CVE-2016-6318. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Reversing a una función (ASM x86-32) – Ej 1
1 year 5 months ago
Buenas a todos y bienvenidos a este artículo, soy b1n4ri0 (otra vez). Hoy vamos a pelearnos un poco con un...
Adrià Pérez Montoro