Aggregator
CVE-2015-4063 | NewStatPress Plugin up to 0.9.8 on WordPress includes/nsp_search.php where1 cross site scripting (News 132038 / EDB-37107)
3 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in NewStatPress Plugin up to 0.9.8 on WordPress. This issue affects some unknown processing of the file includes/nsp_search.php. The manipulation of the argument where1 leads to cross site scripting.
The identification of this vulnerability is CVE-2015-4063. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Attackers Exploit Palo Alto Zero-Day Authentication Bypass
3 months 3 weeks ago
Surge in Attack Attempts Spotted After Palo Alto Networks Details and Patches Flaw
Attackers have stepped up efforts to exploit a vulnerability in the software that runs Palo Alto Networks firewall appliances that could give them direct access to the underlying software. Unauthenticated hackers could use PHP scripts to bypass the PAN-OS management web interface.
Attackers have stepped up efforts to exploit a vulnerability in the software that runs Palo Alto Networks firewall appliances that could give them direct access to the underlying software. Unauthenticated hackers could use PHP scripts to bypass the PAN-OS management web interface.
Red Hat security advisory (AV25-089)
3 months 3 weeks ago
Canadian Centre for Cyber Security
CVE-2013-7346 | Symphony CMS up to 2.3.1 sort cross-site request forgery (EDB-39136)
3 months 3 weeks ago
A vulnerability was found in Symphony CMS up to 2.3.1 and classified as problematic. This issue affects some unknown processing. The manipulation of the argument sort leads to cross-site request forgery.
The identification of this vulnerability is CVE-2013-7346. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Kairos
3 months 3 weeks ago
cohenido
Kairos
3 months 3 weeks ago
cohenido
CVE-2017-2468 | Apple iOS up to 10.2 WebKit memory corruption (HT207617 / EDB-41868)
3 months 3 weeks ago
A vulnerability was found in Apple iOS up to 10.2. It has been rated as critical. Affected by this issue is some unknown functionality of the component WebKit. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2017-2468. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
9 - CVE-2025-24963
3 months 3 weeks ago
Currently trending CVE - hypeScore: 1 - Vitest is a testing framework powered by Vite. The `__screenshot-error` handler on the browser mode HTTP server that responds any file on the file system. Especially if the server is exposed on the network by `browser.api.host: true`, an attacker can send a request to that handle
5 - CVE-2024-10960
3 months 3 weeks ago
Currently trending CVE - hypeScore: 1 - The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'storeUploads' function in all versions up to, and including, 2.6.4. This makes it possible for authenticated attackers, with Contributor-level access
6 - CVE-2024-40591
3 months 3 weeks ago
Currently trending CVE - hypeScore: 1 - An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to super-admi
CVE-2024-54265 | UkrSolution Barcode Scanner with Inventory & Order Manager Plugin cross site scripting
3 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in UkrSolution Barcode Scanner with Inventory & Order Manager Plugin up to 1.6.6 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-54265. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-54276 | Felix Moira Poll Builder Plugin up to 1.3.5 on WordPress cross site scripting
3 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Felix Moira Poll Builder Plugin up to 1.3.5 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-54276. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-54275 | Wibergs Web CSV to HTML Plugin up to 3.04 on WordPress cross site scripting
3 months 3 weeks ago
A vulnerability has been found in Wibergs Web CSV to HTML Plugin up to 3.04 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-54275. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-54266 | ImageRecycle PDF & Image Compression Plugin up to 3.1.16 on WordPress cross site scripting
3 months 3 weeks ago
A vulnerability was found in ImageRecycle PDF & Image Compression Plugin up to 3.1.16 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-54266. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-54277 | Alireza aliniya Nias Course Plugin up to 1.2.1 on WordPress cross site scripting
3 months 3 weeks ago
A vulnerability was found in Alireza aliniya Nias Course Plugin up to 1.2.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-54277. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-54288 | LDD Web Design LDD Directory Lite Plugin up to 3.3 on WordPress cross site scripting
3 months 3 weeks ago
A vulnerability was found in LDD Web Design LDD Directory Lite Plugin up to 3.3 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-54288. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-54286 | Sendsmaily Smaily for WP Plugin up to 3.1.2 on WordPress cross site scripting
3 months 3 weeks ago
A vulnerability classified as problematic has been found in Sendsmaily Smaily for WP Plugin up to 3.1.2 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-54286. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-54287 | Best Wp Developer Advanced Blog Post Block Plugin up to 1.0.4 on WordPress cross site scripting
3 months 3 weeks ago
A vulnerability classified as problematic was found in Best Wp Developer Advanced Blog Post Block Plugin up to 1.0.4 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-54287. The attack can be initiated remotely. There is no exploit available.
vuldb.com
Microsoft to remove the Location History feature in Windows
3 months 3 weeks ago
Microsoft announced the deprecation of the Location History feature from Windows, which let applications like the Cortana virtual assistant to fetch location history of the device. [...]
Bill Toulas