Aggregator
Chinese APT Gelsemium Deploys 'Wolfsbane' Linux Variant
1 day 12 hours ago
In a sign of the times, a backdoor malware whose ancestors date back to 2005 has morphed to target Linux systems.
Nate Nelson, Contributing Writer
CVE-2024-52053 | Wowza Streaming Engine up to 4.8.27+5 Administrator Dashboard cross site scripting
1 day 12 hours ago
A vulnerability was found in Wowza Streaming Engine up to 4.8.27+5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Administrator Dashboard. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-52053. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
RansomHub
1 day 12 hours ago
cohenido
CVE-2024-52054 | Wowza Streaming Engine up to 4.8.27+5 XML File injection
1 day 12 hours ago
A vulnerability was found in Wowza Streaming Engine up to 4.8.27+5. It has been classified as problematic. Affected is an unknown function of the component XML File Handler. The manipulation leads to injection.
This vulnerability is traded as CVE-2024-52054. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52056 | Wowza Streaming Engine up to 4.8.27+5 XML File injection
1 day 12 hours ago
A vulnerability was found in Wowza Streaming Engine up to 4.8.27+5 and classified as problematic. This issue affects some unknown processing of the component XML File Handler. The manipulation leads to injection.
The identification of this vulnerability is CVE-2024-52056. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52055 | Wowza Streaming Engine up to 4.8.27+5 XML File injection
1 day 12 hours ago
A vulnerability has been found in Wowza Streaming Engine up to 4.8.27+5 and classified as problematic. This vulnerability affects unknown code of the component XML File Handler. The manipulation leads to injection.
This vulnerability was named CVE-2024-52055. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52052 | Wowza Streaming Engine up to 4.8.27+5 Privilege Escalation
1 day 12 hours ago
A vulnerability, which was classified as critical, was found in Wowza Streaming Engine up to 4.8.27+5. This affects an unknown part. The manipulation leads to Privilege Escalation.
This vulnerability is uniquely identified as CVE-2024-52052. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
“Free Hugs” – What to be Wary of in Hugging Face – Part 2
1 day 12 hours ago
Enjoy Thr
DEF CON 32 – Unlocking The Gates: Hacking A Secure Industrial Remote Access Solution
1 day 12 hours ago
Authors/Presenters: Moritz Abrell
Our sincere appreciation to DEF CON, and the Presenters/Authors for publishing their erudite DEF CON 32 content. Originating from the conference’s events located at the Las Vegas Convention Center; and via the organizations YouTube channel.
The post DEF CON 32 – Unlocking The Gates: Hacking A Secure Industrial Remote Access Solution appeared first on Security Boulevard.
Marc Handelman
Gaining Visibility & Strengthening SaaS Security: How Sprinklr Uses AppOmni
1 day 12 hours ago
The ChallengeAddressing Sc
CVE-2024-51367 | BlackBoard 2.0.0.2 XML File username.BlackBoard unrestricted upload
1 day 12 hours ago
A vulnerability, which was classified as critical, has been found in BlackBoard 2.0.0.2. Affected by this issue is some unknown functionality of the file \Users\username.BlackBoard of the component XML File Handler. The manipulation leads to unrestricted upload.
This vulnerability is handled as CVE-2024-51367. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-51366 | OmegaT 6.0.1 CONF File \Roaming\Omega unrestricted upload
1 day 12 hours ago
A vulnerability classified as critical was found in OmegaT 6.0.1. Affected by this vulnerability is an unknown functionality of the file \Roaming\Omega of the component CONF File Handler. The manipulation leads to unrestricted upload.
This vulnerability is known as CVE-2024-51366. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-51365 | VisiCut 2.1 ZIP File importSettings unrestricted upload
1 day 12 hours ago
A vulnerability classified as critical has been found in VisiCut 2.1. Affected is the function importSettings of the component ZIP File Handler. The manipulation leads to unrestricted upload.
This vulnerability is traded as CVE-2024-51365. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-51364 | ModbusMechanic 3.0 XML File unrestricted upload
1 day 12 hours ago
A vulnerability was found in ModbusMechanic 3.0. It has been rated as critical. This issue affects some unknown processing of the component XML File Handler. The manipulation leads to unrestricted upload.
The identification of this vulnerability is CVE-2024-51364. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-50054 | mySCADA myPRO Backend filename path traversal (icsa-24-326-07)
1 day 12 hours ago
A vulnerability was found in mySCADA myPRO. It has been declared as problematic. This vulnerability affects unknown code of the component Backend. The manipulation of the argument filename leads to path traversal: '.../...//'.
This vulnerability was named CVE-2024-50054. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47138 | mySCADA myPRO Administrative Interface missing authentication (icsa-24-326-07)
1 day 12 hours ago
A vulnerability was found in mySCADA myPRO. It has been classified as very critical. This affects an unknown part of the component Administrative Interface. The manipulation leads to missing authentication.
This vulnerability is uniquely identified as CVE-2024-47138. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45369 | mySCADA myPRO Web Application improper authentication (icsa-24-326-07)
1 day 12 hours ago
A vulnerability was found in mySCADA myPRO and classified as critical. Affected by this issue is some unknown functionality of the component Web Application. The manipulation leads to improper authentication.
This vulnerability is handled as CVE-2024-45369. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Top 10 rankings shake up in November | Red Canary Threat Intelligence
1 day 12 hours ago
Red Canary
CVE-2024-52034 | mySCADA myPRO Manager os command injection (icsa-24-326-07)
1 day 12 hours ago
A vulnerability has been found in mySCADA myPRO Manager and classified as very critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to os command injection.
This vulnerability is known as CVE-2024-52034. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com