Pirated software seekers are targeted by the new MassJacker clipper malware, according to CyberArk researchers. A new malware campaign spreading a new clipper malware dubbed MassJacker targets users searching for pirated software, Cyberark users warn. A clipper malware is a type of malicious software designed to intercept and manipulate clipboard data, typically for cryptocurrency theft. […]
A vulnerability was found in Ivanti Docs@Work on Android. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2024-37403. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Accept Stripe Payments Plugin up to 2.0.86 on WordPress. It has been rated as problematic. This issue affects the function accept_stripe_payment_ng of the component Shortcode Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-7353. The attack may be initiated remotely. There is no exploit available.
A vulnerability was found in Organization Chart Plugin up to 1.5.0 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation of the argument title_input/node_description leads to cross site scripting.
This vulnerability was named CVE-2024-7355. The attack can be initiated remotely. There is no exploit available.
A vulnerability classified as problematic was found in Cisco ASA and Identity Services Engine. Affected by this vulnerability is an unknown functionality of the component Web-based Management Interface. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-20443. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Cisco Identity Services Engine and classified as problematic. This vulnerability affects unknown code of the component Web-based Management Interface. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-20479. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Kashipara Responsive School Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /smsa/add_class_submit.php. The manipulation of the argument class_name leads to cross site scripting.
This vulnerability was named CVE-2024-41239. The attack can be initiated remotely. There is no exploit available.
A vulnerability, which was classified as problematic, has been found in MainWP Child Reports Plugin up to 2.2 on WordPress. This issue affects some unknown processing of the component Options Update Handler. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2024-7492. The attack may be initiated remotely. There is no exploit available.
A vulnerability classified as problematic has been found in Lightbox & Modal Popup Plugin up to 2.7.28 on WordPress. Affected is an unknown function of the component HTML Data Attribute Handler. The manipulation leads to HTML injection.
This vulnerability is traded as CVE-2024-5668. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability classified as problematic was found in Brizy Plugin up to 2.5.1 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2024-6254. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in Kashipara Responsive School Management System 3.2.0. It has been classified as problematic. Affected is an unknown function of the file /smsa/teacher_login.php. The manipulation of the argument error leads to cross site scripting.
This vulnerability is traded as CVE-2024-41240. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability was found in Kashipara Responsive School Management System 3.2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /smsa/student_login.php. The manipulation of the argument error leads to cross site scripting.
This vulnerability is known as CVE-2024-41242. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in Open WebUI 0.1.105. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-6706. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability was found in Kashipara Responsive School Management System 3.2.0 and classified as problematic. This issue affects some unknown processing of the file /smsa/admin_login.php. The manipulation of the argument error leads to cross site scripting.
The identification of this vulnerability is CVE-2024-41241. The attack may be initiated remotely. There is no exploit available.
A vulnerability was found in Apple Mac OS X up to 10.4. It has been classified as critical. This affects an unknown part. The manipulation of the argument num_sels leads to memory corruption.
This vulnerability is uniquely identified as CVE-2007-4684. The attack needs to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5. It has been declared as problematic. This vulnerability affects the function updateQuestionCou of the file /api/mjkj-chat/chat/mng/update/questionCou of the component Number of Question Handler. The manipulation leads to enforcement of behavioral workflow.
This vulnerability was named CVE-2025-2323. The attack can be initiated remotely. Furthermore, there is an exploit available.
This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability has been found in Apple Safari up to 10.0.2 and classified as critical. This vulnerability affects unknown code of the component WebKit. The manipulation leads to memory corruption.
This vulnerability was named CVE-2017-2373. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in FFmpeg up to 5.1.5. This affects the function fill_audiodata of the file /libswresample/swresample.c. The manipulation leads to heap-based buffer overflow.
This vulnerability is uniquely identified as CVE-2024-7272. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in daniyalahmedk Fuse Social Floating Sidebar Plugin up to 5.4.10 on WordPress. Affected is an unknown function of the component File Upload. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-5226. It is possible to launch the attack remotely. There is no exploit available.