Aggregator
AT&T and Verizon Say Chinese Hackers Ejected From Networks
5 months 2 weeks ago
9 Telcos Have Been Breached by Beijing-Backed 'Salt Typhoon,' White House Says
U.S. telecommunications giants AT&T and Verizon Communications believe they have finally ejected Chinese cyber espionage hackers from their networks. The White House said the "Salt Typhoon" nation-state hackers infiltrated at least nine U.S. telcos' infrastructure, and have been hard to eject.
U.S. telecommunications giants AT&T and Verizon Communications believe they have finally ejected Chinese cyber espionage hackers from their networks. The White House said the "Salt Typhoon" nation-state hackers infiltrated at least nine U.S. telcos' infrastructure, and have been hard to eject.
A Happy, Prosperous & Safe New Year Wish For All
5 months 2 weeks ago
via Photographer Marjory Collins in New York City, NY, USA, January 1943, Blowing Horns on Bleeker Street, New Year's Day
The post A Happy, Prosperous & Safe New Year Wish For All appeared first on Security Boulevard.
Marc Handelman
SecWiki News 2024-12-31 Review
5 months 2 weeks ago
今日暂未更新资讯~
更多最新文章,请访问SecWiki
更多最新文章,请访问SecWiki
2025 | 从“Hello, World!”到未来无限可能
5 months 2 weeks ago
元旦如同一段全新的代码,每一行都是通往梦想的注解。用热爱定义变量,用努力赋值未来,愿新的一年,你能编译出属于自己的奇迹与成功!
Z-BL4CX-H4T Defaced the Website of World Lotto
5 months 2 weeks ago
Z-BL4CX-H4T Defaced the Website of World Lotto
Dark Web Informer - Cyber Threat Intelligence
CVE-2024-56230 | Dynamic Web Lab Dynamic Product Category Grid, Slider for WooCommerce Plugin filename control
5 months 2 weeks ago
A vulnerability was found in Dynamic Web Lab Dynamic Product Category Grid, Slider for WooCommerce Plugin up to 1.1.3 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is handled as CVE-2024-56230. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-56217 | W3 Eden Download Manager Plugin up to 3.3.03 on WordPress authorization
5 months 2 weeks ago
A vulnerability classified as problematic has been found in W3 Eden Download Manager Plugin up to 3.3.03 on WordPress. Affected is an unknown function. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2024-56217. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-56219 | MarketingFire Widget Options Plugin up to 4.0.6.1 on WordPress authorization
5 months 2 weeks ago
A vulnerability classified as problematic was found in MarketingFire Widget Options Plugin up to 4.0.6.1 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to missing authorization.
This vulnerability is known as CVE-2024-56219. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-56215 | Stephen Sherrard Member Directory and Contact Form Plugin up to 1.7.0 on WordPress authorization
5 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Stephen Sherrard Member Directory and Contact Form Plugin up to 1.7.0 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to missing authorization.
This vulnerability is handled as CVE-2024-56215. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-12105 | Progress WhatsUp Gold up to 2024.0.1 HTTP Request path traversal
5 months 2 weeks ago
A vulnerability was found in Progress WhatsUp Gold up to 2024.0.1 and classified as critical. This issue affects some unknown processing of the component HTTP Request Handler. The manipulation leads to path traversal.
The identification of this vulnerability is CVE-2024-12105. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-12106 | Progress WhatsUp Gold up to 2024.0.1 LDAP Setting missing authentication
5 months 2 weeks ago
A vulnerability was found in Progress WhatsUp Gold up to 2024.0.1. It has been classified as critical. This affects an unknown part of the component LDAP Setting Handler. The manipulation leads to missing authentication.
This vulnerability is uniquely identified as CVE-2024-12106. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-12108 | Progress WhatsUp Gold up to 2024.0.1 Public API authentication spoofing
5 months 2 weeks ago
A vulnerability was found in Progress WhatsUp Gold up to 2024.0.1. It has been declared as critical. This vulnerability affects unknown code of the component Public API. The manipulation leads to authentication bypass by spoofing.
This vulnerability was named CVE-2024-12108. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-41738 | IBM Storage Scale Container Native Storage Access up to 5.1.7.0 improper authentication (XFDB-237812)
5 months 2 weeks ago
A vulnerability, which was classified as critical, was found in IBM Storage Scale Container Native Storage Access up to 5.1.7.0. This affects an unknown part of the component Container Handler. The manipulation leads to improper authentication.
This vulnerability is uniquely identified as CVE-2022-41738. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-41737 | IBM Storage Scale Container Native Storage Access up to 5.1.7.0 improper authentication (XFDB-237811)
5 months 2 weeks ago
A vulnerability was found in IBM Storage Scale Container Native Storage Access up to 5.1.7.0 and classified as problematic. This issue affects some unknown processing. The manipulation leads to improper authentication.
The identification of this vulnerability is CVE-2022-41737. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-1644 | SuiteCRM 7.14.2 unrestricted upload
5 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in SuiteCRM 7.14.2. This issue affects some unknown processing. The manipulation leads to unrestricted upload.
The identification of this vulnerability is CVE-2024-1644. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-1297 | Loomio 2.22.0 os command injection
5 months 2 weeks ago
A vulnerability, which was classified as very critical, has been found in Loomio 2.22.0. Affected by this issue is some unknown functionality. The manipulation leads to os command injection.
This vulnerability is handled as CVE-2024-1297. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-1750 | TemmokuMVC up to 2.3 Image Download lib/images_get_down.php get_img_url/img_replace deserialization
5 months 2 weeks ago
A vulnerability, which was classified as critical, was found in TemmokuMVC up to 2.3. Affected is the function get_img_url/img_replace in the library lib/images_get_down.php of the component Image Download Handler. The manipulation leads to deserialization.
This vulnerability is traded as CVE-2024-1750. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2022-43842 | IBM Aspera Console up to 3.4.2 sql injection (XFDB-239079)
5 months 2 weeks ago
A vulnerability was found in IBM Aspera Console up to 3.4.2 and classified as critical. This issue affects some unknown processing. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2022-43842. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-27087 | kirby up to 4.1.0 javascript URL link cross site scripting (GHSA-63h4-w25c-3qv4)
5 months 2 weeks ago
A vulnerability was found in kirby up to 4.1.0. It has been classified as problematic. This affects an unknown part of the component javascript URL Handler. The manipulation of the argument link leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-27087. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com