Aggregator
CVE-2024-51851 | Saleh Attari Best Bootstrap Widgets for Elementor Plugin up to 1.0 on WordPress cross site scripting
Ubuntu security advisory (AV25-100)
Silent Killers: Unmasking a Large-Scale Legacy Driver Exploitation Campaign
Highlights Introduction While the abuse of vulnerable drivers has been around for a while, those that can terminate arbitrary processes have drawn increasing attention in recent years. As Windows security continues to evolve, it has become more challenging for attackers to execute malicious code without being detected. As a result, the attackers often aim to […]
The post Silent Killers: Unmasking a Large-Scale Legacy Driver Exploitation Campaign appeared first on Check Point Research.
CVE-2024-51852 | DynamicWebLab Dynamic Post Grid Elementor Addon Plugin up to 1.0.6 on WordPress cross site scripting
CVE-2024-51846 | Michael Simpson Community Yard Sale Plugin up to 1.1.11 on WordPress cross site scripting
CVE-2024-51850 | bchristopeit WoW Guild Armory Roster Plugin up to 0.5.5 on WordPress cross site scripting
CVE-2024-51847 | giovanebribeiro WP PagSeguro Payments Plugin up to 1.0 on WordPress cross site scripting
CVE-2024-51848 | Digital Zoom Studio Parallaxer Plugin up to 1.00 on WordPress cross site scripting
CVE-2024-51854 | Hola Networks Hola Free Video Player Plugin up to 1.3.9 on WordPress cross site scripting
CVE-2024-51855 | Productineer Redirecter Plugin up to 1.0 on WordPress cross site scripting
PoC exploit for Ivanti Endpoint Manager vulnerabilities released (CVE-2024-13159)
A proof-of-concept (PoC) exploit for four critical Ivanti Endpoint Manager vulnerabilities has been released by Horizon3.ai researchers. The vulnerabilities – CVE-2024-10811, CVE-2024-13161, CVE-2024-13160 and CVE-2024-13159 – may be exploited by remote, unauthenticated attackers to leverage Ivanti EPM machine account credentials for relay attacks and, ultimately, to compromise the Ivanti EPM server. “Compromising the Endpoint Manager server itself would lead to the ability to compromise all of the EPM clients, making this avenue especially impactful,” Horizon3.ai … More →
The post PoC exploit for Ivanti Endpoint Manager vulnerabilities released (CVE-2024-13159) appeared first on Help Net Security.