Aggregator
【安全圈】Atos旗下Eviden公司紧急发布安全公告:IDPKI解决方案曝出高危漏洞
9 months 3 weeks ago
【安全圈】马斯克DOGE网站数据库存在漏洞,任何人可随意篡改内容
9 months 3 weeks ago
MDR for OT Security: The Proactive Defense Against Industrial Cyber Threats
9 months 3 weeks ago
Enhance OT security with MDR. Prevent, detect, and respond to industrial cyber threats for robust protection of your critical infrastructure.
The post MDR for OT Security: The Proactive Defense Against Industrial Cyber Threats appeared first on Sygnia.
Sygnia
CVE-2004-1221 | Darryl Burgdorf WebLibs 1.0 weblibs.pl TextFile path traversal (EDB-24806 / XFDB-18399)
9 months 3 weeks ago
A vulnerability was found in Darryl Burgdorf WebLibs 1.0 and classified as problematic. This issue affects some unknown processing of the file weblibs.pl. The manipulation of the argument TextFile leads to path traversal.
The identification of this vulnerability is CVE-2004-1221. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-11387 | Easy Liveblogs Plugin up to 2.3.5 on WordPress cross site scripting
9 months 3 weeks ago
A vulnerability was found in Easy Liveblogs Plugin up to 2.3.5 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-11387. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-11332 | HIPAA Compliant Forms Plugin up to 1.3.4 on WordPress cross site scripting
9 months 3 weeks ago
A vulnerability was found in HIPAA Compliant Forms Plugin up to 1.3.4 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-11332. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-10880 | JobBoardWP Plugin up to 1.3.0 on WordPress cross site scripting
9 months 3 weeks ago
A vulnerability classified as problematic has been found in JobBoardWP Plugin up to 1.3.0 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-10880. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-1580 | PHPGurukul Nipah Virus Testing Management System 1.0 search-report-result.php searchdata sql injection
9 months 3 weeks ago
A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /search-report-result.php. The manipulation of the argument searchdata leads to sql injection.
This vulnerability is traded as CVE-2025-1580. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The initial researcher advisory mentions contradicting parameter names to be affected.
vuldb.com
CVE-2025-1579 | code-projects Blood Bank System 1.0 /admin/user.php email cross site scripting
9 months 3 weeks ago
A vulnerability was found in code-projects Blood Bank System 1.0 and classified as problematic. This issue affects some unknown processing of the file /admin/user.php. The manipulation of the argument email leads to cross site scripting.
The identification of this vulnerability is CVE-2025-1579. The attack may be initiated remotely. Furthermore, there is an exploit available.
Other parameters might be affected as well.
vuldb.com
CVE-2024-11362 | Payments Plugin and Checkout Plugin for WooCommerce Plugin cross site scripting
9 months 3 weeks ago
A vulnerability classified as problematic was found in Payments Plugin and Checkout Plugin for WooCommerce Plugin up to 1.112.0 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-11362. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-11188 | Formidable Forms Plugin up to 6.16.1.2 on WordPress cross site scripting
9 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Formidable Forms Plugin up to 6.16.1.2 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-11188. The attack may be launched remotely. There is no exploit available.
vuldb.com
加密货币 APT 情报:揭秘 Lazarus Group 入侵手法
9 months 3 weeks ago
网络安全对抗是一场持久战。
What is an Incident Response Retainer, Key Features and Benefits, and Why It Matters
9 months 3 weeks ago
Learn about incident response retainers, their key features, benefits, and why they are essential for protecting your organization from cyber threats.
The post What is an Incident Response Retainer, Key Features and Benefits, and Why It Matters appeared first on Sygnia.
Sygnia
CVE-2024-11426 | AutoListicle Plugin up to 1.2.3 on WordPress cross site scripting
9 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in AutoListicle Plugin up to 1.2.3 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-11426. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-52998 | Adobe Substance 3D Stager up to 3.0.2 out-of-bounds (apsb24-60)
9 months 3 weeks ago
A vulnerability classified as problematic has been found in Adobe Substance 3D Stager up to 3.0.2. This affects an unknown part. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2024-52998. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47863 | Centreon Web up to 24.10 user configuration contact name cross site scripting
9 months 3 weeks ago
A vulnerability was found in Centreon Web up to 24.10. It has been classified as problematic. Affected is an unknown function. The manipulation of the argument user configuration contact name leads to cross site scripting.
This vulnerability is traded as CVE-2024-47863. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-37783 | Gladinet CentreStack 13.12.9934.54690 ForgotPassword.aspx sessionId cross site scripting
9 months 3 weeks ago
A vulnerability was found in Gladinet CentreStack 13.12.9934.54690. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /portal/ForgotPassword.aspx. The manipulation of the argument sessionId leads to cross site scripting.
This vulnerability is known as CVE-2024-37783. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-11330 | Custom CSS, JS & PHP Plugin up to 2.3.0 on WordPress cross site scripting
9 months 3 weeks ago
A vulnerability classified as problematic was found in Custom CSS, JS & PHP Plugin up to 2.3.0 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-11330. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-10519 | Wishlist for WooCommerce Plugin up to 3.1.2 on WordPress wtab cross site scripting
9 months 3 weeks ago
A vulnerability was found in Wishlist for WooCommerce Plugin up to 3.1.2 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument wtab leads to cross site scripting.
This vulnerability is handled as CVE-2024-10519. The attack may be launched remotely. There is no exploit available.
vuldb.com