Aggregator
CVE-2024-12717 | Aklamator INfeed Plugin up to 2.0.0 on WordPress Setting cross site scripting
1 year 5 months ago
A vulnerability was found in Aklamator INfeed Plugin up to 2.0.0 on WordPress. It has been declared as problematic. This vulnerability affects unknown code of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-12717. The attack can be initiated remotely. There is no exploit available.
vuldb.com
Ivanti VPN 零日漏洞正在被黑客利用
1 year 5 months ago
主站 分类 漏洞 工具 极客
Ivanti VPN 零日漏洞正在被黑客利用
1 year 5 months ago
Ivanti 公开披露了影响 ICS VPN 设备的两个关键漏洞: CVE-2025-0282 和 CVE-2025-0283。
CVE-2024-12736 | BU Section Editing Plugin up to 0.9.9 on WordPress cross site scripting
1 year 5 months ago
A vulnerability was found in BU Section Editing Plugin up to 0.9.9 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-12736. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-12715 | Asgard Security Scanner Plugin up to 0.7 on WordPress cross site scripting
1 year 5 months ago
A vulnerability was found in Asgard Security Scanner Plugin up to 0.7 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-12715. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-10815 | PostLists Plugin up to 2.0.2 on WordPress $_SERVER['REQUEST_URI'] cross site scripting
1 year 5 months ago
A vulnerability, which was classified as problematic, was found in PostLists Plugin up to 2.0.2 on WordPress. Affected is an unknown function. The manipulation of the argument $_SERVER['REQUEST_URI'] leads to cross site scripting.
This vulnerability is traded as CVE-2024-10815. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-6324 | GitLab Community Edition/Enterprise Edition up to 17.5.4/17.6.2/17.7.0 algorithmic complexity (Issue 468914 / Nessus ID 213595)
1 year 5 months ago
A vulnerability has been found in GitLab Community Edition and Enterprise Edition up to 17.5.4/17.6.2/17.7.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to inefficient algorithmic complexity.
This vulnerability is known as CVE-2024-6324. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-12731 | Aklamator INfeed Plugin up to 2.0.0 on WordPress cross site scripting
1 year 5 months ago
A vulnerability, which was classified as problematic, has been found in Aklamator INfeed Plugin up to 2.0.0 on WordPress. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-12731. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-12714 | Backlink Monitoring Manager Plugin up to 0.1.3 on WordPress cross site scripting
1 year 5 months ago
A vulnerability classified as problematic was found in Backlink Monitoring Manager Plugin up to 0.1.3 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-12714. The attack can be initiated remotely. There is no exploit available.
vuldb.com
三星准备推出智能手机订阅服务
1 year 5 months ago
登录 注册
三星准备推出智能手机订阅服务
1 year 5 months ago
三星准备下个月为其智能手机和平板设备引入 AI Subscription Club 订阅服务,允许消费者租用/订阅 Galaxy 系列智能手机和平板,名字中的 AI 表示它适用于支持 AI 功能的设备。以一次性价格购买有 AI 功能的 Galaxy 设备的用户暂时不受影响,他们可以免费使用 AI 功能至 2025 年年底,但之后是否收费暂时不清楚。该订阅服务的商业模式类似 Netflix 和 Spotify 等流媒体服务。
俄乌网络战大事件,乌克兰黑客黑掉了俄罗斯互联网
1 year 5 months ago
主站 分类 漏洞 工具 极客
俄乌网络战大事件,乌克兰黑客黑掉了俄罗斯互联网
1 year 5 months ago
乌克兰黑客组织宣布,他们已经攻破了俄罗斯互联网服务提供商Nodex的网络,并在窃取敏感文件后清空了系统。
Ivanti 0-Day Vulnerability Exploited in Wild-Patch Now
1 year 5 months ago
Ivanti released a critical security advisory addressing vulnerabilities in its Connect Secure, Policy Secure, and ZTA Gateways products. This advisory reveals the existence of two significant vulnerabilities, CVE-2025-0282 and CVE-2025-0283, which have been exploited in the wild, necessitating immediate action from users. Critical Vulnerability: CVE-2025-0282 CVE-2025-0282 is a stack-based buffer overflow vulnerability that affects Ivanti […]
The post Ivanti 0-Day Vulnerability Exploited in Wild-Patch Now appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Divya
绿湾包装工队官方商店遭黑客入侵,客户信息被盗风险大增!
1 year 5 months ago
绿湾包装工队(Green Bay Packers)美式足球队通知球迷,一名威胁行为者于 10 月份入侵了其官方线上零售店,并注入了卡片盗刷脚本,以窃取客户的个人和支付信息。
警惕!假冒社会保障局邮件链接暗藏ConnectWise RAT木马
1 year 5 months ago
威胁行为者利用社会工程技术部署凭证网络钓鱼活动,他们制作模仿合法实体(例如社会保障局)的电子邮件来诱骗受害者点击恶意链接。
绿湾包装工队官方商店遭黑客入侵,客户信息被盗风险大增!
1 year 5 months ago
绿湾包装工队(Green Bay Packers)美式足球队通知球迷,一名威胁行为者于 10 月份入侵了其官方线上零售店,并注入了卡片盗刷脚本,以窃取客户的个人和支付信息。国家橄榄球联盟球队表示,10
警惕!假冒社会保障局邮件链接暗藏ConnectWise RAT木马
1 year 5 months ago
2024 年 9 月出现了一场冒充美国社会保障局的网络钓鱼活动,它向电子邮件发送嵌入了 ConnectWise 远程访问木马 (RAT) 安装程序链接的电子邮件。这些电子邮件伪装成更新的福利声明,采用
ZDI-CAN-26247: Apple
1 year 5 months ago
A CVSS score 3.3 AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N severity vulnerability discovered by 'Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative' was reported to the affected vendor on: 2025-01-09, 54 days ago. The vendor is given until 2025-05-09 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.