Aggregator
CNVD漏洞周报2024年第46期
1 year 5 months ago
首发 | 特朗普政府对华网络政策评估
1 year 5 months ago
网络战是选项
CVE-2024-51037 | kalcaddle kodbox up to 1.52.04 Captcha information disclosure
1 year 5 months ago
A vulnerability was found in kalcaddle kodbox up to 1.52.04. It has been classified as problematic. This affects an unknown part of the component Captcha. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-51037. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-52871 | Flagsmith up to 2.134.0 Setting access control
1 year 5 months ago
A vulnerability was found in Flagsmith up to 2.134.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Setting Handler. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2024-52871. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52872 | Flagsmith up to 2.134.0 get_document permission
1 year 5 months ago
A vulnerability classified as critical has been found in Flagsmith up to 2.134.0. This affects the function get_document. The manipulation leads to permission issues.
This vulnerability is uniquely identified as CVE-2024-52872. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-10486 | Google for WooCommerce Plugin up to 2.8.6 on WordPress information disclosure
1 year 5 months ago
A vulnerability, which was classified as problematic, was found in Google for WooCommerce Plugin up to 2.8.6 on WordPress. This affects an unknown part. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-10486. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
Древние галактики и следы воды: главные находки James Webb
1 year 5 months ago
Открытия телескопа продолжают удивлять.
Warning: VMware vCenter and Kemp LoadMaster Flaws Under Active Exploitation
1 year 5 months ago
Now-patched security flaws impacting Progress Kemp LoadMaster and VMware vCenter Server have come under active exploitation in the wild, it has emerged.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added CVE-2024-1212 (CVSS score: 10.0), a maximum-severity security vulnerability in Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog. It was
The Hacker News
CVE-2024-4343 | imartinez privategpt up to 0.3.0 SageMaker LLM Endpoint sagemaker.py complete os command injection
1 year 5 months ago
A vulnerability classified as very critical was found in imartinez privategpt up to 0.3.0. Affected by this vulnerability is the function complete of the file /private_gpt/components/llm/custom/sagemaker.py of the component SageMaker LLM Endpoint. The manipulation leads to os command injection.
This vulnerability is known as CVE-2024-4343. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52524 | Giskard-AI giskard up to 2.15.4 redos (GHSA-pjwm-cr36-mwv3)
1 year 5 months ago
A vulnerability classified as problematic has been found in Giskard-AI giskard up to 2.15.4. This affects an unknown part. The manipulation leads to inefficient regular expression complexity.
This vulnerability is uniquely identified as CVE-2024-52524. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-3760 | lunary-ai lunary up to 1.2.7 allocation of resources
1 year 5 months ago
A vulnerability was found in lunary-ai lunary up to 1.2.7. It has been classified as critical. Affected is an unknown function. The manipulation leads to allocation of resources.
This vulnerability is traded as CVE-2024-3760. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-3501 | lunary-ai lunary up to 1.2.5 API Endpoint /v1/users/me information disclosure
1 year 5 months ago
A vulnerability, which was classified as problematic, was found in lunary-ai lunary up to 1.2.5. This affects an unknown part of the file /v1/users/me of the component API Endpoint. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-3501. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-3502 | lunary-ai lunary up to 1.2.5 User Password information disclosure (dec-4538-8905)
1 year 5 months ago
A vulnerability was found in lunary-ai lunary up to 1.2.5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component User Password Handler. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2024-3502. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-3379 | lunary-ai lunary up to 1.2.6 authorization
1 year 5 months ago
A vulnerability has been found in lunary-ai lunary up to 1.2.6 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to incorrect authorization.
This vulnerability is known as CVE-2024-3379. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-4134 | Linux Kernel up to 6.4 cyttsp4_core.c cyttsp4_stop_wd_timer use after free
1 year 5 months ago
A vulnerability was found in Linux Kernel up to 6.4. It has been declared as problematic. Affected by this vulnerability is the function cyttsp4_stop_wd_timer of the file drivers/input/touchscreen/cyttsp4_core.c. The manipulation leads to use after free.
This vulnerability is known as CVE-2023-4134. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
美国饮用水系统存在300多个漏洞,影响1.1亿人
1 year 5 months ago
美国环境保护署(EPA)标记了300多个饮用水系统的安全漏洞,这些系统为大约1.1亿人提供服务。
Ransomware Evolution: From Triple-Quadruple Extortion to RaaS
1 year 5 months ago
In 1989, the first ransomware attack was recorded. It was the foundational ground that laid the wave of digital invasions that the world has been witnessing with an attack occuring every two seconds. From the monetary aspect, a 30% increase in damage is seen every year. The amount is expected to cross $265 billion by […]
The post Ransomware Evolution: From Triple-Quadruple Extortion to RaaS appeared first on Kratikal Blogs.
The post Ransomware Evolution: From Triple-Quadruple Extortion to RaaS appeared first on Security Boulevard.
Puja Saikia
CVE-2024-43530 | Microsoft Windows 10 21H2/10 22H2/11 22H2/11 23H2/Server 2022 Update Stack access control
1 year 5 months ago
A vulnerability, which was classified as critical, was found in Microsoft Windows 10 21H2/10 22H2/11 22H2/11 23H2/Server 2022. Affected is an unknown function of the component Update Stack. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2024-43530. Attacking locally is a requirement. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-49046 | Microsoft Windows up to Server 2025 Win32 Kernel Subsystem toctou
1 year 5 months ago
A vulnerability was found in Microsoft Windows. It has been rated as critical. Affected by this issue is some unknown functionality of the component Win32 Kernel Subsystem. The manipulation leads to time-of-check time-of-use.
This vulnerability is handled as CVE-2024-49046. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com