Aggregator
Behind the Scenes: Understanding CVE-2022-24547
1 year 6 months ago
Vulnerabilities can often be found in places we don’t expect, and CVE-2022-24547 in CastSrv.exe is
活动预告|CodeWisdom 软件智能化开发学术系列报告 第14期:重新定义团队协作-面向下一代软件工程的LLM Agents
1 year 6 months ago
Tse-Hsun (Peter) ChenLeader of the Software PErformance, Analysis, and Reliability (SPEAR) lab at Co
All I Want for Christmas is a CVE-2024-30085 Exploit
1 year 6 months ago
CVE-2024-30085 is a heap-based buffer overflow vulnerability affecting the Windows Cloud Files Mini
The Top 10 Data Breaches of 2024
1 year 6 months ago
2024 has been a tumultuous year in cybersecurity with numerous significant data breaches compromisin
活动预告|CodeWisdom 软件智能化开发学术系列报告 第14期:重新定义团队协作-面向下一代软件工程的LLM Agents
1 year 6 months ago
报告时间:2024年12月26日(周四)上午10:00
威努特为医疗物联网筑造安全防护矩阵
1 year 6 months ago
守护智慧医疗安全底线!
威努特为医疗物联网筑造安全防护矩阵
1 year 6 months ago
01IoMT背景介绍医疗物联网(IoMT:Internet of Medical Things)是物联网在医疗行业的重要应用。随着医疗行业大力推进数字化和智能化转型,IoMT技术已经成为提升医疗服务效
Daily Dose of Dark Web Informer - December 23rd, 2024
1 year 6 months ago
This daily article is intended to make it easier for those who want to stay updated with my regular Dark Web Informer and X/Twitter posts.
Dark Web Informer - Cyber Threat Intelligence
CVE-2018-25106 | webuidesigning NebulaX Theme up to 5.0 on WordPress libs/Legacy/Legacy.php nebula_send_to_hubspot sql injection
1 year 6 months ago
A vulnerability, which was classified as critical, has been found in webuidesigning NebulaX Theme up to 5.0 on WordPress. This issue affects the function nebula_send_to_hubspot of the file libs/Legacy/Legacy.php. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2018-25106. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
A Threat Actor Claims to be Selling the Data of Cashory
1 year 6 months ago
A Threat Actor Claims to be Selling the Data of Cashory
Dark Web Informer - Cyber Threat Intelligence
CVE-2002-1451 | Desiderata Software Blazix 1.2/1.2.1 HTTP Request Source information disclosure (EDB-21752 / Nessus ID 17151)
1 year 6 months ago
A vulnerability classified as critical was found in Desiderata Software Blazix 1.2/1.2.1. This vulnerability affects unknown code of the component HTTP Request Handler. The manipulation leads to information disclosure (Source).
This vulnerability was named CVE-2002-1451. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2013-1727 | Mozilla Firefox up to 23.0.1 file:/ cross site scripting (EDB-38766 / Nessus ID 70036)
1 year 6 months ago
A vulnerability was found in Mozilla Firefox up to 23.0.1. It has been declared as problematic. This vulnerability affects unknown code of the component file:/ Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2013-1727. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-8636 | Mozilla Firefox 34.0.5 XrayWrapper DOM Object code injection (MFSA2015-09 / EDB-36480)
1 year 6 months ago
A vulnerability was found in Mozilla Firefox 34.0.5. It has been rated as problematic. Affected by this issue is some unknown functionality of the component XrayWrapper. The manipulation as part of DOM Object leads to code injection.
This vulnerability is handled as CVE-2014-8636. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-44655 | Online Pre-owned Showroom Management System 1.0 Login Form sql injection (Exploit 50560 / EDB-50560)
1 year 6 months ago
A vulnerability was found in Online Pre-owned Showroom Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the component Login Form. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2021-44655. Access to the local network is required for this attack. Furthermore, there is an exploit available.
vuldb.com
U.S. CISA adds Acclaim Systems USAHERDS flaw to its Known Exploited Vulnerabilities catalog
1 year 6 months ago
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Acclaim Systems USAHERDS flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Acclaim Systems USAHERDS vulnerability, tracked as CVE-2021-44207 (CVSS score: 8.1) to its Known Exploited Vulnerabilities (KEV) catalog. USAHERDS, developed by Acclaim Systems, is a web-based application designed to […]
Pierluigi Paganini
CVE-2021-44207 | Acclaim USAHERDS up to 7.4.0.1 hard-coded credentials (MNDT-2021-0012)
1 year 6 months ago
A vulnerability classified as critical was found in Acclaim USAHERDS up to 7.4.0.1. This vulnerability affects unknown code. The manipulation leads to hard-coded credentials.
This vulnerability was named CVE-2021-44207. The attack can only be initiated within the local network. Furthermore, there is an exploit available.
vuldb.com
CVE-2023-32538 | Fuji Electric TELLUS/TELLUS Lite 4.0.15.0 SIM2 File stack-based overflow
1 year 6 months ago
A vulnerability, which was classified as critical, was found in Fuji Electric TELLUS and TELLUS Lite 4.0.15.0. Affected is an unknown function of the component SIM2 File Handler. The manipulation leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2023-32538. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-31239 | Fuji Electric V-Server/V-Server Lite up to 4.0.15.0 VPR File stack-based overflow
1 year 6 months ago
A vulnerability was found in Fuji Electric V-Server and V-Server Lite up to 4.0.15.0. It has been classified as critical. This affects an unknown part of the component VPR File Handler. The manipulation leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2023-31239. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
FBI, DC3, and NPA Identify North Korean Cyber Actors, Known as TraderTraitor, Behind $308 Million Cryptocurrency Theft from Bitcoin.DMM.com
1 year 6 months ago
FBI, DC3, and NPA Identify North Korean Cyber Actors, Known as TraderTraitor, Behind $308 Million Cryptocurrency Theft from Bitcoin.DMM.com
Dark Web Informer - Cyber Threat Intelligence