Aggregator
CVE-2024-2203 | Plus Addons for Elementor Plugin up to 5.4.1 on WordPress Clients Widget file inclusion (ID 3056776)
CVE-2024-2139 | Master Addons for Elementor Plugin up to 2.0.5.6 on WordPress Pricing Table Widget cross site scripting (ID 3050636)
CVE-2024-2210 | Plus Addons for Elementor Plugin up to 5.4.1 on WordPress Team Member Listing file inclusion (ID 3056776)
CVE-2024-2120 | Elementor Website Builder Plugin up to 3.20.1 on WordPress Post Navigation cross site scripting
CVE-2024-2956 | Simple Ajax Chat Plugin up to 20231101 on WordPress cross site scripting
CVE-2024-2962 | Networker Plugin up to 1.1.9 on WordPress authorization
CVE-2024-1770 | Meta Tag Manager Plugin up to 3.0.2 on WordPress code injection (ID 3054910)
CVE-2024-2091 | Elementor Addon Elements Plugin up to 1.13.1 on WordPress cross site scripting
CVE-2024-2110 | Events Manager Plugin up to 6.4.7.1 on WordPress cross-site request forgery (ID 3054883)
CVE-2024-2111 | Events Manager Plugin up to 6.4.7.1 on WordPress cross site scripting
CVE-2024-2841 | Otter Blocks Plugin up to 2.6.5 on WordPress cross site scripting
CVE-2024-2475 | Media Library Assistant Plugin up to 3.13 on WordPress Shortcode mla_gallery cross site scripting
Nginx 1.29.8 and FreeNginx Released With Critical Security Updates
Web server administrators must prioritize updating their infrastructure, as Nginx 1.29.8 and the parallel FreeNginx project have officially released critical updates. Released on April 7, 2026, these new versions introduce essential security features, enhanced cryptographic compatibility, and crucial bug fixes designed to ensure robust server performance and defend against modern cyber threats. FreeNginx, the fork […]
The post Nginx 1.29.8 and FreeNginx Released With Critical Security Updates appeared first on Cyber Security News.
Mirax Android Trojan Turns Devices Into Residential Proxy Nodes
Red Hat security advisory (AV26-341)
Building a CLI for all of Cloudflare
Marimo RCE Vulnerability Exploited in the Within 10 Hours of Disclosure
A critical vulnerability was disclosed in Marimo, an open-source reactive Python notebook platform. Less than 10 hours later, attackers successfully weaponized the flaw to steal sensitive cloud credentials, highlighting the extreme speed of modern threat actors. The security flaw is formally tracked as CVE-2026-39987 (formerly GHSA-2679-6mx9-h9xc) and carries a Critical CVSS v4.0 score of 9.3. […]
The post Marimo RCE Vulnerability Exploited in the Within 10 Hours of Disclosure appeared first on Cyber Security News.
До пяти лет за публикацию, тюрьма для директора платформы. Новый закон впервые делает CEO лично ответственным за то, что публикуют пользователи его сайта
Critical Axios Vulnerability Allows Remote Code Execution – PoC Released
The cybersecurity community is on high alert after the disclosure of a critical security flaw in Axios, a widely used promise-based HTTP client for Node.js and browsers. Security researcher Jason Saayman recently disclosed an unrestricted vulnerability that allows exfiltration of cloud metadata. This dangerous flaw enables attackers to execute remote code or compromise the entire cloud […]
The post Critical Axios Vulnerability Allows Remote Code Execution – PoC Released appeared first on Cyber Security News.