Aggregator
CVE-2024-53472 | WeGIA 3.2.0 cross-site request forgery
CVE-2024-53470 | WeGIA 3.2.0 gateway_pagamento.php id/name cross site scripting
CVE-2024-11379 | Broadcast Plugin up to 51.01 on WordPress cross site scripting
CVE-2024-10836 | Flixita Plugin up to 1.0.82 on WordPress id cross site scripting
CVE-2024-9769 | Video Gallery Plugin up to 2.4.1 on WordPress cross site scripting
Auto-Generated Password Vulnerability In Sitevision Leaks Signing Key
A critical security flaw in Sitevision CMS versions 10.3.1 and older has exposed SAML authentication signing keys, enabling potential authentication bypass and session hijacking. The vulnerability, tracked as CVE-2022-35202, stems from weak auto-generated passwords protecting Java keystores, which could be extracted and brute-forced to compromise private keys. Sitevision, a widely adopted content management system in […]
The post Auto-Generated Password Vulnerability In Sitevision Leaks Signing Key appeared first on Cyber Security News.
CVE-2024-49041 | Microsoft Edge up to 131.0.2903.63 the ui performs the wrong action (Nessus ID 212105)
CVE-2024-11201 | myCred Plugin up to 2.7.5.2 on WordPress Shortcode mycred_send cross site scripting
CVE-2024-10879 | ForumWP Plugin up to 2.1.2 on WordPress cross site scripting
CVE-2024-11204 | ForumWP Plugin up to 2.1.2 on WordPress URL Parameter cross site scripting
CVE-2024-2776 | Campcodes Online Marriage Registration System 1.0 /admin/search.php searchdata sql injection
CVE-2024-2943 | Campcodes Online Examination System 1.0 deleteExamExe.php id sql injection
CVE-2024-2944 | Campcodes Online Examination System 1.0 deleteCourseExe.php id sql injection
CVE-2024-2945 | Campcodes Online Examination System 1.0 updateExaminee.php id sql injection
CVE-2024-33553 | 8theme XStore Core Plugin up to 5.3.5 on WordPress deserialization
CVE-2024-33558 | 8theme XStore Core Plugin up to 5.3.5 on WordPress authorization
Cases of China-Backed Spy Groups Using Ransomware Come to Light
Cyberattacks detected by Trend Micro and Orange Cyberdefense find hackers using malware linked to China-backed groups and ransomware, adding more evidence that nation-state cyberespionage groups are also now using ransomware and further blurring the line between the two.
The post Cases of China-Backed Spy Groups Using Ransomware Come to Light appeared first on Security Boulevard.