CVE Alert: CVE-2024-10392
Vulnerability Summary: CVE-2024-10392 The AI Power: Complete AI Pack plugin for WordPress is vulnerable to arbitrary file uploads due to...
Vulnerability Summary: CVE-2024-10392 The AI Power: Complete AI Pack plugin for WordPress is vulnerable to arbitrary file uploads due to...
Vulnerability Summary: CVE-2024-9434 The WPGlobus Translate Options plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up...
Vulnerability Summary: CVE-2024-9700 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable...
Vulnerability Summary: CVE-2024-9446 The WP Simple Anchors Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
Vulnerability Summary: CVE-2024-9165 The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to Stored Cross-Site...
Vulnerability Summary: CVE-2024-9430 The Get Quote For Woocommerce – Request A Quote For Woocommerce plugin for WordPress is vulnerable to...
Vulnerability Summary: CVE-2024-43930 Cross-Site Request Forgery (CSRF) vulnerability in eyecix JobSearch allows Cross Site Request Forgery.This issue affects JobSearch: from...
Vulnerability Summary: CVE-2024-43383 Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator. This issue affects Apache Lucene.NET's Replicator library: from 4.8.0-beta00005...
Vulnerability Summary: CVE-2024-30149 HCL AppScan Source
Vulnerability Summary: CVE-2024-49685 Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds (Tweets Widget) allows Cross Site Request...
Vulnerability Summary: CVE-2024-49674 Cross-Site Request Forgery (CSRF) vulnerability in Lukas Huser EKC Tournament Manager allows Upload a Web Shell to...
Vulnerability Summary: CVE-2024-10454 Clickjacking vulnerability in Clibo Manager v1.1.9.12 in the '/public/login' directory, a login panel. This vulnerability occurs due...
Vulnerability Summary: CVE-2024-43984 Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue affects Podlove Podcast...
Vulnerability Summary: CVE-2024-43933 Cross-Site Request Forgery (CSRF) vulnerability in WPMobile.App allows Stored XSS.This issue affects WPMobile.App: from n/a through 11.48....
Vulnerability Summary: CVE-2024-8934 A local user with administrative access rights can enter specialy crafted values for settings at the user...
Vulnerability Summary: CVE-2024-8553 A vulnerability was found in Foreman's loader macros introduced with report templates. These macros may allow an...
Vulnerability Summary: CVE-2024-51254 DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling...
Vulnerability Summary: CVE-2024-42835 langflow v1.0.12 was discovered to contain a remote code execution (RCE) vulnerability via the PythonCodeTool component. Affected...
Vulnerability Summary: CVE-2024-51259 DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling...
Vulnerability Summary: CVE-2024-48910 DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to...
Ransomware Group: RHYSIDA VICTIM NAME: Hope Valley Recovery NOTE: No files or stolen information are by RedPacket Security. Any legal...
Ransomware Group: CACTUS VICTIM NAME: lsstac NOTE: No files or stolen information are by RedPacket Security. Any legal issues relating...
The Information provided at the time of posting was detected as "Cobalt Strike". Depending on when you are viewing this...
Cybersecurity researchers have flagged a "massive" campaign that targets exposed Git configurations to siphon credentials, clone private repositories, and even...