CVE-2024-33059 – Apache Web Server Memory Corruption Vulnerability

The following table lists the changes that have been made to the CVE-2024-33059 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 06, 2025 Action […]

CVE-2024-33055 – Acronis Storage OpenStack flaw in IOCTL Handler

The following table lists the changes that have been made to the CVE-2024-33055 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 06, 2025 Action […]

CVE-2024-23366 – Apache James Information Disclosure

The following table lists the changes that have been made to the CVE-2024-23366 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 06, 2025 Action […]

CVE-2024-21464 – Cisco ASA Denial of Service

The following table lists the changes that have been made to the CVE-2024-21464 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 06, 2025 Action […]

Haunted — Blue Team Labs Online Write-up

Haunted — Blue Team Labs Online Write-up HauntedOne of the company’s websites has been defaced, raising alarms. Collaborate with other analysts to uncover the identity of the adversary and assess the situation.Category: Threat IntelligenceTo … Read more Published Date: Jan 06, 2025 (23 hours, 18 minutes ago) Vulnerabilities has been mentioned in this article.

CVE-2024-10957: UpdraftPlus WordPress Plugin Vulnerability

CVE-2024-10957: UpdraftPlus WordPress Plugin Vulnerability CVE-2024-10957 is a high-severity vulnerability affecting the UpdraftPlus: WP Backup & Migration Plugin for WordPress. This vulnerability, present in versions up to and including 1.24.11, enables atta … Read more Published Date: Jan 06, 2025 (1 day ago) Vulnerabilities has been mentioned in this article. CVE-2024-10957 CVE-2024-12108 CVE-2024-11944 CVE-2024-12987 CVE-2024-49113 CVE-2024-43405 […]

EAGERBEE, with updated and novel components, targets the Middle East

EAGERBEE, with updated and novel components, targets the Middle East Introduction In our recent investigation into the EAGERBEE backdoor, we found that it was being deployed at ISPs and governmental entities in the Middle East. Our analysis uncovered new components use … Read more Published Date: Jan 06, 2025 (1 day, 1 hour ago) Vulnerabilities has been […]

CVE-2024-12311 – Icegram Express WordPress Plugin SQL Injection Vulnerability

CVE ID : CVE-2024-12311 Published : Jan. 6, 2025, 6:15 a.m. | 38 minutes ago Description : The Email Subscribers by Icegram Express WordPress plugin before 5.7.44 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks Severity: 0.0 | NA Visit the link for […]

CVE-2024-11849 – Pods WordPress Stored Cross-Site Scripting (XSS)

CVE ID : CVE-2024-11849 Published : Jan. 6, 2025, 6:15 a.m. | 38 minutes ago Description : The Pods WordPress plugin before 3.2.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example […]

CVE-2024-12302 – Icegram Engage Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2024-12302 Published : Jan. 6, 2025, 6:15 a.m. | 38 minutes ago Description : The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its Campaign settings, which could allow authors and above to perform Stored Cross-Site Scripting attacks Severity: 0.0 | NA Visit the link for more details, […]