CVE-2024-12131 – WordPress WP Job Portal Insecure Direct Object Reference
CVE ID : CVE-2024-12131 Published : Jan. 7, 2025, 1:15 p.m. | 22 minutes ago Description : The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.5 due to missing validation on a […]
SonicWall waarschuwt voor actief misbruikt lek in SSLVPN-functie firewalls
SonicWall waarschuwt voor actief misbruikt lek in SSLVPN-functie firewalls SonicWall waarschuwt organisaties voor een actief aangevallen kwetsbaarheid in de SSLVPN-functionaliteit van de firewalls die het biedt. Een beveiligingsupdate om het probleem te verhelpen zou vandaag … Read more Published Date: Jan 07, 2025 (1 hour, 24 minutes ago) Vulnerabilities has been mentioned in this article.
SonicWall verhelpt authentication bypass in SSLVPN-functie firewalls
SonicWall verhelpt authentication bypass in SSLVPN-functie firewalls dinsdag 7 januari 2025, 13:25 door Redactie, 3 reactiesLaatst bijgewerkt: Vandaag, 08:35 SonicWall heeft een authentication bypass in de SSLVPN-functionaliteit van SonicOS verholpen, het besturingssys … Read more Published Date: Jan 07, 2025 (21 hours, 45 minutes ago) Vulnerabilities has been mentioned in this article.
CVE-2024-52891 – IBM Concert Software CSRF Log Injection Vulnerability
The following table lists the changes that have been made to the CVE-2024-52891 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 07, 2025 Action […]
CVE-2024-52893 – IBM Concert Software Information Disclosure Vulnerability
The following table lists the changes that have been made to the CVE-2024-52893 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 07, 2025 Action […]
CVE-2024-12711 – “WordPress RSVP and Event Management Plugin Authentication Bypass”
CVE ID : CVE-2024-12711 Published : Jan. 7, 2025, 12:15 p.m. | 38 minutes ago Description : The RSVP and Event Management plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX functions like bulk_delete_attendees() and bulk_delete_questions() in all versions up to, and including, 2.7.13. This makes it possible […]
CVE-2024-52367 – IBM Concert Software Information Disclosure Vulnerability
The following table lists the changes that have been made to the CVE-2024-52367 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 07, 2025 Action […]
CVE-2024-52366 – IBM Concert Software Information Disclosure via Defaults to Insecure Protocols
IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
CVE-2024-12425 – LibreOffice Path Traversal Font Vulnerability
The following table lists the changes that have been made to the CVE-2024-12425 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 07, 2025 Action […]
CVE-2024-12033 – Jupiter X Core WordPress Unauthenticated Remote Code Execution (RCE)
CVE ID : CVE-2024-12033 Published : Jan. 7, 2025, 12:15 p.m. | 38 minutes ago Description : The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the sync_libraries() function in all versions up to, and including, 4.8.5. This makes it possible for authenticated attackers, with Subscriber-level […]