Mirai Botnet Variant Exploits Four-Faith Router Vulnerability for DDoS Attacks

Mirai Botnet Variant Exploits Four-Faith Router Vulnerability for DDoS Attacks A Mirai botnet variant has been found exploiting a newly disclosed security flaw impacting Four-Faith industrial routers since early November 2024 with the goal of conducting distributed denial-of-ser … Read more Published Date: Jan 08, 2025 (2 hours, 34 minutes ago) Vulnerabilities has been mentioned in this […]

CVE-2024-12853 – WordPress Modula Image Gallery Remote File Upload Vulnerability

CVE ID : CVE-2024-12853 Published : Jan. 8, 2025, 10:15 a.m. | 49 minutes ago Description : The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functionality in all versions up to, and including, 2.11.10. This makes it possible for authenticated attackers, […]

CVE-2024-9939 – WordPress File Upload Path Traversal Vulnerability

CVE ID : CVE-2024-9939 Published : Jan. 8, 2025, 9:15 a.m. | 26 minutes ago Description : The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.13 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read files outside of the originally intended directory. Severity: […]

CVE-2024-54676 – Apache OpenMeetings Object Deserialization Vulnerability

The following table lists the changes that have been made to the CVE-2024-54676 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 08, 2025 Action […]

CVE-2024-45033 – Apache Airflow Fab Provider Insufficient Session Expiration Remote Authentication Bypass

The following table lists the changes that have been made to the CVE-2024-45033 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 08, 2025 Action […]

CVE-2024-13186 – Apache MinigameCenter Information Leak

The following table lists the changes that have been made to the CVE-2024-13186 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 08, 2025 Action […]

CVE-2024-13185 – Apache MinigameCenter Information Disclosure

The following table lists the changes that have been made to the CVE-2024-13185 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 08, 2025 Action […]

CVE-2024-12855 – AdForest for WordPress AJAX Capability Bypass

CVE ID : CVE-2024-12855 Published : Jan. 8, 2025, 9:15 a.m. | 26 minutes ago Description : The AdForest theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions like ‘sb_remove_ad’ in all versions up to, and including, 5.1.7. This makes it possible for authenticated attackers, […]