Mirai Botnet Variant Exploits Four-Faith Router Vulnerability for DDoS Attacks
Mirai Botnet Variant Exploits Four-Faith Router Vulnerability for DDoS Attacks A Mirai botnet variant has been found exploiting a newly disclosed security flaw impacting Four-Faith industrial routers since early November 2024 with the goal of conducting distributed denial-of-ser … Read more Published Date: Jan 08, 2025 (2 hours, 34 minutes ago) Vulnerabilities has been mentioned in this […]
CVE-2024-12854 – “WordPress Garden Gnome Package Plugin Remote Code Execution File Upload Vulnerability”
CVE ID : CVE-2024-12854 Published : Jan. 8, 2025, 10:15 a.m. | 49 minutes ago Description : The Garden Gnome Package plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the functionality that automatically extracts ‘ggpkg’ files that have been uploaded in all versions up to, and including, 2.3.0. […]
CVE-2024-12853 – WordPress Modula Image Gallery Remote File Upload Vulnerability
CVE ID : CVE-2024-12853 Published : Jan. 8, 2025, 10:15 a.m. | 49 minutes ago Description : The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functionality in all versions up to, and including, 2.11.10. This makes it possible for authenticated attackers, […]
CVE-2024-12712 – BigCommerce Unauthenticated Order Status Modification Vulnerability
CVE ID : CVE-2024-12712 Published : Jan. 8, 2025, 10:15 a.m. | 49 minutes ago Description : The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the webhook function in all versions up to, and including, 5.7.8. This makes it possible for […]
CVE-2024-9939 – WordPress File Upload Path Traversal Vulnerability
CVE ID : CVE-2024-9939 Published : Jan. 8, 2025, 9:15 a.m. | 26 minutes ago Description : The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.13 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read files outside of the originally intended directory. Severity: […]
CVE-2024-54676 – Apache OpenMeetings Object Deserialization Vulnerability
The following table lists the changes that have been made to the CVE-2024-54676 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 08, 2025 Action […]
CVE-2024-45033 – Apache Airflow Fab Provider Insufficient Session Expiration Remote Authentication Bypass
The following table lists the changes that have been made to the CVE-2024-45033 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 08, 2025 Action […]
CVE-2024-13186 – Apache MinigameCenter Information Leak
The following table lists the changes that have been made to the CVE-2024-13186 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 08, 2025 Action […]
CVE-2024-13185 – Apache MinigameCenter Information Disclosure
The following table lists the changes that have been made to the CVE-2024-13185 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 08, 2025 Action […]
CVE-2024-12855 – AdForest for WordPress AJAX Capability Bypass
CVE ID : CVE-2024-12855 Published : Jan. 8, 2025, 9:15 a.m. | 26 minutes ago Description : The AdForest theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions like ‘sb_remove_ad’ in all versions up to, and including, 5.1.7. This makes it possible for authenticated attackers, […]