CVE-2024-12067 – WordPress WP Travel SQL Injection
CVE ID : CVE-2024-12067 Published : Jan. 9, 2025, 11:15 a.m. | 32 minutes ago Description : The WP Travel – Ultimate Travel Booking System, Tour Management Engine plugin for WordPress is vulnerable to SQL Injection via the ‘booking_itinerary’ parameter of the ‘wptravel_get_booking_data’ function in all versions up to, and including, 10.0.0 due to insufficient escaping […]
CVE-2024-11929 – WordPress Responsive FlipBook Stored Cross-Site Scripting
CVE ID : CVE-2024-11929 Published : Jan. 9, 2025, 11:15 a.m. | 32 minutes ago Description : The Responsive FlipBook Plugin WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the rfbwp_save_settings() functionin all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated […]
CVE-2024-11642 – “Post Grid Master WordPress Local File Inclusion Vulnerability”
The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.4.12 via the ‘locate_template’ function. This makes it possible for unauthenticated attackers to include and execute arbitrary […]
Mandiant: Ivanti VPN-lek sinds halverwege december misbruikt bij aanvallen
Mandiant: Ivanti VPN-lek sinds halverwege december misbruikt bij aanvallen Een kwetsbaarheid in Ivanti Connect Secure die het mogelijk maakt om vpn-servers op afstand over te nemen en waarvoor gisterenavond een beveiligingsupdate verscheen is sinds halverwege december misbru … Read more Published Date: Jan 09, 2025 (1 hour, 3 minutes ago) Vulnerabilities has been mentioned in this article. […]
CVE-2025-0347 – Code-Projects Admission Management System SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-0347 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 09, 2025 Action […]
CVE-2025-0348 – CampCodes DepEd Equipment Inventory System Cross-Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2025-0348 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 09, 2025 Action […]
SOC239 — Remote Code Execution Detected in Splunk Enterprise
SOC239 — Remote Code Execution Detected in Splunk Enterprise In this writeup, I will investigate one of the alerts on Letsdefend, “SOC239 — Remote Code Execution Detected in Splunk Enterprise”This alert is about CVE-2023–46214. The vulnerability is caused by Sp … Read more Published Date: Jan 09, 2025 (1 hour, 44 minutes ago) Vulnerabilities has been mentioned in this […]
“SOC227 — Microsoft SharePoint Server Elevation of Privilege — Possible CVE-2023–29357…
“SOC227 — Microsoft SharePoint Server Elevation of Privilege — Possible CVE-2023–29357… In this writeup, I will investigate one of the alerts on Letsdefend, “SOC227 — Microsoft SharePoint Server Elevation of Privilege — Possible CVE-2023–29357 Exploitation”.The CVE-2023–29357 vulnerabili … Read more Published Date: Jan 09, 2025 (1 hour, 44 minutes ago) Vulnerabilities has been mentioned in this article.
SOC235 — Atlassian Confluence Broken Access Control 0-Day CVE-2023-22515
SOC235 — Atlassian Confluence Broken Access Control 0-Day CVE-2023-22515 In this writeup, I will investigate one of the alerts on Letsdefend, “SOC235 — Atlassian Confluence Broken Access Control 0-Day CVE-2023–22515”The CVE-2023–22515 affects certain versions of Atlassian … Read more Published Date: Jan 09, 2025 (1 hour, 44 minutes ago) Vulnerabilities has been mentioned in this article.
Lek in firewall-migratietool Palo Alto Networks geeft toegang tot wachtwoorden
Lek in firewall-migratietool Palo Alto Networks geeft toegang tot wachtwoorden Kwetsbaarheden in de firewall-migratietool van Palo Alto Networks maken het mogelijk voor aanvallers om wachtwoorden en andere gevoelige data te stelen. Vorig jaar werden drie soortgelijke kwetsbaarhe … Read more Published Date: Jan 09, 2025 (2 hours ago) Vulnerabilities has been mentioned in this article.