CVE-2024-12067 – WordPress WP Travel SQL Injection

CVE ID : CVE-2024-12067 Published : Jan. 9, 2025, 11:15 a.m. | 32 minutes ago Description : The WP Travel – Ultimate Travel Booking System, Tour Management Engine plugin for WordPress is vulnerable to SQL Injection via the ‘booking_itinerary’ parameter of the ‘wptravel_get_booking_data’ function in all versions up to, and including, 10.0.0 due to insufficient escaping […]

CVE-2024-11929 – WordPress Responsive FlipBook Stored Cross-Site Scripting

CVE ID : CVE-2024-11929 Published : Jan. 9, 2025, 11:15 a.m. | 32 minutes ago Description : The Responsive FlipBook Plugin WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the rfbwp_save_settings() functionin all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated […]

CVE-2024-11642 – “Post Grid Master WordPress Local File Inclusion Vulnerability”

The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.4.12 via the ‘locate_template’ function. This makes it possible for unauthenticated attackers to include and execute arbitrary […]

Mandiant: Ivanti VPN-lek sinds halverwege december misbruikt bij aanvallen

Mandiant: Ivanti VPN-lek sinds halverwege december misbruikt bij aanvallen Een kwetsbaarheid in Ivanti Connect Secure die het mogelijk maakt om vpn-servers op afstand over te nemen en waarvoor gisterenavond een beveiligingsupdate verscheen is sinds halverwege december misbru … Read more Published Date: Jan 09, 2025 (1 hour, 3 minutes ago) Vulnerabilities has been mentioned in this article. […]

CVE-2025-0347 – Code-Projects Admission Management System SQL Injection Vulnerability

The following table lists the changes that have been made to the CVE-2025-0347 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 09, 2025 Action […]

CVE-2025-0348 – CampCodes DepEd Equipment Inventory System Cross-Site Scripting Vulnerability

The following table lists the changes that have been made to the CVE-2025-0348 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 09, 2025 Action […]

SOC239 — Remote Code Execution Detected in Splunk Enterprise

SOC239 — Remote Code Execution Detected in Splunk Enterprise In this writeup, I will investigate one of the alerts on Letsdefend, “SOC239 — Remote Code Execution Detected in Splunk Enterprise”This alert is about CVE-2023–46214. The vulnerability is caused by Sp … Read more Published Date: Jan 09, 2025 (1 hour, 44 minutes ago) Vulnerabilities has been mentioned in this […]

“SOC227 — Microsoft SharePoint Server Elevation of Privilege — Possible CVE-2023–29357…

“SOC227 — Microsoft SharePoint Server Elevation of Privilege — Possible CVE-2023–29357… In this writeup, I will investigate one of the alerts on Letsdefend, “SOC227 — Microsoft SharePoint Server Elevation of Privilege — Possible CVE-2023–29357 Exploitation”.The CVE-2023–29357 vulnerabili … Read more Published Date: Jan 09, 2025 (1 hour, 44 minutes ago) Vulnerabilities has been mentioned in this article.

SOC235 — Atlassian Confluence Broken Access Control 0-Day CVE-2023-22515

SOC235 — Atlassian Confluence Broken Access Control 0-Day CVE-2023-22515 In this writeup, I will investigate one of the alerts on Letsdefend, “SOC235 — Atlassian Confluence Broken Access Control 0-Day CVE-2023–22515”The CVE-2023–22515 affects certain versions of Atlassian … Read more Published Date: Jan 09, 2025 (1 hour, 44 minutes ago) Vulnerabilities has been mentioned in this article.

Lek in firewall-migratietool Palo Alto Networks geeft toegang tot wachtwoorden

Lek in firewall-migratietool Palo Alto Networks geeft toegang tot wachtwoorden Kwetsbaarheden in de firewall-migratietool van Palo Alto Networks maken het mogelijk voor aanvallers om wachtwoorden en andere gevoelige data te stelen. Vorig jaar werden drie soortgelijke kwetsbaarhe … Read more Published Date: Jan 09, 2025 (2 hours ago) Vulnerabilities has been mentioned in this article.