CVE-2024-11758 – “WP SPID Italia Stored Cross-Site Scripting Vulnerability”

CVE ID : CVE-2024-11758 Published : Jan. 11, 2025, 8:15 a.m. | 33 minutes ago Description : The WP SPID Italia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s shortcode in all versions up to, and including, 2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes […]

CVE-2024-11386 – GatorMail SmartForms WordPress Stored XSS

CVE ID : CVE-2024-11386 Published : Jan. 11, 2025, 8:15 a.m. | 33 minutes ago Description : The GatorMail SmartForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s ‘gatormailsmartform’ shortcode in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes […]

CVE-2024-11892 – WordPress Accordion Slider Lite Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2024-11892 Published : Jan. 11, 2025, 8:15 a.m. | 33 minutes ago Description : The Accordion Slider Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s ‘accordion_slider’ shortcode in all versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This […]

CVE-2024-11874 – WordPress Grid Accordion Lite Stored Cross-Site Scripting

CVE ID : CVE-2024-11874 Published : Jan. 11, 2025, 8:15 a.m. | 33 minutes ago Description : The Grid Accordion Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s ‘grid_accordion’ shortcode in all versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This […]

2025-01-09: CVE-2017-0199 XLS –> HTA –> VBS –> steganography –> DBatLoader/GuiLoader style malware

2025-01-09: CVE-2017-0199 XLS –> HTA –> VBS –> steganography –> DBatLoader/GuiLoader style malware 2025-01-09 (THURSDAY): CVE-2017-0199 XLS –> HTA –> VBS –> STEGANOGRAPHY –> DBATLOADER/GUILOADER STYLE MALWARE NOTES: Zip files are password-protected.  Of note, this site has a new password scheme … Read more Published Date: Jan 11, 2025 (2 hours, 27 minutes ago) Vulnerabilities has been […]

CVE-2024-42174 – HCL MyXalytics Username Enumeration Vulnerability

The following table lists the changes that have been made to the CVE-2024-42174 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 11, 2025 Action […]

CVE-2024-42172 – HCL MyXalytics Broken Authentication Vulnerability

HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to identity theft and system control. This vulnerability arises from poor configuration, logic errors, or software bugs and can affect any application with access control, including databases, network infrastructure, and web applications.

CVE-2024-42171 – HCL MyXalytics Session Fixation Vulnerability

The following table lists the changes that have been made to the CVE-2024-42171 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 11, 2025 Action […]

CVE-2024-42173 – HCL MyXalytics Unsecured Authentication Flaw

The following table lists the changes that have been made to the CVE-2024-42173 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 11, 2025 Action […]

CVE-2024-42170 – HCL MyXalytics Session Fixation Vulnerability

The following table lists the changes that have been made to the CVE-2024-42170 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 11, 2025 Action […]