Aquabot Exploits Mitel Flaw CVE-2024-41710
Aquabot Exploits Mitel Flaw CVE-2024-41710 The Aquabot botnet, a sophisticated variant of the Mirai botnet, has been actively exploiting CVE-2024-41710, a high-severity command injection vulnerability in Mitel SIP phones. This detailed analysi … Read more Published Date: Jan 30, 2025 (3 hours, 20 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-22217 CVE-2025-0065 CVE-2024-41710
Kritiek beveiligingslek in Microsoft Accounts kon aanvaller meer rechten geven
Kritiek beveiligingslek in Microsoft Accounts kon aanvaller meer rechten geven Microsoft heeft een kritieke kwetsbaarheid in Microsoft Accounts verholpen waardoor een ongeautoriseerde aanvaller ‘over een netwerk’ zijn rechten kon verhogen. Via een Microsoft Account kan er toegan … Read more Published Date: Jan 30, 2025 (3 hours, 50 minutes ago) Vulnerabilities has been mentioned in this article. […]
CVE-2025-0834 – Wondershare Dr.Fone Privilege Escalation Vulnerability
The following table lists the changes that have been made to the CVE-2025-0834 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 30, 2025 Action […]
CVE-2024-13758 – PayPal for WordPress CSRF Vulnerability
CVE ID : CVE-2024-13758 Published : Jan. 30, 2025, 9:15 a.m. | 36 minutes ago Description : The CP Contact Form with PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.52. This is due to missing or incorrect nonce validation on the cp_contact_form_paypal_check_init_actions() function. This makes it […]
CVE-2024-13732 – WordPress Gutenberg Blocks Stored Cross-Site Scripting.parseColor
CVE ID : CVE-2024-13732 Published : Jan. 30, 2025, 9:15 a.m. | 36 minutes ago Description : The Responsive Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘section_tag’ parameter in all versions up to, and including, 1.9.9 due to insufficient input sanitization and output escaping. This makes it […]
CVE-2024-13694 – “WooCommerce Wishlist Insecure Direct Object Reference (IDOR)”
CVE ID : CVE-2024-13694 Published : Jan. 30, 2025, 9:15 a.m. | 36 minutes ago Description : The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.7 via the download_pdf_file() function due to missing validation on a […]
CVE-2024-13470 – Ninja Forms WordPress Stored Cross-Site Scripting
CVE ID : CVE-2024-13470 Published : Jan. 30, 2025, 8:15 a.m. | 1 hour, 35 minutes ago Description : The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s shortcode in all versions up to, and including, 3.8.24 due to insufficient input sanitization […]
Unpatched PHP Voyager Flaws Leave Servers Open to One-Click RCE Exploits
Unpatched PHP Voyager Flaws Leave Servers Open to One-Click RCE Exploits Web Security / Vulnerability Three security flaws have been disclosed in the open-source PHP package Voyager that could be exploited by an attacker to achieve one-click remote code execution on affect … Read more Published Date: Jan 30, 2025 (4 hours ago) Vulnerabilities has been […]
CVE-2024-13642 – “Stratum Elementor Widgets Stored Cross-Site Scripting Vulnerability”
CVE ID : CVE-2024-13642 Published : Jan. 30, 2025, 7:15 a.m. | 35 minutes ago Description : The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s Image Hotspot widget in all versions up to, and including, 1.4.7 due to insufficient input sanitization and output escaping on user supplied […]
CVE-2024-13457 – WordPress Event Tickets and Registration Insecure Direct Object Reference Vulnerability
CVE ID : CVE-2024-13457 Published : Jan. 30, 2025, 7:15 a.m. | 35 minutes ago Description : The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.1 via the tc-order-id parameter due to missing validation on a user controlled key. This makes it […]