CVE-2024-52004 Remote code execution vulnerabilities in MediaCMS

MediaCMS is an open source video and media CMS, written in Python/Django and React, featuring a REST API. MediaCMS has been prone to vulnerabilities that upon special cases can lead to remote code exe ...

Continue Reading
CVE-2024-10325 Elementor Header & Footer Builder <= 1.6.45 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The Elementor Header &amp; Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.6.45 due to insuff ...

Continue Reading
Malicious NPM Packages Target Roblox Users with Data-Stealing Malware

A new campaign has targeted the npm package repository with malicious JavaScript libraries that are designed to infect Roblox users with open-source stealer malware such as Skuld and Blank-Grabber. &a ...

Continue Reading
CVE-2024-10325

The Elementor Header &amp; Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.6.45 due to insuff ...

Continue Reading
CVE-2024-50589

An unauthenticated attacker with access to the local network of the medical office can query an unprotected Fast Healthcare Interoperability Resources (FHIR) API to get access to sensitive electroni ...

Continue Reading
QSC: A multi-plugin framework used by CloudComputating group in cyberespionage campaigns

Introduction In 2021, we began to investigate an attack on the telecom industry in South Asia. During the investigation, we discovered QSC: a multi-plugin malware framework that loads and runs plugins ...

Continue Reading
CVE-2024-10325 Elementor Header & Footer Builder <= 1.6.45 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The Elementor Header &amp; Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.6.45 due to insuff ...

Continue Reading
CVE-2024-10325 Elementor Header & Footer Builder <= 1.6.45 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The Elementor Header &amp; Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.6.45 due to insuff ...

Continue Reading

Back to Main

Subscribe for the latest news: