CVE Notify
17.9K subscribers
4 photos
154K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
๐Ÿšจ CVE-2024-5455
The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.5.4 via the 'magazine_style' parameter within the Dynamic Smart Showcase widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other โ€œsafeโ€ file types can be uploaded and included.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-5756
The Email Subscribers by Icegram Express โ€“ Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.23 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-36823
The encrypt() function of Ninja Core v7.0.0 was discovered to use a weak cryptographic algorithm, leading to a possible leakage of sensitive information.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-26184
Secure Boot Security Feature Bypass Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-28899
Secure Boot Security Feature Bypass Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-30013
Windows MultiPoint Services Remote Code Execution Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-35266
Azure DevOps Server Spoofing Vulnerability

๐ŸŽ–@cveNotify
๐Ÿ‘1
๐Ÿšจ CVE-2024-35267
Azure DevOps Server Spoofing Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-35270
Windows iSCSI Service Denial of Service Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2015-1419
Unspecified vulnerability in vsftpd 3.0.2 and earlier allows remote attackers to bypass access restrictions via unknown vectors, related to deny_file parsing.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2014-9710
The Btrfs implementation in the Linux kernel before 3.19 does not ensure that the visible xattr state is consistent with a requested replacement, which allows local users to bypass intended ACL settings and gain privileges via standard filesystem operations (1) during an xattr-replacement time window, related to a race condition, or (2) after an xattr-replacement attempt that fails because the data does not fit.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2015-7613
Race condition in the IPC object implementation in the Linux kernel through 4.2.3 allows local users to gain privileges by triggering an ipc_addid call that leads to uid and gid comparisons against uninitialized data, related to msg.c, shm.c, and util.c.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2015-2925
The prepend_path function in fs/dcache.c in the Linux kernel before 4.2.4 does not properly handle rename actions inside a bind mount, which allows local users to bypass an intended container protection mechanism by renaming a directory, related to a "double-chroot attack."

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2017-16531
drivers/usb/core/config.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device, related to the USB_DT_INTERFACE_ASSOCIATION descriptor.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2017-16532
The get_endpoints function in drivers/usb/misc/usbtest.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted USB device.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-30061
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-30071
Windows Remote Access Connection Manager Information Disclosure Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-30079
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-30081
Windows NTLM Spoofing Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-30098
Windows Cryptographic Services Security Feature Bypass Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-32987
Microsoft SharePoint Server Information Disclosure Vulnerability

๐ŸŽ–@cveNotify