Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

WordPress WPForms 1.7.8 Cross Site Scripting

WordPress WPForms plugin version 1.7.8 suffers from a cross site scripting vulnerability.

Packet Storm
#xss#vulnerability#windows#wordpress#php#auth
Forcepoint (Stonesoft VPN Client) 6.2.0 / 6.8.0 Local Privilege Escalation

Forcepoint (Stonesoft VPN Client) versions 6.2.0 and 6.8.0 suffer from a privilege escalation vulnerability.

CrowdStrike Falcon Agent 6.44.15806 Uninstall Issue

CrowdStrike Falcon Agent version 6.44.15806 has an uninstall bypass flaw that works without an installation token.

Lavasoft 4.1.0.409 Unquoted Service Path

Lavasoft version 4.1.0.409 suffers from an unquoted service path vulnerability.

Virtual Reception 1.0 Directory Traversal

Virtual Reception version 1.0 suffers from a directory traversal vulnerability.

DSL-124 Wireless N300 ADSL2+ Backup Disclosure

DSL-124 Wireless N300 ADSL2+ suffers from a backup disclosure vulnerability.

myBB forums 1.8.26 Cross Site Scripting

myBB forums version 1.8.26 suffers from a persistent cross site scripting vulnerability.

CVE-2023-29059: CWE-506: Embedded Malicious Code (4.10)

3CX DesktopApp through 18.12.416 has embedded malicious code, as exploited in the wild in March 2023. This affects versions 18.12.407 and 18.12.416 of the Electron Windows application shipped in Update 7, and versions 18.11.1213, 18.12.402, 18.12.407, and 18.12.416 of the Electron macOS application.

Dreamer CMS 4.0.0 SQL Injection

Dreamer CMS version 4.0.0 suffers from a remote SQL injection vulnerability.