Vulnerabilities 2024

​Hotjar's OAuth+XSS Flaw Exposes Millions at Risk of Account Takeover

A critical flaw in Hotjar that combines XSS with OAuth putting millions of websites at risk, exposing user data and risking account takeovers. Hotjar, a trusted product experience insights platform u…

Rama Sadhu
Updated by Rama Sadhu

Critical Apache OFBiz Zero-day AuthBiz (CVE-2023-49070 and CVE-2023-51467)

Cybersecurity researchers recently uncovered a critical flaw in the widely used Apache OFBiz Enterprise Resource Planning (ERP) system, CVE-2023-51467. The zero-day vulnerability CVE-2023-51467 poses…

vinugayathri.chinnasamy@indusface.com
Updated by vinugayathri.chinnasamy@indusface.com

CVE-2024-4879 & CVE-2024-5217 Exposed - The Risks of RCE in ServiceNow

Recent critical vulnerabilities in ServiceNow, a widely used cloud platform, have put numerous organizations at risk of data breaches. Threat actors are exploiting these input validation flaws, enabl…

Rama Sadhu
Updated by Rama Sadhu

ScreenConnect Authentication Bypass (CVE-2024-1709 & CVE-2024-1708)

ConnectWise ScreenConnect, a widely used remote desktop product, has recently been found vulnerable to two critical security flaws, assigned CVE numbers CVE-2024-1709 and CVE-2024-1708. These vulnera…

vinugayathri.chinnasamy@indusface.com
Updated by vinugayathri.chinnasamy@indusface.com

CVE-2024-4577 – A PHP CGI Argument Injection Vulnerability in Windows Servers

On June 7, 2024, a new critical PHP vulnerability CVE-2024-4577 was revealed, mainly impacting XAMPP on Windows. It happens when PHP runs in CGI mode with specific language settings, like Chinese or…

vinugayathri.chinnasamy@indusface.com
Updated by vinugayathri.chinnasamy@indusface.com

CVE-2024-8517 – Unauthenticated Remote Code Execution in SPIP

A critical security flaw has been discovered in SPIP, a popular open-source content management system (CMS). This flaw, identified as CVE-2024-8517, stems from a command injection issue in the BigUp…

Rama Sadhu
Updated by Rama Sadhu

CVE-2024-1071 – Critical Vulnerability in Ultimate Member WordPress Plugin

A critical security flaw, known as CVE-2024-1071, has been found in the Ultimate Member plugin for WordPress. This vulnerability, with a CVSS score of 9.8, poses a significant risk to over 200,000 ac…

vinugayathri.chinnasamy@indusface.com
Updated by vinugayathri.chinnasamy@indusface.com

Cryptocurrency Mining Attack Exploiting PHP Vulnerabilities: An Emerging Threat

Introduction. A new and growing threat has emerged, targeting vulnerable PHP servers with a sophisticated cryptocurrency mining attack. This exploit takes advantage of misconfigured or unpatched PHP…

Rama Sadhu
Updated by Rama Sadhu

Contact

This site is protected by hCaptcha and its Privacy Policy and Terms of Service apply.