Vulnerabilities 2024

​Hotjar's OAuth+XSS Flaw Exposes Millions at Risk of Account Takeover

A critical flaw in Hotjar that combines XSS with OAuth putting millions of websites at risk, exposing user data and risking account takeovers. Hotjar, a trusted product experience insights platform u…

Rama Sadhu
Updated by Rama Sadhu

CVE-2024-1071 – Critical Vulnerability in Ultimate Member WordPress Plugin

A critical security flaw, known as CVE-2024-1071, has been found in the Ultimate Member plugin for WordPress. This vulnerability, with a CVSS score of 9.8, poses a significant risk to over 200,000 ac…

vinugayathri.chinnasamy@indusface.com
Updated by vinugayathri.chinnasamy@indusface.com

CVE-2024-4577 – A PHP CGI Argument Injection Vulnerability in Windows Servers

On June 7, 2024, a new critical PHP vulnerability CVE-2024-4577 was revealed, mainly impacting XAMPP on Windows. It happens when PHP runs in CGI mode with specific language settings, like Chinese or…

vinugayathri.chinnasamy@indusface.com
Updated by vinugayathri.chinnasamy@indusface.com

CVE-2024-4879 & CVE-2024-5217 Exposed - The Risks of RCE in ServiceNow

Recent critical vulnerabilities in ServiceNow, a widely used cloud platform, have put numerous organizations at risk of data breaches. Threat actors are exploiting these input validation flaws, enabl…

Rama Sadhu
Updated by Rama Sadhu

CVE-2024-8517 – Unauthenticated Remote Code Execution in SPIP

A critical security flaw has been discovered in SPIP, a popular open-source content management system (CMS). This flaw, identified as CVE-2024-8517, stems from a command injection issue in the BigUp…

Rama Sadhu
Updated by Rama Sadhu

Critical Apache OFBiz Zero-day AuthBiz (CVE-2023-49070 and CVE-2023-51467)

Cybersecurity researchers recently uncovered a critical flaw in the widely used Apache OFBiz Enterprise Resource Planning (ERP) system, CVE-2023-51467. The zero-day vulnerability CVE-2023-51467 poses…

vinugayathri.chinnasamy@indusface.com
Updated by vinugayathri.chinnasamy@indusface.com

ScreenConnect Authentication Bypass (CVE-2024-1709 & CVE-2024-1708)

ConnectWise ScreenConnect, a widely used remote desktop product, has recently been found vulnerable to two critical security flaws, assigned CVE numbers CVE-2024-1709 and CVE-2024-1708. These vulnera…

vinugayathri.chinnasamy@indusface.com
Updated by vinugayathri.chinnasamy@indusface.com

Contact

This site is protected by hCaptcha and its Privacy Policy and Terms of Service apply.