A huge collection of 3400+ free website templates JAR theme com WP themes and more at the biggest community-driven free web design site
Home / security-advisories (page 2)

security-advisories

Multiple critical vulnerabilities affecting WordPress (CVE-2024-3604, CVE-2024-6314, CVE-2024-6313, CVE-2024-6365)

Advisory No: TZCERT/SA/2024/07/10-2 Date of First Release: 10th July 2024 Source: Wordfence Software Affected: osm, iq-testimonials, forms-gutenberg, woo-product-tables Overview: WordPress is vulnerable to four critical vulnerabilities. Exploitation of these vulnerabilities makes remote code execution possible. Description: Four WordPress plugins namely osm, iq-testimonials, forms-gutenberg, and woo-product-tables are affected by the vulnerabilities …

Read More »

Critical Vulnerabilities in multiple IBM vulnerabilities (CVE-2024-1597, CVE-2022-46337)

Advisory No: TZCERT/SA/2024/07/10-1 Date of First Release: 10th July 2024 Source: IBM Software Affected:  PostgreSQL JDBC Driver, Apache Derby Overview: Multiple IBM products depending on  PostgreSQL JDBC Driver, and Apache Derby are vulnerable to critical vulnerabilities. Attackers can exploit the vulnerabilities to dump critical data or execute arbitrary code. Description: …

Read More »

Arbitrary code execution vulnerability on IBM Instana Observability (CVE-2023-39410)

Advisory No: TZCERT/SA/2024/07/04-2 Date of First Release: 4th July 2024 Source: IBM Software Affected: IBM Observability with Instana (OnPrem) Overview: WordPress is vulnerable to four critical vulnerabilities. The attackers can leverage the vulnerability to take control of the affected system. Description: IBM Observability with Instana (OnPrem) is affected by a …

Read More »

High severity vulnerabilities affecting WordPress (CVE-2024-5943, CVE-2024-2385, CVE-2024-6319, CVE-2024-6318)

Advisory No: TZCERT/SA/2024/07/04-1 Date of First Release: 4th July 2024 Source: Wordfence Software Affected: wp-nested-pages, addons-for-elementor and IMGspider Overview: WordPress is vulnerable to four critical vulnerabilities. The attackers can leverage the vulnerabilities to take control of the affected system. Description: Three WordPress plugins namely wp-nested-pages, addons-for-elementor and IMGspider as affected …

Read More »

High severity vulnerabilities in HPE ProLiant and HPE Edgeline Servers Using BIOS (PixieFail) (CVE-2023-45229, CVE-2023-45230, CVE-2023-45234, CVE-2023-45235, CVE-2021-38575)

Advisory No: TZCERT/SA/2024/05/31-2 Date of First Release: 31st May 2024 Source: Hewlett-Packard (HP) Software Affected:  Servers Overview: HPE ProLiant and HPE Edgeline Servers are vulnerable to multiple high severity vulnerabilities. The attackers can leverage the vulnerabilities to take control of the affected system. Description: The five high-severity vulnerabilities among other …

Read More »

Critical Vulnerabilities affecting WordPress (CVE-2024-5522, CVE-2024-5150, CVE-2024-3412)

Advisory No: TZCERT/SA/2024/05/31-1 Date of First Release: 31st May 2024 Source: Wordfence Software Affected:  html5-video-player,  login-with-phone-number,  wp-staging Overview: WordPress is vulnerable to three critical vulnerabilities. The attackers can leverage the vulnerabilities to take control of the affected system. Description: Three WordPress plugins namely html5-video-player,  login-with-phone-number,  wp-staging are affected by the …

Read More »

Critical Vulnerabilities affecting WordPress (CVE-2024-4544, CVE-2024-0867, CVE-2024-1974)

Advisory No: TZCERT/SA/2024/05/24-2 Date of First Release: 24th May 2024 Source: Wordfence Software Affected: pie-register-social-site, email-log and ht-mega-for-elementor, Overview: WordPress is vulnerable to three critical vulnerabilities. The attackers can leverage the vulnerabilities to take control of the affected system. Description: Three WordPress plugins namely pie-register-social-site, email-log and ht-mega-for-elementor as affected …

Read More »

Arbitrary Code Execution Vulnerabilities in Multiple IBM Products (CVE-2023-45871, CVE-2023-39320, CVE-2023-51385)

Advisory No: TZCERT/SA/2024/05/24-1 Date of First Release: 24th May 2024 Source: IBM Software Affected: IBM Cloud Object System, IBM QRadar SIEM, IBM Security Guardium, IBM Storage Copy, IBM Storage Protect, IBM Storage Scale System, IBM Cloud Pak for Data Scheduling, IBM Spectrum Protect Plus, IBM AIX IBM i, IBM QRadar, …

Read More »

Critical Authentication Bypass Vulnerability in The GitHub Enterprise Server (CVE-2024-4985)

Advisory No: TZCERT/SA/2024/05/23 Date of First Release: 23rd May 2024 Source: GitHub Software Affected: GitHub Enterprise Server (GHES) prior to Version 3.13.0 Overview: GitHub Enterprise Servers (GHES) prior to version 3.13.0 is affected by a critical authentication bypass vulnerability. The vulnerability allows an unauthorized access to the instance without requiring …

Read More »

Remote Code Execution Vulnerabilities in IBM Operational Decision Manager, and IBM i Modernization Engine for Lifecycle Integration (CVE-2019-19919, CVE-2019-12384)

Advisory No: TZCERT/SA/2024/05/17-6 Date of First Release: 17th May 2024 Source: IBM Software Affected: IBM Operational Decision Manager, IBM i Modernization Engine for Lifecycle Integration Overview: IBM applications are vulnerable to critical vulnerabilities. The attackers can leverage the vulnerability to execute arbitrary code on the affected system. Description: IBM Operational …

Read More »