Tag : 2024-06-12

4 attack reports | 120 vulnerabilities

Attack Reports

Title Published Tags Description Number of indicators
Ransomware Attackers May Have Used Privilege Escalation Vulnerability as Zero-day June 12, 2024, 1:01 p.m. Recent analysis by a cybersecurity firm suggests that a ransomware group might have exploited a Windows privilege escalation vuln… 5
Dipping into Danger: The WARMCOOKIE backdoor June 12, 2024, 10:41 a.m. Elastic Security Labs identified a new wave of email campaigns targeting environments by deploying a novel backdoor dubbed WARMCO… 6
Smishing Triad Is Targeting Pakistan To Defraud Banking Customers At Scale June 12, 2024, 10:35 a.m. Resecurity has identified a new activity of a cybercrime group known as Smishing Triad, which has expanded its operations to Paki… 14
UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion June 12, 2024, 10:34 a.m. An extensive cybercriminal campaign led by a threat actor codenamed UNC5537 has compromised numerous Snowflake customer database … 48

Vulnerabilities

CVE CVSS Published Product impacted Tags
CVE-2024-4898 9.8 June 12, 2024, 11:15 a.m. LOGO-VULNERABLEInstaWP Connect – 1-click WP Staging & Migration plugin for WordPress
CVE-2024-37036 9.8 June 12, 2024, 5:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-4315 9.1 June 12, 2024, 1:15 a.m. LOGO-VULNERABLEparisneo/lollms
CVE-2024-5211 9.1 June 12, 2024, 12:15 p.m. LOGO-VULNERABLEmintplex-labs/anything-llm
CVE-2024-4845 8.8 June 12, 2024, 10:15 a.m. LOGO-VULNERABLEIcegram Express plugin for WordPress
CVE-2024-25949 8.8 June 12, 2024, 1:15 p.m. LOGO-VULNERABLEDell OS10 Networking Switches
CVE-2024-5543 8.1 June 12, 2024, 2:15 a.m. LOGO-VULNERABLESlideshow Gallery LITE plugin for WordPress
CVE-2024-3183 8.1 June 12, 2024, 9:15 a.m. LOGO-VULNERABLEFreeIPA
CVE-2024-5154 8.1 June 12, 2024, 9:15 a.m. LOGO-VULNERABLEcri-o
CVE-2024-37300 8.1 June 12, 2024, 4:15 p.m. LOGO-VULNERABLEJupyterHub
CVE-2024-37037 8.1 June 12, 2024, 5:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-28964 7.8 June 12, 2024, 3:15 p.m. LOGO-VULNERABLEDell Common Event Enabler
CVE-2024-0865 7.8 June 12, 2024, 6:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-2747 7.8 June 12, 2024, 6:15 p.m. LOGO-VULNERABLEEasergy Studio
CVE-2023-48280 7.5 June 12, 2024, 10:15 a.m. LOGO-VULNERABLEConsensu.Io
CVE-2024-37038 7.5 June 12, 2024, 5:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-5896 7.3 June 12, 2024, 4:15 p.m. LOGO-VULNERABLESourceCodester Employee and Visitor Gate Pass Logging System
CVE-2024-2698 7.1 June 12, 2024, 8:15 a.m. LOGO-VULNERABLEFreeIPA
CVE-2024-34065 7.1 June 12, 2024, 3:15 p.m. LOGO-VULNERABLE@strapi/plugin-users-permissions
CVE-2024-0160 6.8 June 12, 2024, 7:15 a.m. LOGO-VULNERABLEDell Client Platform
CVE-2024-5468 6.5 June 12, 2024, 9:15 a.m. LOGO-VULNERABLEWordPress Header Builder Plugin - Pearl
CVE-2023-40209 6.5 June 12, 2024, 10:15 a.m. LOGO-VULNERABLEHighcompress Image Compressor
CVE-2024-5674 6.5 June 12, 2024, 11:15 a.m. LOGO-VULNERABLEWordPress Newsletter - API v1 and v2 addon plugin
CVE-2024-5056 6.5 June 12, 2024, 12:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-5313 6.5 June 12, 2024, 1:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-23445 6.5 June 12, 2024, 2:15 p.m. LOGO-VULNERABLEElasticsearch
CVE-2024-31881 6.5 June 12, 2024, 7:15 p.m. LOGO-VULNERABLEIBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server)
CVE-2024-4892 6.4 June 12, 2024, 2:15 a.m. LOGO-VULNERABLEBuddyPress plugin for WordPress
CVE-2024-4564 6.4 June 12, 2024, 4:15 a.m. LOGO-VULNERABLECoDesigner WooCommerce Builder for Elementor plugin
CVE-2024-3559 6.4 June 12, 2024, 5:15 a.m. LOGO-VULNERABLECustom Field Suite plugin for WordPress
CVE-2024-5892 6.4 June 12, 2024, 6:15 a.m. LOGO-VULNERABLEWordPress Divi Torque Lite Theme plugin
CVE-2024-3925 6.4 June 12, 2024, 8:15 a.m. LOGO-VULNERABLEElement Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress
CVE-2024-5266 6.4 June 12, 2024, 9:15 a.m. LOGO-VULNERABLEDownload Manager Pro plugin for WordPress
CVE-2024-3492 6.4 June 12, 2024, 11:15 a.m. LOGO-VULNERABLEWordPress Events Manager plugin
CVE-2024-5558 6.4 June 12, 2024, 5:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-5893 6.3 June 12, 2024, 3:15 p.m. LOGO-VULNERABLESourceCodester Cab Management System
CVE-2024-5894 6.3 June 12, 2024, 3:15 p.m. LOGO-VULNERABLESourceCodester Online Eyewear Shop
CVE-2024-5895 6.3 June 12, 2024, 3:15 p.m. LOGO-VULNERABLESourceCodester Employee and Visitor Gate Pass Logging System
CVE-2024-5898 6.3 June 12, 2024, 5:15 p.m. LOGO-VULNERABLEitsourcecode Payroll Management System
CVE-2024-5739 6.1 June 12, 2024, 7:15 a.m. LOGO-VULNERABLELINE for iOS
CVE-2024-37304 6.1 June 12, 2024, 3:15 p.m. LOGO-VULNERABLENuGet Gallery
CVE-2024-5559 6.1 June 12, 2024, 6:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-37039 5.9 June 12, 2024, 5:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2023-51671 5.4 June 12, 2024, 9:15 a.m. LOGO-VULNERABLEFunnelKit Checkout
CVE-2023-51679 5.4 June 12, 2024, 9:15 a.m. LOGO-VULNERABLEBulkGate SMS Plugin for WooCommerce
CVE-2023-52177 5.4 June 12, 2024, 9:15 a.m. LOGO-VULNERABLESoftLab Integrate Google Drive
CVE-2023-38395 5.4 June 12, 2024, 10:15 a.m. LOGO-VULNERABLEAfzal Multani WP Clone Menu
CVE-2023-40672 5.4 June 12, 2024, 10:15 a.m. LOGO-VULNERABLESticky Social Media Icons
CVE-2024-2092 5.4 June 12, 2024, 10:15 a.m. LOGO-VULNERABLEElementor Addon Elements plugin for WordPress
CVE-2024-37297 5.4 June 12, 2024, 3:15 p.m. LOGO-VULNERABLEWooCommerce
CVE-2024-5759 5.4 June 12, 2024, 4:15 p.m. LOGO-VULNERABLETenable Security Center
CVE-2024-37040 5.4 June 12, 2024, 5:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2023-51537 5.3 June 12, 2024, 9:15 a.m. LOGO-VULNERABLEAwesome Support
CVE-2023-40603 5.3 June 12, 2024, 10:15 a.m. LOGO-VULNERABLESimple Org Chart
CVE-2023-41240 5.3 June 12, 2024, 10:15 a.m. LOGO-VULNERABLEPricing Deals for WooCommerce
CVE-2023-51413 5.3 June 12, 2024, 10:15 a.m. LOGO-VULNERABLEPiotnet Forms
CVE-2024-31217 5.3 June 12, 2024, 3:15 p.m. LOGO-VULNERABLEStrapi
CVE-2024-5560 5.3 June 12, 2024, 5:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-28762 5.3 June 12, 2024, 6:15 p.m. LOGO-VULNERABLEIBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server)
CVE-2023-29267 5.3 June 12, 2024, 7:15 p.m. LOGO-VULNERABLEIBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server)
CVE-2024-28970 4.7 June 12, 2024, 7:15 a.m. LOGO-VULNERABLEDell Client BIOS
CVE-2024-5742 4.7 June 12, 2024, 9:15 a.m. LOGO-VULNERABLEGNU Nano
CVE-2024-5557 4.5 June 12, 2024, 5:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-5553 4.4 June 12, 2024, 4:15 a.m. LOGO-VULNERABLEPremium Addons for Elementor plugin for WordPress
CVE-2024-1766 4.4 June 12, 2024, 11:15 a.m. LOGO-VULNERABLEWordPress Download Manager plugin
CVE-2023-51526 4.3 June 12, 2024, 9:15 a.m. LOGO-VULNERABLESimple Staff List
CVE-2023-51670 4.3 June 12, 2024, 9:15 a.m. LOGO-VULNERABLEFunnelKit FunnelKit Checkout
CVE-2023-51680 4.3 June 12, 2024, 9:15 a.m. LOGO-VULNERABLEQuotes for WooCommerce
CVE-2023-52117 4.3 June 12, 2024, 9:15 a.m. LOGO-VULNERABLEProfileGrid
CVE-2023-25030 4.3 June 12, 2024, 10:15 a.m. LOGO-VULNERABLEBuy Me a Coffee
CVE-2023-44234 4.3 June 12, 2024, 10:15 a.m. LOGO-VULNERABLEWP GPX Map
CVE-2023-47828 4.3 June 12, 2024, 10:15 a.m. LOGO-VULNERABLEwpMandrill
CVE-2023-47845 4.3 June 12, 2024, 10:15 a.m. LOGO-VULNERABLEGrab & Save
CVE-2023-51524 4.3 June 12, 2024, 10:15 a.m. LOGO-VULNERABLEweForms
CVE-2024-5897 4.3 June 12, 2024, 4:15 p.m. LOGO-VULNERABLESourceCodester Employee and Visitor Gate Pass Logging System
CVE-2024-5891 4.2 June 12, 2024, 2:15 p.m. LOGO-VULNERABLEQuay
CVE-2024-5203 3.7 June 12, 2024, 9:15 a.m. LOGO-VULNERABLEKeycloak
CVE-2024-1891 3.5 June 12, 2024, 4:15 p.m. LOGO-VULNERABLETenable Security Center
CVE-2024-5798 2.6 June 12, 2024, 7:15 p.m. LOGO-VULNERABLEVault
CVE-2024-29181 2.3 June 12, 2024, 3:15 p.m. LOGO-VULNERABLEStrapi
CVE-2024-36103 None June 12, 2024, 1:15 a.m. LOGO-VULNERABLEWRC-X5400GS-B
CVE-2024-36856 None June 12, 2024, 3:15 a.m. LOGO-VULNERABLERMQTT Broker
CVE-2024-0427 None June 12, 2024, 6:15 a.m. LOGO-VULNERABLEARForms - Premium WordPress Form Builder Plugin
CVE-2024-36454 None June 12, 2024, 6:15 a.m. LOGO-VULNERABLEIPCOM EX2 Series (V01L0x Series)
CVE-2024-4924 None June 12, 2024, 6:15 a.m. LOGO-VULNERABLESocial Sharing Plugin WordPress plugin
CVE-2024-5776 None June 12, 2024, 8:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-5777 None June 12, 2024, 8:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-5778 None June 12, 2024, 8:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-5779 None June 12, 2024, 8:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-5780 None June 12, 2024, 8:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-5781 None June 12, 2024, 8:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-5782 None June 12, 2024, 8:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-5783 None June 12, 2024, 8:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-5873 None June 12, 2024, 8:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-1576 None June 12, 2024, 2:15 p.m. LOGO-VULNERABLEMegaBIP software
CVE-2024-1577 None June 12, 2024, 2:15 p.m. LOGO-VULNERABLEMegaBIP
CVE-2024-1659 None June 12, 2024, 2:15 p.m. LOGO-VULNERABLEMegaBIP software
CVE-2024-36263 None June 12, 2024, 2:15 p.m. LOGO-VULNERABLEApache Submarine Server Core
CVE-2024-36264 None June 12, 2024, 2:15 p.m. LOGO-VULNERABLEApache Submarine Commons Utils
CVE-2024-36699 None June 12, 2024, 2:15 p.m. LOGO-VULNERABLEGNU Debugger
CVE-2024-2300 None June 12, 2024, 3:15 p.m. LOGO-VULNERABLEHP Advance Mobile Applications for iOS
CVE-2024-36265 None June 12, 2024, 3:15 p.m. LOGO-VULNERABLEApache Submarine Server Core
CVE-2024-36691 None June 12, 2024, 3:15 p.m. LOGO-VULNERABLEPPGo_Jobs
CVE-2024-36840 None June 12, 2024, 3:15 p.m. LOGO-VULNERABLEBoelter Blue System Management
CVE-2024-36761 None June 12, 2024, 4:15 p.m. LOGO-VULNERABLEnaga
CVE-2024-22855 None June 12, 2024, 5:15 p.m. LOGO-VULNERABLEITSS iMLog
CVE-2024-2230 None June 12, 2024, 5:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-37878 None June 12, 2024, 5:15 p.m. LOGO-VULNERABLETWCMS
CVE-2024-5905 None June 12, 2024, 5:15 p.m. LOGO-VULNERABLEPalo Alto Networks Cortex XDR agent
CVE-2024-5906 None June 12, 2024, 5:15 p.m. LOGO-VULNERABLEPalo Alto Networks Prisma Cloud Compute
CVE-2024-5907 None June 12, 2024, 5:15 p.m. LOGO-VULNERABLEPalo Alto Networks Cortex XDR agent
CVE-2024-5908 None June 12, 2024, 5:15 p.m. LOGO-VULNERABLEPalo Alto Networks GlobalProtect app
CVE-2024-5909 None June 12, 2024, 5:15 p.m. LOGO-VULNERABLEPalo Alto Networks Cortex XDR agent
CVE-2024-24051 None June 12, 2024, 6:15 p.m. LOGO-VULNERABLEMonoprice Select Mini V2
CVE-2024-37629 None June 12, 2024, 6:15 p.m. LOGO-VULNERABLESummerNote
CVE-2023-49559 None June 12, 2024, 8:15 p.m. LOGO-VULNERABLEvektah gqlparser open-source-library
CVE-2024-36523 None June 12, 2024, 9:15 p.m. LOGO-VULNERABLEWvp GB28181 Pro
CVE-2024-37665 None June 12, 2024, 9:15 p.m. LOGO-VULNERABLEWvp GB28181 Pro
CVE-2024-3467 None June 12, 2024, 9:15 p.m. LOGO-VULNERABLEAVEVA PI Asset Framework Client
CVE-2024-3468 None June 12, 2024, 9:15 p.m. LOGO-VULNERABLEAVEVA PI Web API