Tag : 2024-07-02

4 attack reports | 146 vulnerabilities

Attack Reports

Title Published Tags Description Number of indicators
ONNX Store: Phishing-as-a-Service Platform Targeting Financial Institution July 2, 2024, 3:45 p.m. This intelligence report analyzes the ONNX Store, a phishing-as-a-service platform targeting financial institutions through embed… 25
Exposing FakeBat loader: distribution methods and adversary infrastructure July 2, 2024, 8:33 a.m. During the first semester of 2024, FakeBat (aka EugenLoader, PaykLoader) was one of the most widespread loaders using the drive-b… 237
Mining Gang's New Tool: k4spreader July 2, 2024, 8:22 a.m. QIanxin describes the discovery and analysis of k4spreader, a new malware installer and spreader tool developed by the 8220 minin… 35
Exploiting CVE-2021-40444 to Infiltrate Systems July 2, 2024, 8:09 a.m. A recently detected attack exploited a vulnerability in Microsoft Office to deploy spyware called MerkSpy. The initial vector was… 6

Vulnerabilities

CVE CVSS Published Product impacted Tags
CVE-2023-41917 10.0 July 2, 2024, 8:15 a.m. LOGO-VULNERABLESpeed-Measurement feature
CVE-2023-41918 10.0 July 2, 2024, 8:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-6172 9.8 July 2, 2024, 7:15 a.m. LOGO-VULNERABLEEmail Subscribers by Icegram Express - Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin
CVE-2023-41919 9.8 July 2, 2024, 8:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2023-41920 9.8 July 2, 2024, 8:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2023-41921 9.8 July 2, 2024, 8:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-6439 9.8 July 2, 2024, 11:15 a.m. LOGO-VULNERABLESourceCodester Home Owners Collection Management System
CVE-2024-6440 9.8 July 2, 2024, 11:15 a.m. LOGO-VULNERABLESourceCodester Home Owners Collection Management System
CVE-2024-36404 9.8 July 2, 2024, 2:15 p.m. LOGO-VULNERABLEGeoTools
CVE-2024-4708 9.8 July 2, 2024, 11:15 p.m. LOGO-VULNERABLEmySCADA myPRO
CVE-2024-32755 9.1 July 2, 2024, 2:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-5349 8.8 July 2, 2024, 5:15 a.m. LOGO-VULNERABLELA-Studio Element Kit for Elementor plugin for WordPress
CVE-2023-41926 8.8 July 2, 2024, 8:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-34593 8.8 July 2, 2024, 10:15 a.m. LOGO-VULNERABLElibrtp.so
CVE-2024-37479 8.5 July 2, 2024, 8:15 a.m. LOGO-VULNERABLELA-Studio Element Kit for Elementor
CVE-2024-34584 8.4 July 2, 2024, 10:15 a.m. LOGO-VULNERABLESumenNService
CVE-2024-4897 8.4 July 2, 2024, 3:15 p.m. LOGO-VULNERABLEparisneo/lollms-webui
CVE-2024-36243 8.2 July 2, 2024, 9:15 a.m. LOGO-VULNERABLEOpenHarmony
CVE-2024-36260 8.2 July 2, 2024, 9:15 a.m. LOGO-VULNERABLEOpenHarmony
CVE-2024-37030 8.2 July 2, 2024, 9:15 a.m. LOGO-VULNERABLEOpenHarmony
CVE-2024-37077 8.2 July 2, 2024, 9:15 a.m. LOGO-VULNERABLEOpenHarmony
CVE-2024-37185 8.2 July 2, 2024, 9:15 a.m. LOGO-VULNERABLEOpenHarmony
CVE-2024-4679 7.8 July 2, 2024, 2:15 a.m. LOGO-VULNERABLEHitachi JP1/Extensible SNMP Agent for Windows
CVE-2024-20888 7.8 July 2, 2024, 10:15 a.m. LOGO-VULNERABLEOneUIHome
CVE-2024-20891 7.8 July 2, 2024, 10:15 a.m. LOGO-VULNERABLESamsung SystemUI
CVE-2024-34585 7.8 July 2, 2024, 10:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-34595 7.8 July 2, 2024, 10:15 a.m. LOGO-VULNERABLEAndroid SystemUI
CVE-2024-34122 7.8 July 2, 2024, 2:15 p.m. LOGO-VULNERABLEAcrobat for Edge
CVE-2024-38519 7.8 July 2, 2024, 2:15 p.m. LOGO-VULNERABLEyt-dlp
CVE-2024-4467 7.8 July 2, 2024, 4:15 p.m. LOGO-VULNERABLEQEMU
CVE-2024-20895 7.7 July 2, 2024, 10:15 a.m. LOGO-VULNERABLEDar service
CVE-2024-5865 7.7 July 2, 2024, 4:15 p.m. LOGO-VULNERABLEDelinea Centrify PAS
CVE-2024-4836 7.5 July 2, 2024, 9:15 a.m. LOGO-VULNERABLEEdito CMS
CVE-2024-34587 7.5 July 2, 2024, 10:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-34596 7.5 July 2, 2024, 10:15 a.m. LOGO-VULNERABLESmartThings
CVE-2023-41922 7.2 July 2, 2024, 8:15 a.m. LOGO-VULNERABLEwebserver
CVE-2023-41923 7.2 July 2, 2024, 8:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-39323 7.1 July 2, 2024, 4:15 p.m. LOGO-VULNERABLEaimeos/ai-admin-graphql
CVE-2024-32756 6.8 July 2, 2024, 2:15 p.m. LOGO-VULNERABLELinux kernel
CVE-2024-32757 6.8 July 2, 2024, 2:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-32932 6.8 July 2, 2024, 3:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-32854 6.7 July 2, 2024, 7:15 a.m. LOGO-VULNERABLEDell PowerScale OneFS
CVE-2024-37126 6.7 July 2, 2024, 8:15 a.m. LOGO-VULNERABLEDell PowerScale OneFS
CVE-2024-37132 6.7 July 2, 2024, 8:15 a.m. LOGO-VULNERABLEDell PowerScale OneFS
CVE-2024-37133 6.7 July 2, 2024, 8:15 a.m. LOGO-VULNERABLEDell PowerScale OneFS
CVE-2024-37134 6.7 July 2, 2024, 8:15 a.m. LOGO-VULNERABLEDell PowerScale OneFS
CVE-2024-20892 6.5 July 2, 2024, 10:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-6438 6.5 July 2, 2024, 11:15 a.m. LOGO-VULNERABLEHitout Carsale
CVE-2024-39316 6.5 July 2, 2024, 4:15 p.m. LOGO-VULNERABLERack
CVE-2024-5938 6.4 July 2, 2024, 2:15 a.m. LOGO-VULNERABLEBoot Store theme for WordPress
CVE-2024-5419 6.4 July 2, 2024, 4:15 a.m. LOGO-VULNERABLEVoid Contact Form 7 Widget For Elementor Page Builder plugin for WordPress
CVE-2024-1427 6.4 July 2, 2024, 6:15 a.m. LOGO-VULNERABLEThe Post Grid - Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress
CVE-2024-5219 6.4 July 2, 2024, 7:15 a.m. LOGO-VULNERABLEEasy Google Maps plugin for WordPress
CVE-2024-3513 6.4 July 2, 2024, 8:15 a.m. LOGO-VULNERABLEUltimate Blocks - WordPress Blocks Plugin
CVE-2024-5504 6.4 July 2, 2024, 8:15 a.m. LOGO-VULNERABLERife Elementor Extensions & Templates plugin for WordPress
CVE-2024-5260 6.4 July 2, 2024, 9:15 a.m. LOGO-VULNERABLESina Extension for Elementor plugin for WordPress
CVE-2024-6382 6.4 July 2, 2024, 6:15 p.m. LOGO-VULNERABLEMongoDB Rust Driver
CVE-2024-6441 6.3 July 2, 2024, 12:15 p.m. LOGO-VULNERABLEORIPA
CVE-2024-6452 6.3 July 2, 2024, 8:15 p.m. LOGO-VULNERABLElinlinjava litemall
CVE-2024-6453 6.3 July 2, 2024, 10:15 p.m. LOGO-VULNERABLEitsourcecode Farm Management System
CVE-2024-5544 6.1 July 2, 2024, 8:15 a.m. LOGO-VULNERABLEMedia Library Assistant plugin for WordPress
CVE-2024-20893 6.1 July 2, 2024, 10:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-32852 5.9 July 2, 2024, 7:15 a.m. LOGO-VULNERABLEDell PowerScale OneFS
CVE-2024-20889 5.9 July 2, 2024, 10:15 a.m. LOGO-VULNERABLEBLE (Bluetooth Low Energy) module
CVE-2024-20901 5.9 July 2, 2024, 10:15 a.m. LOGO-VULNERABLElibsaped
CVE-2024-34586 5.9 July 2, 2024, 10:15 a.m. LOGO-VULNERABLEKnoxCustomManagerService
CVE-2024-39315 5.7 July 2, 2024, 8:15 p.m. LOGO-VULNERABLEPomerium
CVE-2024-20896 5.5 July 2, 2024, 10:15 a.m. LOGO-VULNERABLESamsung Galaxy devices
CVE-2024-34594 5.5 July 2, 2024, 10:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-39322 5.5 July 2, 2024, 9:15 p.m. LOGO-VULNERABLEaimeos/ai-admin-jsonadm
CVE-2024-4268 5.4 July 2, 2024, 11:15 a.m. LOGO-VULNERABLEUltimate Blocks - WordPress Blocks Plugin
CVE-2024-6264 5.4 July 2, 2024, 11:15 a.m. LOGO-VULNERABLEPost Meta Data Manager plugin for WordPress
CVE-2023-41927 5.3 July 2, 2024, 8:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2023-41928 5.3 July 2, 2024, 8:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-5545 5.3 July 2, 2024, 8:15 a.m. LOGO-VULNERABLEMotors – Car Dealer, Classifieds & Listing plugin for WordPress
CVE-2024-20890 5.3 July 2, 2024, 10:15 a.m. LOGO-VULNERABLEBLE (Bluetooth Low Energy) for Samsung devices
CVE-2024-34588 5.3 July 2, 2024, 10:15 a.m. LOGO-VULNERABLEUnknown
CVE-2024-34589 5.3 July 2, 2024, 10:15 a.m. LOGO-VULNERABLEUnknown
CVE-2024-34601 5.3 July 2, 2024, 10:15 a.m. LOGO-VULNERABLEGalaxyStore
CVE-2024-6088 5.3 July 2, 2024, 11:15 a.m. LOGO-VULNERABLELearnPress WordPress LMS Plugin
CVE-2024-6099 5.3 July 2, 2024, 11:15 a.m. LOGO-VULNERABLELearnPress - WordPress LMS Plugin
CVE-2024-39891 5.3 July 2, 2024, 6:15 p.m. LOGO-VULNERABLEAuthy API
CVE-2024-39325 5.3 July 2, 2024, 9:15 p.m. LOGO-VULNERABLEaimeos/ai-controller-frontend
CVE-2024-2819 5.1 July 2, 2024, 2:15 a.m. LOGO-VULNERABLEHitachi Ops Center Common Services
CVE-2024-0158 5.1 July 2, 2024, 7:15 a.m. LOGO-VULNERABLEDell BIOS
CVE-2024-5866 5.0 July 2, 2024, 4:15 p.m. LOGO-VULNERABLEDelinea Centrify PAS
CVE-2024-6011 4.8 July 2, 2024, 10:15 a.m. LOGO-VULNERABLECost Calculator Builder plugin for WordPress
CVE-2024-32853 4.4 July 2, 2024, 7:15 a.m. LOGO-VULNERABLEDell PowerScale OneFS
CVE-2024-39326 4.4 July 2, 2024, 9:15 p.m. LOGO-VULNERABLESkillTree
CVE-2024-38857 4.3 July 2, 2024, 8:15 a.m. LOGO-VULNERABLECheckmk
CVE-2024-20894 4.3 July 2, 2024, 10:15 a.m. LOGO-VULNERABLEUnknown
CVE-2024-34590 4.3 July 2, 2024, 10:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-34591 4.3 July 2, 2024, 10:15 a.m. LOGO-VULNERABLEUnknown
CVE-2024-34592 4.3 July 2, 2024, 10:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-6012 4.3 July 2, 2024, 10:15 a.m. LOGO-VULNERABLECost Calculator Builder plugin for WordPress
CVE-2024-20897 4.0 July 2, 2024, 10:15 a.m. LOGO-VULNERABLESamsung IMS service
CVE-2024-20898 4.0 July 2, 2024, 10:15 a.m. LOGO-VULNERABLESoftphoneClient in IMS service
CVE-2024-20899 4.0 July 2, 2024, 10:15 a.m. LOGO-VULNERABLESamsung IMS Service
CVE-2024-20900 4.0 July 2, 2024, 10:15 a.m. LOGO-VULNERABLEMTP application
CVE-2024-34583 4.0 July 2, 2024, 10:15 a.m. LOGO-VULNERABLESamsung
CVE-2024-6381 4.0 July 2, 2024, 6:15 p.m. LOGO-VULNERABLElibbson
CVE-2024-39324 3.8 July 2, 2024, 9:15 p.m. LOGO-VULNERABLEaimeos/ai-admin-graphql
CVE-2024-31071 3.3 July 2, 2024, 9:15 a.m. LOGO-VULNERABLEOpenHarmony
CVE-2024-36278 3.3 July 2, 2024, 9:15 a.m. LOGO-VULNERABLEOpenHarmony
CVE-2024-34597 3.3 July 2, 2024, 10:15 a.m. LOGO-VULNERABLESamsung Health
CVE-2024-34599 3.3 July 2, 2024, 10:15 a.m. LOGO-VULNERABLETips for Android
CVE-2024-34600 3.3 July 2, 2024, 10:15 a.m. LOGO-VULNERABLESamsung Flow
CVE-2024-38537 0.0 July 2, 2024, 8:15 p.m. LOGO-VULNERABLEFides
CVE-2024-3999 None July 2, 2024, 6:15 a.m. LOGO-VULNERABLEEazyDocs WordPress plugin
CVE-2024-4627 None July 2, 2024, 6:15 a.m. LOGO-VULNERABLERank Math SEO WordPress plugin
CVE-2024-5606 None July 2, 2024, 6:15 a.m. LOGO-VULNERABLEQuiz and Survey Master (QSM) WordPress plugin
CVE-2024-5767 None July 2, 2024, 6:15 a.m. LOGO-VULNERABLEWordPress Plugin sitetweet
CVE-2024-39119 None July 2, 2024, 1:15 p.m. LOGO-VULNERABLEidccms
CVE-2024-39143 None July 2, 2024, 2:15 p.m. LOGO-VULNERABLEResidenceCMS
CVE-2023-51776 None July 2, 2024, 3:15 p.m. LOGO-VULNERABLEJungo WinDriver
CVE-2023-51777 None July 2, 2024, 3:15 p.m. LOGO-VULNERABLEJungo WinDriver
CVE-2023-51778 None July 2, 2024, 3:15 p.m. LOGO-VULNERABLEJungo WinDriver
CVE-2024-22102 None July 2, 2024, 3:15 p.m. LOGO-VULNERABLEWinDriver
CVE-2024-22103 None July 2, 2024, 3:15 p.m. LOGO-VULNERABLEJungo WinDriver
CVE-2024-22104 None July 2, 2024, 3:15 p.m. LOGO-VULNERABLEJungo WinDriver
CVE-2024-22105 None July 2, 2024, 4:15 p.m. LOGO-VULNERABLEJungo WinDriver
CVE-2024-22106 None July 2, 2024, 4:15 p.m. LOGO-VULNERABLEJungo WinDriver
CVE-2024-25086 None July 2, 2024, 4:15 p.m. LOGO-VULNERABLEJungo WinDriver
CVE-2024-25087 None July 2, 2024, 4:15 p.m. LOGO-VULNERABLEJungo WinDriver
CVE-2024-25088 None July 2, 2024, 4:15 p.m. LOGO-VULNERABLEJungo WinDriver
CVE-2024-26314 None July 2, 2024, 4:15 p.m. LOGO-VULNERABLEJungo WinDriver
CVE-2024-3826 None July 2, 2024, 4:15 p.m. LOGO-VULNERABLEAkana
CVE-2022-32147 None July 2, 2024, 5:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2022-32191 None July 2, 2024, 5:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2022-3428 None July 2, 2024, 5:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2022-41718 None July 2, 2024, 5:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2022-41726 None July 2, 2024, 5:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2022-41728 None July 2, 2024, 5:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2022-41729 None July 2, 2024, 5:15 p.m. LOGO-VULNERABLEGo programming language
CVE-2022-41730 None July 2, 2024, 5:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2023-39324 None July 2, 2024, 5:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-39206 None July 2, 2024, 6:15 p.m. LOGO-VULNERABLEMSP360 Backup Agent
CVE-2024-39894 None July 2, 2024, 6:15 p.m. LOGO-VULNERABLEOpenSSH
CVE-2024-6341 None July 2, 2024, 6:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2022-25477 None July 2, 2024, 7:15 p.m. LOGO-VULNERABLERealtek RtsPer driver for PCIe Card Reader
CVE-2022-25478 None July 2, 2024, 7:15 p.m. LOGO-VULNERABLERealtek RtsPer driver for PCIe Card Reader
CVE-2022-25479 None July 2, 2024, 7:15 p.m. LOGO-VULNERABLERealtek RtsPer driver for PCIe Card Reader
CVE-2022-25480 None July 2, 2024, 7:15 p.m. LOGO-VULNERABLERealtek RtsPer driver for PCIe Card Reader
CVE-2022-30636 None July 2, 2024, 8:15 p.m. LOGO-VULNERABLEGo programming language
CVE-2023-24531 None July 2, 2024, 8:15 p.m. LOGO-VULNERABLEGo programming language
CVE-2024-24791 None July 2, 2024, 10:15 p.m. LOGO-VULNERABLEUNKNOWN