Tag: remote-code-execution
-
Vulnerabilities in employee management system could lead to remote code execution, login credential theft
Talos also recently helped to responsibly disclose and patch other vulnerabilities in the Foxit PDF Reader and two open-source libraries that support … First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/vulnerability-roundup-may-1-2024/
-
Exploit for critical Progress Telerik auth bypass released, patch now
Researchers have published a proof-of-concept (PoC) exploit script demonstrating a chained remote code execution (RCE) vulnerability on Progress Teler… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/exploit-for-critical-progress-telerik-auth-bypass-released-patch-now/
-
Ivanti Patches Critical Remote Code Execution Flaws in Endpoint Manager
Ivanti on Tuesday rolled out fixes to address multiple critical security flaws in Endpoint Manager (EPM) that could be exploited to achieve remote cod… First seen on thehackernews.com Jump to article: thehackernews.com/2024/05/ivanti-patches-critical-remote-code.html
-
Security Advisory: Microsoft Windows DNS Server Remote Code Execution Vulnerability
Summary On July 14th, 2020 Microsoft publicly disclosed the existence of a critical severity vulnerability in all recent versions of the Microsoft Win… First seen on research.kudelskisecurity.com Jump to article: research.kudelskisecurity.com/2020/07/17/security-advisory-microsoft-windows-dns-server-remote-code-execution-vulnerability/
-
Fortinet FortiSIEM Vulnerabilities Expose Systems to Remote Code Execution
Multiple vulnerabilities have recently been discovered in Fortinet FortiSIEM, raising concerns over potential remote code execution exploits. FortiSIE… First seen on thecyberexpress.com Jump to article: thecyberexpress.com/fortinet-fortisiem-vulnerability/
-
Experts released PoC exploit code for RCE in Fortinet SIEM
Researchers released a proof-of-concept (PoC) exploit for remote code execution flaw CVE-2024-23108 in Fortinet SIEM solution. Security researchers at… First seen on securityaffairs.com Jump to article: securityaffairs.com/163797/hacking/fortinet-siem-critical-rce-poc.html
-
TP-Link Archer C5400X gaming router is affected by a critical flaw
Researchers warn of a critical remote code execution vulnerability in TP-Link Archer C5400X gaming router. Researchers at OneKeydiscovered a a critica… First seen on securityaffairs.com Jump to article: securityaffairs.com/163762/hacking/tp-link-archer-c5400x-critical-flaw.html
-
Critical Netflix Genie Bug Opens Big Data Orchestration to RCE
The severe security vulnerability (CVE-2024-4701, CVSS 9.9) gives remote attackers a way to burrow into Netflix’s Genie open source platform, which is… First seen on darkreading.com Jump to article: www.darkreading.com/application-security/netflix-fixes-critical-vulnerability-on-big-data-orchestration-service
-
Exploit released for maximum severity Fortinet RCE bug, patch now
‹Security researchers have released a proof-of-concept (PoC) exploit for a maximum-severity vulnerability in Fortinet’s security information and event… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/exploit-released-for-maximum-severity-fortinet-rce-bug-patch-now/
-
TP-Link fixes critical RCE bug in popular C5400X gaming router
The TP-Link Archer C5400X gaming router is vulnerable to security flaws that could enable an unauthenticated, remote attacker to execute commands on t… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/tp-link-fixes-critical-rce-bug-in-popular-c5400x-gaming-router/
-
Critical Bug Allows DoS, RCE, Data Leaks in All Major Cloud Platforms
An on-by-default endpoint in ubiquitous logging service Fluent Bit contains an oversight that hackers can toy with to rattle most any cloud environmen… First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/critical-bug-dos-rce-data-leaks-in-all-major-cloud-platforms
-
AI-as-a-Service Platform Patches Critical RCE Vulnerability
Hackers Could Exploit Bug on Replicate to Steal Data, Manipulate AI Models. Attackers could have exploited a now-mitigated critical vulnerability in t… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/ai-as-a-service-platform-patches-critical-rce-vulnerability-a-25324
-
Critical SQL Injection flaws impact Ivanti Endpoint Manager (EPM)
Ivanti addressed multiple flaws in the Endpoint Manager (EPM), including remote code execution vulnerabilities. Ivanti this week rolled out security p… First seen on securityaffairs.com Jump to article: securityaffairs.com/163587/security/ivanti-endpoint-manager-critical-sql-injection.html
-
Patch up 4 critical bugs in ArubaOS lead to remote code execution
First seen on theregister.com Jump to article: www.theregister.com/2024/05/02/hpe_aruba_patches/
-
Critical Fluent Bit flaw impacts all major cloud providers
‹A critical Fluent Bit vulnerability that can be exploited in denial-of-service and remote code execution attacks impacts all major cloud providers an… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/critical-fluent-bit-flaw-impacts-all-major-cloud-providers/
-
Critical Flaw In Confluence Server Let Attackers Execute Arbitrary Code
The widely used team workspace corporate wiki Confluence has been discovered to have a critical remote code execution vulnerability. This vulnerabilit… First seen on gbhackers.com Jump to article: gbhackers.com/critical-confluence-server-flaw/
-
CISA Warns of Attacks Exploiting NextGen Healthcare Mirth Connect Flaw
CISA has added CVE-2023-43208, an unauthenticated remote code execution vulnerability, to its KEV catalog. The post added CVE-2023-43208, an unauthen… First seen on securityweek.com Jump to article: www.securityweek.com/cisa-warns-of-attacks-exploiting-nextgen-healthcare-mirth-connect-flaw/
-
Experts released PoC exploit code for RCE in QNAP QTS
Experts warn of fifteen vulnerabilities in the QNAP QTS, the operating system for the Taiwanese vendor’s NAS products. An audit of QNAP QTS conducted … First seen on securityaffairs.com Jump to article: securityaffairs.com/163470/hacking/fifteen-vulnerabilities-in-the-qnap-qts.html
-
QNAP Rushes Patch for Code Execution Flaw in NAS Devices
QNAP rolls out patches for multiple vulnerabilities after proof-of-concept exploit published for a remote code execution vulnerability. The post ls ou… First seen on securityweek.com Jump to article: www.securityweek.com/qnap-rushes-patch-for-code-execution-flaw-in-nas-devices/
-
AI Python Package Flaw ‘Llama Drama’ Threatens Software Supply Chain
The Llama Drama vulnerability in the Llama-cpp-Python package exposes AI models to remote code execution (RCE) attacks, enabling attackers to steal da… First seen on hackread.com Jump to article: www.hackread.com/ai-python-package-flaw-llama-drama-supply-chain/
-
PoC Exploit Released for QNAP QTS zero-day RCE Flaw
Researchers have shown a proof-of-concept (PoC) attack for a zero-day remote code execution (RCE) flaw in the QTS operating system from QNAP. Users of… First seen on gbhackers.com Jump to article: gbhackers.com/poc-exploit-released-2/
-
QNAP QTS zero-day in Share feature gets public RCE exploit
An extensive security audit of QNAP QTS, the operating system for the company’s NAS products, has uncovered fifteen vulnerabilities of varying severit… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/qnap-qts-zero-day-in-share-feature-gets-public-rce-exploit/
-
Critical Git Vulnerability Let Attackers Execute Remote Code : PoC Published
A critical remote code execution vulnerability has been discovered in the git clone which was assigned with CVE-2024-32002 and the severity has been g… First seen on gbhackers.com Jump to article: gbhackers.com/git-flaw-remote-code-execution/
-
6K-plus AI models may be affected by critical RCE vulnerability
First seen on scmagazine.com Jump to article: www.scmagazine.com/news/6k-plus-ai-models-may-be-affected-by-critical-rce-vulnerability
-
Critical Git vulnerability allows RCE when cloning repositories with submodules (CVE-2024-32002)
New versions of Git are out, with fixes for five vulnerabilities, the most critical (CVE-2024-32002) of which can be used by attackers to remotely exe… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/05/16/git-cve-2024-32002/
-
PoC Exploit Released For D-LINK RCE Zero-Day Vulnerability
Two critical vulnerabilities have been discovered in D-Link DIR-X4860 routers which were associated with Authentication bypass due to HNAP port and re… First seen on gbhackers.com Jump to article: gbhackers.com/d-link-rce-zero-day-exploit-released/
-
Critical Tinyproxy Flaw Opens Over 50,000 Hosts to Remote Code Execution
More than 50% of the 90,310 hosts have been found exposing a Tinyproxy service on the internet that’s vulnerable to a critical unpatched security flaw… First seen on thehackernews.com Jump to article: thehackernews.com/2024/05/critical-tinyproxy-flaw-opens-over.html
-
PoC exploit released for RCE zero-day in D-Link EXO AX4800 routers
The D-Link EXO AX4800 (DIR-X4860) router is vulnerable to remote unauthenticated command execution that could lead to complete device takeovers by att… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/poc-exploit-released-for-rce-zero-day-in-d-link-exo-ax4800-routers/
-
Critical Bug Could Open 50K+ Tinyproxy Servers to DoS, RCE
First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/critical-bug-50k-tinyproxy-servers-dos-rce
-
Four Critical Vulnerabilities Expose HPE Aruba Devices to RCE Attacks
HPE Aruba Networking (formerly Aruba Networks) has released security updates to address critical flaws impacting ArubaOS that could result in remote c… First seen on thehackernews.com Jump to article: thehackernews.com/2024/05/four-critical-vulnerabilities-expose.html

