Lucene search

K

Telegram Bot & Channel Security Vulnerabilities

securelist
securelist

Message board scams

Marketplace fraud is nothing new. Cybercriminals swindle money out of buyers and sellers alike. Lately, we've seen a proliferation of cybergangs operating under the Fraud-as-a-Service model and specializing in tricking users of online marketplaces, in particular, message boards. Criminals are...

6.4AI Score

2024-05-27 01:00 PM
9
redhatcve
redhatcve

CVE-2021-47502

In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wcd934x: handle channel mappping list correctly Currently each channel is added as list to dai channel list, however there is danger of adding same channel to multiple dai channel list which endups corrupting the...

6.6AI Score

0.0004EPSS

2024-05-27 11:30 AM
6
redhatcve
redhatcve

CVE-2021-47521

In the Linux kernel, the following vulnerability has been resolved: can: sja1000: fix use after free in ems_pcmcia_add_card() If the last channel is not available then "dev" is freed. Fortunately, we can just use "pdev->irq" instead. Also we should check if at least one channel was set...

7.8CVSS

6.7AI Score

0.0004EPSS

2024-05-27 11:03 AM
4
githubexploit

9.8CVSS

7.1AI Score

0.97EPSS

2024-05-27 03:31 AM
90
nvd
nvd

CVE-2024-36255

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper input validation on post actions which allows an attacker to run a playbook checklist task command as another user via creating and sharing a deceptive post action that unexpectedly runs a slash c...

5.7CVSS

5.7AI Score

0.0004EPSS

2024-05-26 02:15 PM
1
cve
cve

CVE-2024-36255

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper input validation on post actions which allows an attacker to run a playbook checklist task command as another user via creating and sharing a deceptive post action that unexpectedly runs a slash c...

5.7CVSS

6.9AI Score

0.0004EPSS

2024-05-26 02:15 PM
28
cve
cve

CVE-2024-5272

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to restrict the audience of the "custom_playbooks_playbook_run_updated" webhook event, which allows a guest on a channel with a playbook run linked to see all the details of the playbook run when the run is marked by....

4.3CVSS

6.7AI Score

0.0004EPSS

2024-05-26 02:15 PM
28
nvd
nvd

CVE-2024-5272

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to restrict the audience of the "custom_playbooks_playbook_run_updated" webhook event, which allows a guest on a channel with a playbook run linked to see all the details of the playbook run when the run is marked by....

4.3CVSS

4.6AI Score

0.0004EPSS

2024-05-26 02:15 PM
2
nvd
nvd

CVE-2024-32045

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access controls for channel and team membership when linking a playbook run to a channel which allows members to link their runs to private channels they were not members...

5.9CVSS

5.7AI Score

0.0004EPSS

2024-05-26 02:15 PM
1
cve
cve

CVE-2024-34029

Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1 and 8.1.x <= 8.1.12 fail to perform a proper authorization check in the /api/v4/groups//channels//link endpoint which allows a user to learn the members of an AD/LDAP group that is linked to a team by adding the group to a channel, even if...

4.3CVSS

6.7AI Score

0.0004EPSS

2024-05-26 02:15 PM
29
nvd
nvd

CVE-2024-34152

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper access control which allows a guest to get the metadata of a public playbook run that linked to the channel they are guest via sending an RHSRuns GraphQL query request to the...

4.3CVSS

4.6AI Score

0.0004EPSS

2024-05-26 02:15 PM
nvd
nvd

CVE-2024-34029

Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1 and 8.1.x <= 8.1.12 fail to perform a proper authorization check in the /api/v4/groups//channels//link endpoint which allows a user to learn the members of an AD/LDAP group that is linked to a team by adding the group to a channel, even if...

4.3CVSS

4.5AI Score

0.0004EPSS

2024-05-26 02:15 PM
1
cve
cve

CVE-2024-32045

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access controls for channel and team membership when linking a playbook run to a channel which allows members to link their runs to private channels they were not members...

5.9CVSS

6.8AI Score

0.0004EPSS

2024-05-26 02:15 PM
26
cve
cve

CVE-2024-34152

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper access control which allows a guest to get the metadata of a public playbook run that linked to the channel they are guest via sending an RHSRuns GraphQL query request to the...

4.3CVSS

6.8AI Score

0.0004EPSS

2024-05-26 02:15 PM
33
nvd
nvd

CVE-2024-31859

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper authorization checks which allows a member running a playbook in an existing channel to be promoted to a channel...

4.3CVSS

4.5AI Score

0.0004EPSS

2024-05-26 02:15 PM
cve
cve

CVE-2024-31859

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper authorization checks which allows a member running a playbook in an existing channel to be promoted to a channel...

4.3CVSS

6.7AI Score

0.0004EPSS

2024-05-26 02:15 PM
28
cve
cve

CVE-2024-29215

Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access control which allows a user to run a slash command in a channel they are not a member of via linking a playbook run to that channel and running a slash command as a playbook...

4.3CVSS

6.8AI Score

0.0004EPSS

2024-05-26 02:15 PM
25
nvd
nvd

CVE-2024-29215

Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access control which allows a user to run a slash command in a channel they are not a member of via linking a playbook run to that channel and running a slash command as a playbook...

4.3CVSS

4.7AI Score

0.0004EPSS

2024-05-26 02:15 PM
cvelist
cvelist

CVE-2024-29215 Slash commands run in channel without channel membership via playbook task commands

Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access control which allows a user to run a slash command in a channel they are not a member of via linking a playbook run to that channel and running a slash command as a playbook...

4.3CVSS

4.7AI Score

0.0004EPSS

2024-05-26 01:33 PM
vulnrichment
vulnrichment

CVE-2024-29215 Slash commands run in channel without channel membership via playbook task commands

Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access control which allows a user to run a slash command in a channel they are not a member of via linking a playbook run to that channel and running a slash command as a playbook...

4.3CVSS

7AI Score

0.0004EPSS

2024-05-26 01:33 PM
vulnrichment
vulnrichment

CVE-2024-36255 Post actions can run playbook checklist task commands

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper input validation on post actions which allows an attacker to run a playbook checklist task command as another user via creating and sharing a deceptive post action that unexpectedly runs a slash c...

5.7CVSS

7.1AI Score

0.0004EPSS

2024-05-26 01:32 PM
2
cvelist
cvelist

CVE-2024-36255 Post actions can run playbook checklist task commands

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper input validation on post actions which allows an attacker to run a playbook checklist task command as another user via creating and sharing a deceptive post action that unexpectedly runs a slash c...

5.7CVSS

5.7AI Score

0.0004EPSS

2024-05-26 01:32 PM
1
cvelist
cvelist

CVE-2024-31859 Member promoted to channel admin via playbooks run linking to channel

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper authorization checks which allows a member running a playbook in an existing channel to be promoted to a channel...

4.3CVSS

4.5AI Score

0.0004EPSS

2024-05-26 01:31 PM
vulnrichment
vulnrichment

CVE-2024-31859 Member promoted to channel admin via playbooks run linking to channel

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper authorization checks which allows a member running a playbook in an existing channel to be promoted to a channel...

4.3CVSS

6.8AI Score

0.0004EPSS

2024-05-26 01:31 PM
1
cvelist
cvelist

CVE-2024-5272 Run Details leak to guest via webhook event "custom_playbooks_playbook_run_updated"

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to restrict the audience of the "custom_playbooks_playbook_run_updated" webhook event, which allows a guest on a channel with a playbook run linked to see all the details of the playbook run when the run is marked by....

4.3CVSS

4.6AI Score

0.0004EPSS

2024-05-26 01:29 PM
2
vulnrichment
vulnrichment

CVE-2024-5272 Run Details leak to guest via webhook event "custom_playbooks_playbook_run_updated"

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to restrict the audience of the "custom_playbooks_playbook_run_updated" webhook event, which allows a guest on a channel with a playbook run linked to see all the details of the playbook run when the run is marked by....

4.3CVSS

6.8AI Score

0.0004EPSS

2024-05-26 01:29 PM
vulnrichment
vulnrichment

CVE-2024-32045 Playbook run link to private channel grants channel access

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access controls for channel and team membership when linking a playbook run to a channel which allows members to link their runs to private channels they were not members...

5.9CVSS

6.9AI Score

0.0004EPSS

2024-05-26 01:29 PM
1
cvelist
cvelist

CVE-2024-32045 Playbook run link to private channel grants channel access

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access controls for channel and team membership when linking a playbook run to a channel which allows members to link their runs to private channels they were not members...

5.9CVSS

5.7AI Score

0.0004EPSS

2024-05-26 01:29 PM
2
cvelist
cvelist

CVE-2024-34152 Playbook Run Metadata leak to Guest

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper access control which allows a guest to get the metadata of a public playbook run that linked to the channel they are guest via sending an RHSRuns GraphQL query request to the...

4.3CVSS

4.6AI Score

0.0004EPSS

2024-05-26 01:28 PM
2
vulnrichment
vulnrichment

CVE-2024-34029 AD/LDAP Group Members Leak

Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1 and 8.1.x <= 8.1.12 fail to perform a proper authorization check in the /api/v4/groups//channels//link endpoint which allows a user to learn the members of an AD/LDAP group that is linked to a team by adding the group to a channel, even if...

4.3CVSS

6.8AI Score

0.0004EPSS

2024-05-26 01:27 PM
1
cvelist
cvelist

CVE-2024-34029 AD/LDAP Group Members Leak

Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1 and 8.1.x <= 8.1.12 fail to perform a proper authorization check in the /api/v4/groups//channels//link endpoint which allows a user to learn the members of an AD/LDAP group that is linked to a team by adding the group to a channel, even if...

4.3CVSS

4.5AI Score

0.0004EPSS

2024-05-26 01:27 PM
2
githubexploit
githubexploit

Exploit for CVE-2024-5084

Wordpress Hash Form – Drag & Drop Form Builder <= 1.1.0 -...

9.8CVSS

8.5AI Score

0.035EPSS

2024-05-25 03:49 AM
43
nvd
nvd

CVE-2021-47521

In the Linux kernel, the following vulnerability has been resolved: can: sja1000: fix use after free in ems_pcmcia_add_card() If the last channel is not available then "dev" is freed. Fortunately, we can just use "pdev->irq" instead. Also we should check if at least one channel was set...

7.8CVSS

6.7AI Score

0.0004EPSS

2024-05-24 03:15 PM
1
cve
cve

CVE-2021-47521

In the Linux kernel, the following vulnerability has been resolved: can: sja1000: fix use after free in ems_pcmcia_add_card() If the last channel is not available then "dev" is freed. Fortunately, we can just use "pdev->irq" instead. Also we should check if at least one channel was set...

7.8CVSS

6.9AI Score

0.0004EPSS

2024-05-24 03:15 PM
28
debiancve
debiancve

CVE-2021-47521

In the Linux kernel, the following vulnerability has been resolved: can: sja1000: fix use after free in ems_pcmcia_add_card() If the last channel is not available then "dev" is freed. Fortunately, we can just use "pdev->irq" instead. Also we should check if at least one channel was set...

7.8CVSS

6.8AI Score

0.0004EPSS

2024-05-24 03:15 PM
5
nvd
nvd

CVE-2021-47502

In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wcd934x: handle channel mappping list correctly Currently each channel is added as list to dai channel list, however there is danger of adding same channel to multiple dai channel list which endups corrupting the...

6.6AI Score

0.0004EPSS

2024-05-24 03:15 PM
1
cve
cve

CVE-2021-47502

In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wcd934x: handle channel mappping list correctly Currently each channel is added as list to dai channel list, however there is danger of adding same channel to multiple dai channel list which endups corrupting the...

6.8AI Score

0.0004EPSS

2024-05-24 03:15 PM
24
debiancve
debiancve

CVE-2021-47502

In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wcd934x: handle channel mappping list correctly Currently each channel is added as list to dai channel list, however there is danger of adding same channel to multiple dai channel list which endups corrupting the...

6.7AI Score

0.0004EPSS

2024-05-24 03:15 PM
2
cvelist
cvelist

CVE-2021-47521 can: sja1000: fix use after free in ems_pcmcia_add_card()

In the Linux kernel, the following vulnerability has been resolved: can: sja1000: fix use after free in ems_pcmcia_add_card() If the last channel is not available then "dev" is freed. Fortunately, we can just use "pdev->irq" instead. Also we should check if at least one channel was set...

6.6AI Score

0.0004EPSS

2024-05-24 03:09 PM
1
vulnrichment
vulnrichment

CVE-2021-47521 can: sja1000: fix use after free in ems_pcmcia_add_card()

In the Linux kernel, the following vulnerability has been resolved: can: sja1000: fix use after free in ems_pcmcia_add_card() If the last channel is not available then "dev" is freed. Fortunately, we can just use "pdev->irq" instead. Also we should check if at least one channel was set...

7AI Score

0.0004EPSS

2024-05-24 03:09 PM
1
cvelist
cvelist

CVE-2021-47502 ASoC: codecs: wcd934x: handle channel mappping list correctly

In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wcd934x: handle channel mappping list correctly Currently each channel is added as list to dai channel list, however there is danger of adding same channel to multiple dai channel list which endups corrupting the...

6.5AI Score

0.0004EPSS

2024-05-24 03:01 PM
vulnrichment
vulnrichment

CVE-2021-47502 ASoC: codecs: wcd934x: handle channel mappping list correctly

In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wcd934x: handle channel mappping list correctly Currently each channel is added as list to dai channel list, however there is danger of adding same channel to multiple dai channel list which endups corrupting the...

7AI Score

0.0004EPSS

2024-05-24 03:01 PM
1
githubexploit

10CVSS

7.2AI Score

0.946EPSS

2024-05-24 12:02 PM
186
thn
thn

Update Chrome Browser Now: 4th Zero-Day Exploit Discovered in May 2024

Google on Thursday rolled out fixes to address a high-severity security flaw in its Chrome browser that it said has been exploited in the wild. Assigned the CVE identifier CVE-2024-5274, the vulnerability relates to a type confusion bug in the V8 JavaScript and WebAssembly engine. It was reported.....

9.6CVSS

7.7AI Score

0.968EPSS

2024-05-24 10:10 AM
5
openvas

8.8CVSS

6.2AI Score

0.003EPSS

2024-05-24 12:00 AM
1
openvas

8.8CVSS

6.2AI Score

0.003EPSS

2024-05-24 12:00 AM
2
openvas

8.8CVSS

6.2AI Score

0.003EPSS

2024-05-24 12:00 AM
1
ubuntucve
ubuntucve

CVE-2021-47502

In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wcd934x: handle channel mappping list correctly Currently each channel is added as list to dai channel list, however there is danger of adding same channel to multiple dai channel list which endups corrupting the...

6.7AI Score

0.0004EPSS

2024-05-24 12:00 AM
2
ubuntucve
ubuntucve

CVE-2021-47521

In the Linux kernel, the following vulnerability has been resolved: can: sja1000: fix use after free in ems_pcmcia_add_card() If the last channel is not available then "dev" is freed. Fortunately, we can just use "pdev->irq" instead. Also we should check if at least one channel was set...

7.8CVSS

6.8AI Score

0.0004EPSS

2024-05-24 12:00 AM
2
kaspersky
kaspersky

KLA68204 DoS vulnerability in Opera

Type confusion vulnerability was found in Opera. Malicious users can exploit this vulnerability to cause denial of service. Original advisories Opera 110.0.5130.39 Stable update Stable Channel Update for Desktop Exploitation Public exploits exist for this vulnerability. Related products Opera CVE.....

8.8CVSS

6.4AI Score

0.003EPSS

2024-05-24 12:00 AM
4
Total number of security vulnerabilities52838