πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Dark Web Forum Activity Surged 44% in Early COVID Months πŸ•΄

Researchers analyzed the activity of five popular English- and Russian-speaking Dark Web forums and discovered exponential membership growth.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-29500 β€Ό

Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-35170 β€Ό

Dell EMC Unisphere for PowerMax versions prior to 9.1.0.9, Dell EMC Unisphere for PowerMax versions prior to 9.0.2.16, and Dell EMC PowerMax OS 5978.221.221 and 5978.479.479 contain a Cross-Site Scripting (XSS) vulnerability. An authenticated malicious user may potentially exploit this vulnerability to inject javascript code and affect other authenticated usersÒ€ℒ sessions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-23249 β€Ό

GigaVUE-OS (GVOS) 5.4 - 5.9 stores a Redis database password in plaintext.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36051 β€Ό

Directory traversal vulnerability in page_edit.php in MiniCMS V1.10 allows remote attackers to read arbitrary files via the state parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36066 β€Ό

GJSON <1.6.5 allows attackers to cause a denial of service (remote) via crafted JSON.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36052 β€Ό

Directory traversal vulnerability in post-edit.php in MiniCMS V1.10 allows remote attackers to include and execute arbitrary files via the state parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-29501 β€Ό

Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X & T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-29490 β€Ό

Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a Denial of Service vulnerability on NAS Servers with NFS exports. A remote authenticated attacker could potentially exploit this vulnerability and cause Denial of Service (Storage Processor Panic) by sending specially crafted UDP requests.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-20484 β€Ό

An issue was discovered in Viki Vera 4.9.1.26180. A user without access to a project could download or upload project files by opening the Project URL directly in the browser after logging in.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26181 β€Ό

Dell EMC Isilon OneFS versions 8.1 and later and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation vulnerability on a SmartLock Compliance mode cluster. The compadmin user connecting using ISI PRIV LOGIN SSH or ISI PRIV LOGIN CONSOLE can elevate privileges to the root user if they have ISI PRIV HARDENING privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-29489 β€Ό

Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contains a plain-text password storage vulnerability. A user credentials (including the Unisphere admin privilege user) password is stored in a plain text in a system file. A local authenticated attacker with access to the system files may use the exposed password to gain access with the privileges of the compromised user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36067 β€Ό

GJSON <=v1.6.5 allows attackers to cause a denial of service (panic: runtime error: slice bounds out of range) via a crafted GET call.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-29437 β€Ό

SQL injection in the Buzz module of OrangeHRM through 4.6 allows remote authenticated attackers to execute arbitrary SQL commands via the orangehrmBuzzPlugin/lib/dao/BuzzDao.php loadMorePostsForm[profileUserId] parameter to the buzz/loadMoreProfile endpoint.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-20483 β€Ό

An issue was discovered in Viki Vera 4.9.1.26180. An attacker could set a user's last name to an XSS Payload, and read another user's cookie and use that to login to the application.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26199 β€Ό

Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a plain-text password storage vulnerability. A user credentials (including the Unisphere admin privilege user) password is stored in a plain text in multiple log files. A local authenticated attacker with access to the log files may use the exposed password to gain access with the privileges of the compromised user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-29502 β€Ό

Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X & T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-23250 β€Ό

GigaVUE-OS (GVOS) 5.4 - 5.9 uses a weak algorithm for a hash stored in internal database.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-7336 β€Ό

Cross Site Request Forgery vulnerability in McAfee Network Security Management (NSM) prior to 10.1.7.35 and NSM 9.x prior to 9.2.9.55 may allow an attacker to change the configuration of the Network Security Manager via a carefully crafted HTTP request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3026 β€Ό

Invision Community IPS Community Suite before 4.5.4.2 allows XSS during the quoting of a post or comment.

πŸ“– Read

via "National Vulnerability Database".
❌ Feds Pinpoint Russia as β€˜Likely’ Culprit Behind SolarWinds Attack ❌

The widespread compromise affecting key government agencies is ongoing, according to the U.S. government.

πŸ“– Read

via "Threat Post".