βΌ CVE-2021-37911 βΌ
π Read
via "National Vulnerability Database".
The management interface of BenQ smart wireless conference projector does not properly control user's privilege. Attackers can access any system directory of this device through the interface and execute arbitrary commands if he enters the local subnetwork.π Read
via "National Vulnerability Database".
βΌ CVE-2021-24581 βΌ
π Read
via "National Vulnerability Database".
The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin does not have CSRF check in place when saving its settings, allowing the issue to be exploited via a CSRF attack.π Read
via "National Vulnerability Database".
βΌ CVE-2021-24592 βΌ
π Read
via "National Vulnerability Database".
The Sitewide Notice WP WordPress plugin before 2.3 does not sanitise some of its settings before outputting them in frontend pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedπ Read
via "National Vulnerability Database".
βΌ CVE-2021-24667 βΌ
π Read
via "National Vulnerability Database".
A stored cross-site scripting vulnerability has been discovered in : Simply Gallery Blocks with Lightbox (Version Γ’β¬β 2.2.0 & below). The vulnerability exists in the Lightbox functionality where a user with low privileges is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficient validation of image parameters in meta data.π Read
via "National Vulnerability Database".
βΌ CVE-2021-24438 βΌ
π Read
via "National Vulnerability Database".
The ShareThis Dashboard for Google Analytics WordPress plugin before 2.5.2 does not sanitise or escape the 'ga_action' parameter in the stats view before outputting it back in an attribute when the plugin is connected to a Google Analytics account, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administratorπ Read
via "National Vulnerability Database".
βΌ CVE-2021-25958 βΌ
π Read
via "National Vulnerability Database".
In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at multiple locations but leaks out sensitive table info which may aid the attacker for further recon. A user can register with a very long password, but when he tries to login with it an exception occurs.π Read
via "National Vulnerability Database".
βΌ CVE-2021-24665 βΌ
π Read
via "National Vulnerability Database".
The WP Video Lightbox WordPress plugin before 1.9.3 does not escape the attributes of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacksπ Read
via "National Vulnerability Database".
βΌ CVE-2021-24579 βΌ
π Read
via "National Vulnerability Database".
The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unserialize() function without any validation or sanitisation, which could lead to a PHP Object Injection. Even though the plugin did not contain a suitable gadget to fully exploit the issue, other installed plugins on the blog could allow such issue to be exploited and lead to RCE in some cases.π Read
via "National Vulnerability Database".
π¦Ώ Paying ransom should be your last resort, cybersecurity expert says π¦Ώ
π Read
via "Tech Republic".
Some organizations can get by without paying in a ransomware attack, but others really have no choice, he says.π Read
via "Tech Republic".
TechRepublic
Paying ransom should be your last resort, cybersecurity expert says
Some organizations can get by without paying in a ransomware attack, but others really have no choice, he says.
π¦Ώ Expert: Governments and businesses must come together to combat ransomware threat π¦Ώ
π Read
via "Tech Republic".
Nations have to stop sheltering bad actors in order to stop them, expert says.π Read
via "Tech Republic".
TechRepublic
Expert: Governments and businesses must come together to combat ransomware threat
Nations have to stop sheltering bad actors in order to stop them, expert says.
β Microsoft Exchange βProxyTokenβ Bug Allows Email Snooping β
π Read
via "Threat Post".
The bug (CVE-2021-33766) is an information-disclosure issue that could reveal victims' personal information, sensitive company data and more.π Read
via "Threat Post".
Threat Post
Microsoft Exchange βProxyTokenβ Bug Allows Email Snooping
The bug (CVE-2021-33766) is an information-disclosure issue that could reveal victims' personal information, sensitive company data and more.
β The Underground Economy: Recon, Weaponization & Delivery for Account Takeovers β
π Read
via "Threat Post".
In part one of a two-part series, Akamai's director of security technology and strategy, Tony Lauro, lays out what orgs need to know to defend against account takeover attacks.π Read
via "Threat Post".
Threat Post
The Underground Economy: Recon, Weaponization & Delivery for Account Takeovers
In part one of a two-part series, Akamai's director of security technology and strategy, Tony Lauro, lays out what orgs need to know to defend against account takeover attacks.
π New DOJ Fellowship Program to Bridge Gap in Cyber Law Knowledge π
π Read
via "".
The Justice Department announced a new Cyber Fellowship program for attorneys to develop skills to handle emerging national security threats like ransomware.π Read
via "".
Digital Guardian
New DOJ Fellowship Program to Bridge Gap in Cyber Law Knowledge
The Justice Department announced a new Cyber Fellowship program for attorneys to develop skills to handle emerging national security threats like ransomware.
βΌ CVE-2021-29631 βΌ
π Read
via "National Vulnerability Database".
In FreeBSD 13.0-STABLE before n246941-20f96f215562, 12.2-STABLE before r370400, 11.4-STABLE before r370399, 13.0-RELEASE before p4, 12.2-RELEASE before p10, and 11.4-RELEASE before p13, certain VirtIO-based device models in bhyve failed to handle errors when fetching I/O descriptors. A malicious guest may cause the device model to operate on uninitialized I/O vectors leading to memory corruption, crashing of the bhyve process, and possibly arbitrary code execution in the bhyve process.π Read
via "National Vulnerability Database".
βΌ CVE-2020-18125 βΌ
π Read
via "National Vulnerability Database".
A reflected cross-site scripting (XSS) vulnerability in the /plugin/ajax.php component of Indexhibit 2.1.5 allows attackers to execute arbitrary web scripts or HTML.π Read
via "National Vulnerability Database".
βΌ CVE-2021-22024 βΌ
π Read
via "National Vulnerability Database".
The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can read any log file resulting in sensitive information disclosure.π Read
via "National Vulnerability Database".
βΌ CVE-2021-21774 βΌ
π Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-21773. Reason: This candidate is a reservation duplicate of CVE-2021-21773. Notes: All CVE users should reference CVE-2021-21773 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.π Read
via "National Vulnerability Database".
βΌ CVE-2021-38393 βΌ
π Read
via "National Vulnerability Database".
A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter agid before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37416 βΌ
π Read
via "National Vulnerability Database".
Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page.π Read
via "National Vulnerability Database".
βΌ CVE-2021-32991 βΌ
π Read
via "National Vulnerability Database".
Delta Electronics DIAEnergie Version 1.7.5 and prior is vulnerable to cross-site request forgery, which may allow an attacker to cause a user to carry out an action unintentionally.π Read
via "National Vulnerability Database".
βΌ CVE-2021-34066 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in EdgeGallery/developer before v1.0. There is a "Deserialization of yaml file" vulnerability that can allow attackers to execute system command through uploading the malicious constructed YAML file.π Read
via "National Vulnerability Database".