‼ CVE-2020-18126 ‼
📖 Read
via "National Vulnerability Database".
Multiple stored cross-site scripting (XSS) vulnerabilities in the Sections module of Indexhibit 2.1.5 allows attackers to execute arbitrary web scripts or HTML.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-35633 ‼
📖 Read
via "National Vulnerability Database".
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser<EW>::read_sface() store_sm_boundary_item() Edge_of.A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger this vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-32967 ‼
📖 Read
via "National Vulnerability Database".
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without being authenticated or authorized, which may allow the attacker to log in and use the device with administrative privileges.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-22022 ‼
📖 Read
via "National Vulnerability Database".
The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability. A malicious actor with administrative access to vRealize Operations Manager API can read any arbitrary file on server leading to information disclosure.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-22027 ‼
📖 Read
via "National Vulnerability Database".
The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack leading to information disclosure.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-33007 ‼
📖 Read
via "National Vulnerability Database".
A heap-based buffer overflow in Delta Electronics TPEditor: v1.98.06 and prior may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-33019 ‼
📖 Read
via "National Vulnerability Database".
A stack-based buffer overflow vulnerability in Delta Electronics DOPSoft Version 4.00.11 and prior may be exploited by processing a specially crafted project file, which may allow an attacker to execute arbitrary code.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-33003 ‼
📖 Read
via "National Vulnerability Database".
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a weak hashing algorithm.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-29630 ‼
📖 Read
via "National Vulnerability Database".
In FreeBSD 13.0-STABLE before n246938-0729ba2f49c9, 12.2-STABLE before r370383, 11.4-STABLE before r370381, 13.0-RELEASE before p4, 12.2-RELEASE before p10, and 11.4-RELEASE before p13, the ggatec daemon does not validate the size of a response before writing it to a fixed-sized buffer allowing a malicious attacker in a privileged network position to overwrite the stack of ggatec and potentially execute arbitrary code.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-38343 ‼
📖 Read
via "National Vulnerability Database".
The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npBulkActions`, `npBulkEdit`, `npListingSort`, and `npCategoryFilter` `admin_post` actions.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-37421 ‼
📖 Read
via "National Vulnerability Database".
Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.📖 Read
via "National Vulnerability Database".
❌ Army Testing Facial Recognition in Child-Care Centers ❌
📖 Read
via "Threat Post".
Army looking for AI to layer over daycare CCTV to boost ‘family quality of life.’📖 Read
via "Threat Post".
Threat Post
Army Testing Facial Recognition in Child-Care Centers
Army looking for AI to layer over daycare CCTV to boost ‘family quality of life.’
❌ HPE Warns Sudo Bug Gives Attackers Root Privileges to Aruba Platform ❌
📖 Read
via "Threat Post".
HPE joins Apple in warning customers of a high-severity Sudo vulnerability.📖 Read
via "Threat Post".
Threat Post
HPE Warns Sudo Bug Gives Attackers Root Privileges to Aruba Platform
HPE joins Apple in warning customers of a high-severity Sudo vulnerability.
‼ CVE-2021-32831 ‼
📖 Read
via "National Vulnerability Database".
Total.js framework (npm package total.js) is a framework for Node.js platfrom written in pure JavaScript similar to PHP's Laravel or Python's Django or ASP.NET MVC. In total.js framework before version 3.4.9, calling the utils.set function with user-controlled values leads to code-injection. This can cause a variety of impacts that include arbitrary code execution. This is fixed in version 3.4.9.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-39175 ‼
📖 Read
via "National Vulnerability Database".
HedgeDoc is a platform to write and share markdown. In versions prior to 1.9.0, an unauthenticated attacker can inject arbitrary JavaScript into the speaker-notes of the slide-mode feature by embedding an iframe hosting the malicious code into the slides or by embedding the HedgeDoc instance into another page. The problem is patched in version 1.9.0. There are no known workarounds aside from upgrading.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-34434 ‼
📖 Read
via "National Vulnerability Database".
In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then existing subscriptions for that client are not revoked.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-39132 ‼
📖 Read
via "National Vulnerability Database".
### Impact An authorized user can upload a zip-format plugin with a crafted plugin.yaml, or a crafted aclpolicy yaml file, or upload an untrusted project archive with a crafted aclpolicy yaml file, that can cause the server to run untrusted code on Rundeck Community or Enterprise Edition. An authenticated user can make a POST request, that can cause the server to run untrusted code on Rundeck Enterprise Edition. The zip-format plugin issues requires authentication and authorization to these access levels, and affects all Rundeck editions: * `admin` level access to the `system` resource type The ACL Policy yaml file upload issues requires authentication and authorization to these access levels, and affects all Rundeck editions: * `create` `update` or `admin` level access to a `project_acl` resource * `create` `update` or `admin` level access to the `system_acl` resource The unauthorized POST request requires authentication, but no specific authorization, and affects Rundeck Enterprise only. ### Patches Versions 3.4.3, 3.3.14 ### Workarounds Please visit [https://rundeck.com/security](https://rundeck.com/security) for information about specific workarounds. ### For more information If you have any questions or comments about this advisory: * Email us at [security@rundeck.com](mailto:security@rundeck.com) To report security issues to Rundeck please use the form at [https://rundeck.com/security](https://rundeck.com/security) Reporter: Rojan Rijal from Tinder Red Team📖 Read
via "National Vulnerability Database".
‼ CVE-2021-35062 ‼
📖 Read
via "National Vulnerability Database".
A Shell Metacharacter Injection vulnerability in result.php in DRK Odenwaldkreis Testerfassung March-2021 allow an attacker with a valid token of a COVID-19 test result to execute shell commands with the permissions of the web server.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-32832 ‼
📖 Read
via "National Vulnerability Database".
Rocket.Chat is an open-source fully customizable communications platform developed in JavaScript. In Rocket.Chat before versions 3.11.3, 3.12.2, and 3.13 an issue with certain regular expressions could lead potentially to Denial of Service. This was fixed in versions 3.11.3, 3.12.2, and 3.13.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-36692 ‼
📖 Read
via "National Vulnerability Database".
libjxl v0.3.7 is affected by a Divide By Zero in issue in lib/extras/codec_apng.cc jxl::DecodeImageAPNG(). When encoding a malicous APNG file using cjxl, an attacker can trigger a denial of service.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-36691 ‼
📖 Read
via "National Vulnerability Database".
libjxl v0.5.0 is affected by a Assertion failed issue in lib/jxl/image.cc jxl::PlaneBase::PlaneBase(). When encoding a malicous GIF file using cjxl, an attacker can trigger a denial of service.📖 Read
via "National Vulnerability Database".