โ S3 Ep50: Two 0-days plus another 0-day plus a fast food bug [Podcast] โ
๐ Read
via "Naked Security".
Bugs! So many bugs! Latest episode - listen now...๐ Read
via "Naked Security".
Naked Security
S3 Ep50: Two 0-days plus another 0-day plus a fast food bug [Podcast]
Bugs! So many bugs! Latest episode โ listen nowโฆ
๐ฆฟ You can now eliminate the password for your Microsoft account ๐ฆฟ
๐ Read
via "Tech Republic".
By using an alternative means of authentication, you can now go passwordless on your Microsoft account.๐ Read
via "Tech Republic".
๐๏ธ Remote code execution flaw allowed hijack of Motorola Halo+ baby monitors ๐๏ธ
๐ Read
via "The Daily Swig".
Expectant parent finds severe security problems in his new baby monitor๐ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Remote code execution flaw allowed hijack of Motorola Halo+ baby monitors
Expectant parent finds severe security problems in his new baby monitor
โผ CVE-2021-39189 โผ
๐ Read
via "National Vulnerability Database".
Pimcore is an open source data & experience management platform. In versions prior to 10.1.3, it is possible to enumerate usernames via the forgot password functionality. This issue is fixed in version 10.1.3. As a workaround, one may apply the available patch manually.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-19155 โผ
๐ Read
via "National Vulnerability Database".
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component 'modules/filemanager/FileManagerController.java'.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-19154 โผ
๐ Read
via "National Vulnerability Database".
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-19148 โผ
๐ Read
via "National Vulnerability Database".
Cross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'Nickname' parameter in the component '/jfinal_cms/front/person/profile.html'.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-19157 โผ
๐ Read
via "National Vulnerability Database".
Cross Site Scripting (CSS) in Wenku CMS v3.4 allows remote attackers to execute arbitrary code via the 'Intro' parameter for the component '/index.php?m=ucenter&a=index'.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-19151 โผ
๐ Read
via "National Vulnerability Database".
Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via the component 'jfinal_cms/admin/filemanager/list'.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-40157 โผ
๐ Read
via "National Vulnerability Database".
A user may be tricked into opening a malicious FBX file which may exploit an Untrusted Pointer Dereference vulnerability in FBXรขโฌโขs Review version 1.5.0 and prior causing it to run arbitrary code on the system.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-21798 โผ
๐ Read
via "National Vulnerability Database".
An exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a stack variable to go out of scope, resulting in the application dereferencing a stale pointer. This can lead to code execution under the context of the application. An attacker can convince a user to open a document to trigger the vulnerability.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-19146 โผ
๐ Read
via "National Vulnerability Database".
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'TemplatePath' parameter in the component 'jfinal_cms/admin/folder/list'.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-38156 โผ
๐ Read
via "National Vulnerability Database".
In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-19158 โผ
๐ Read
via "National Vulnerability Database".
Cross Site Scripting (XSS) in S-CMS build 20191014 and earlier allows remote attackers to execute arbitrary code via the 'Site Title' parameter of the component '/data/admin/#/app/config/'.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-27044 โผ
๐ Read
via "National Vulnerability Database".
An Out-Of-Bounds Write Vulnerability in Autodesk FBX Review version 1.5.0 and prior may lead to code execution through maliciously crafted DLL files or information disclosure.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-19147 โผ
๐ Read
via "National Vulnerability Database".
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the 'getFolder()' function in the component '/modules/filemanager/FileManager.java'.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-19159 โผ
๐ Read
via "National Vulnerability Database".
Cross Site Request Forgery (CSRF) in LaikeTui v3 allows remote attackers to execute arbitrary code via the component '/index.php?module=member&action=add'.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-19150 โผ
๐ Read
via "National Vulnerability Database".
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/FileManagerController.java'.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-19156 โผ
๐ Read
via "National Vulnerability Database".
Cross Site Scripting (XSS) in Ari Adminer v1 allows remote attackers to execute arbitrary code via the 'Title' parameter of the 'Add New Connections' component when the 'save()' function is called.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-21122 โผ
๐ Read
via "National Vulnerability Database".
UReport v2.2.9 contains a Server-Side Request Forgery (SSRF) in the designer page which allows attackers to detect intranet device ports.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-21125 โผ
๐ Read
via "National Vulnerability Database".
An arbitrary file creation vulnerability in UReport 2.2.9 allows attackers to execute arbitrary code.๐ Read
via "National Vulnerability Database".