βΌ CVE-2021-35052 βΌ
π Read
via "National Vulnerability Database".
A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37022 βΌ
π Read
via "National Vulnerability Database".
There is a Heap-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause root permission which can be escalated.π Read
via "National Vulnerability Database".
ποΈ Microsoft unveils βSuper Duper Secure Modeβ in latest version of Edge ποΈ
π Read
via "The Daily Swig".
Browser goes further to protect against bugs by disabling JITπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Microsoft unveils βSuper Duper Secure Modeβ in latest version of Edge
Browser goes further to protect against bugs by disabling JIT
π΄ Holiday Scams Drive SMS Phishing Attacks π΄
π Read
via "Dark Reading".
Attackers typically target consumers with malicious text messages containing obfuscated links, but experts say businesses are threatened as well.π Read
via "Dark Reading".
Dark Reading
Holiday Scams Drive SMS Phishing Attacks
Attackers typically target consumers with malicious text messages containing obfuscated links, but experts say businesses are threatened as well.
βΌ CVE-2021-36333 βΌ
π Read
via "National Vulnerability Database".
Dell EMC CloudLink 7.1 and all prior versions contain a Buffer Overflow Vulnerability. A local low privileged attacker, may potentially exploit this vulnerability, leading to an application crash.π Read
via "National Vulnerability Database".
βΌ CVE-2021-24812 βΌ
π Read
via "National Vulnerability Database".
The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lead to Stored Cross-Site Scripting issues when an admin import a malicious CSV.π Read
via "National Vulnerability Database".
βΌ CVE-2021-21561 βΌ
π Read
via "National Vulnerability Database".
Dell PowerScale OneFS version 8.1.2 contains a sensitive information exposure vulnerability. This would allow a malicious user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE privileges to gain access to sensitive information in the log files.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36313 βΌ
π Read
via "National Vulnerability Database".
Dell EMC CloudLink 7.1 and all prior versions contain an OS command injection Vulnerability. A remote high privileged attacker, may potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker. This vulnerability is considered critical as it may be leveraged to completely compromise the vulnerable application as well as the underlying operating system. Dell recommends customers to upgrade at the earliest opportunity.π Read
via "National Vulnerability Database".
βΌ CVE-2021-24892 βΌ
π Read
via "National Vulnerability Database".
Insecure Direct Object Reference in edit function of Advanced Forms (Free & Pro) before 1.6.9 allows authenticated remote attacker to change arbitrary user's email address and request for reset password, which could lead to take over of WordPress's administrator account. To exploit this vulnerability, an attacker must register to obtain a valid WordPress's user and use such user to authenticate with WordPress in order to exploit the vulnerable edit function.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36314 βΌ
π Read
via "National Vulnerability Database".
Dell EMC CloudLink 7.1 and all prior versions contain an Arbitrary File Creation Vulnerability. A remote unauthenticated attacker, may potentially exploit this vulnerability, leading to the execution of arbitrary files on the end user system.π Read
via "National Vulnerability Database".
βΌ CVE-2021-38875 βΌ
π Read
via "National Vulnerability Database".
IBM MQ 8.0, 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.1 CD, and 9.2 CD is vulnerable to a denial of service attack caused by an error processing messages. IBM X-Force ID: 208398.π Read
via "National Vulnerability Database".
βΌ CVE-2021-25986 βΌ
π Read
via "National Vulnerability Database".
In Django-wiki, versions 0.0.20 to 0.7.8 are vulnerable to Stored Cross-Site Scripting (XSS) in Notifications Section. An attacker who has access to edit pages can inject JavaScript payload in the title field. When a victim gets a notification regarding the changes made in the application, the payload in the notification panel renders and loads external JavaScript.π Read
via "National Vulnerability Database".
βΌ CVE-2021-24641 βΌ
π Read
via "National Vulnerability Database".
The Images to WebP WordPress plugin before 1.9 does not have CSRF checks in place when performing some administrative actions, which could result in modification of plugin settings, Denial-of-Service, as well as arbitrary image conversionπ Read
via "National Vulnerability Database".
βΌ CVE-2021-43019 βΌ
π Read
via "National Vulnerability Database".
Adobe Creative Cloud version 5.5 (and earlier) are affected by a privilege escalation vulnerability in the resources leveraged by the Setup.exe service. An unauthenticated attacker could leverage this vulnerability to remove files and escalate privileges under the context of SYSTEM . An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability on the product installer. User interaction is required before product installation to abuse this vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2021-24891 βΌ
π Read
via "National Vulnerability Database".
The Elementor Website Builder WordPress plugin before 3.1.4 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issueπ Read
via "National Vulnerability Database".
βΌ CVE-2021-3672 βΌ
π Read
via "National Vulnerability Database".
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.π Read
via "National Vulnerability Database".
βΌ CVE-2021-24830 βΌ
π Read
via "National Vulnerability Database".
The Advanced Access Manager WordPress plugin before 6.8.0 does not escape some of its settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedπ Read
via "National Vulnerability Database".
βΌ CVE-2021-24700 βΌ
π Read
via "National Vulnerability Database".
The Forminator WordPress plugin before 1.15.4 does not sanitize and escape the email field label, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowedπ Read
via "National Vulnerability Database".
βΌ CVE-2021-36301 βΌ
π Read
via "National Vulnerability Database".
Dell iDRAC 9 prior to version 4.40.40.00 and iDRAC 8 prior to version 2.80.80.80 contain a Stack Buffer Overflow in Racadm. An authenticated remote attacker may potentially exploit this vulnerability to control process execution and gain access to the underlying operating system.π Read
via "National Vulnerability Database".
βΌ CVE-2021-38891 βΌ
π Read
via "National Vulnerability Database".
IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 209508.π Read
via "National Vulnerability Database".
βΌ CVE-2021-38980 βΌ
π Read
via "National Vulnerability Database".
IBM Tivoli Key Lifecycle Manager (IBM Security Guardium Key Lifecycle Manager) 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 212786.π Read
via "National Vulnerability Database".