πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-23095 β€Ό

Open Design Alliance Drawings SDK before 2022.12.1 mishandles the loading of JPG files. Unchecked input data from a crafted JPG file leads to memory corruption. An attacker can leverage this vulnerability to execute code in the context of the current process.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33828 β€Ό

The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploaded to a public share) are supposed to be deleted upon detection.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44537 β€Ό

ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execution.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2021-33827 β€Ό

The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0235 β€Ό

node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4170 β€Ό

calibre-web is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23303 β€Ό

The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23304 β€Ό

The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3853 β€Ό

chaskiq is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3857 β€Ό

chaskiq is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

πŸ“– Read

via "National Vulnerability Database".
⚠ Romance scammer who targeted 670 women gets 28 months in jail ⚠

Found love online? Sending them money? Friends and family warning you it could be a scam? Don't be too quick to dismiss their concerns...

πŸ“– Read

via "Naked Security".
❀1
πŸ•΄ Mastering the Art of Cloud Tagging Using Data Science πŸ•΄

Cloud tagging, the process of labeling cloud assets by certain attributes or operational values, can unlock behavioral insights to optimize and automate cyber asset management at scale.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ White House tackles β€˜unique security challenges’ faced by open source ecosystem during dedicated virtual summit πŸ—“οΈ

Silicon Valley giants joined government officials to thrash out remedies to software supply chain woes

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-25025 β€Ό

The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25024 β€Ό

The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading to Reflected Cross-SIte Scripting issues

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25061 β€Ό

The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-calendars admin page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0253 β€Ό

livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24909 β€Ό

The ACF Photo Gallery Field WordPress plugin before 1.7.5 does not sanitise and escape the post parameter in the includes/acf_photo_gallery_metabox_edit.php file before outputing back in an attribute, leading to a Reflected Cross-Site Scripting issue

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25005 β€Ό

The SEUR Oficial WordPress plugin before 1.7.0 does not sanitize and escape some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4164 β€Ό

calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24838 β€Ό

The AnyComment WordPress plugin through 0.2.17 has an API endpoint which passes user input via the redirect parameter to the wp_redirect() function without being validated first, leading to an Open Redirect issue, which according to the vendor, is a feature.

πŸ“– Read

via "National Vulnerability Database".