πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-44217 β€Ό

In Ericsson CodeChecker through 6.18.0, a Stored Cross-site scripting (XSS) vulnerability in the comments component of the reports viewer allows remote attackers to inject arbitrary web script or HTML via the POST JSON data of the /CodeCheckerService API.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41551 β€Ό

Leostream Connection Broker 9.0.40.17 allows administrators to conduct directory traversal attacks by uploading z ZIP file that contains a symbolic link.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0263 β€Ό

Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7.

πŸ“– Read

via "National Vulnerability Database".
❌ β€˜White Rabbit’ Ransomware May Be New FIN8 Tool ❌

It's a double-extortion play that uses the command-line password β€˜KissMe’ to hide its nasty acts and adorns its ransom note with cutesy ASCII bunny art.

πŸ“– Read

via "Threat Post".
⚠ Serious Security: Apple Safari leaks private data via database API – what you need to know ⚠

There's a tiny data leakage bug in the WebKit browser engine... but it could act as a "supercookie" identifier for your browsing

πŸ“– Read

via "Naked Security".
⚠ Romance scammer who targeted 670 women gets 28 months in jail ⚠

Found love online? Sending them money? Friends and family warning you it could be a scam? Don't be too quick to dismiss their concerns...

πŸ“– Read

via "Naked Security".
πŸ•΄ US Search for Vulnerabilities Drives 10x Increase in Bug Reports πŸ•΄

Cross-site scripting and broken access controls continued to be the top classes of vulnerabilities researchers discovered, according to Bugcrowd's annual vulnerability report.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-41807 β€Ό

Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts easier.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0125 β€Ό

An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not verifying that a maintainer of a project had the right access to import members from a target project.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-14110 β€Ό

AX3600 router sensitive information leaked.There is an unauthorized interface through luci to obtain sensitive information and log in to the web background.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0232 β€Ό

The User Registration, Login & Landing Pages WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the loader_text parameter found in the ~/includes/templates/landing-page.php file which allows attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.2.7. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0093 β€Ό

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab allows a user with an expired password to access sensitive information through RSS feeds.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34406 β€Ό

NVIDIA Tegra kernel driver contains a vulnerability in NVHost, where a specific race condition can lead to a null pointer dereference, which may lead to a system reboot.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46005 β€Ό

Sourcecodester Car Rental Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via vehicalorcview parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34401 β€Ό

NVIDIA Linux kernel distributions contain a vulnerability in nvmap NVGPU_IOCTL_CHANNEL_SET_ERROR_NOTIFIER, where improper access control may lead to code execution, compromised integrity, or denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41809 β€Ό

SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, in a preview function allowed making queries from the server with certain document types referencing external entities.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0090 β€Ό

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of their commits in the UI.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0172 β€Ό

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP restriction for public projects through GraphQL allowing unauthorised users to read titles of issues, merge requests and milestones.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46012 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0236 β€Ό

The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-wpie-general.php file. This made it possible for unauthenticated attackers to download any imported or exported information from a vulnerable site which can contain sensitive information like user data. This affects versions up to, and including, 3.9.15.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4083 β€Ό

A read-after-free memory flaw was found in the Linux kernel's garbage collection for Unix domain socket file handlers in the way users call close() and fget() simultaneously and can potentially trigger a race condition. This flaw allows a local user to crash the system or escalate their privileges on the system. This flaw affects Linux kernel versions prior to 5.16-rc4.

πŸ“– Read

via "National Vulnerability Database".