βΌ CVE-2021-45382 βΌ
π Read
via "National Vulnerability Database".
A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the DDNS function in ncc2 binary file. Note: DIR-810L, DIR-820L, DIR-830L, DIR-826L, DIR-836L, all hardware revisions, have reached their End of Life ("EOL") /End of Service Life ("EOS") Life-Cycle and as such this issue will not be patched.π Read
via "National Vulnerability Database".
βΌ CVE-2021-46319 βΌ
π Read
via "National Vulnerability Database".
Remote Code Execution (RCE) vulnerability exists in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin. Malicious users can use this vulnerability to use "\ " or backticks to bypass the shell metacharacters in the ssid0 or ssid1 parameters to execute arbitrary commands.This vulnerability is due to the fact that CVE-2019-17509 is not fully patched and can be bypassed by using line breaks or backticks on its basis.π Read
via "National Vulnerability Database".
βΌ CVE-2021-46314 βΌ
π Read
via "National Vulnerability Database".
A Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetNetworkTomographySettings.php of D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin because backticks can be used for command injection when judging whether it is a reasonable domain name.π Read
via "National Vulnerability Database".
βΌ CVE-2022-22916 βΌ
π Read
via "National Vulnerability Database".
O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.π Read
via "National Vulnerability Database".
βΌ CVE-2022-23646 βΌ
π Read
via "National Vulnerability Database".
Next.js is a React framework. Starting with version 10.0.0 and prior to version 12.1.0, Next.js is vulnerable to User Interface (UI) Misrepresentation of Critical Information. In order to be affected, the `next.config.js` file must have an `images.domains` array assigned and the image host assigned in `images.domains` must allow user-provided SVG. If the `next.config.js` file has `images.loader` assigned to something other than default, the instance is not affected. Version 12.1.0 contains a patch for this issue. As a workaround, change `next.config.js` to use a different `loader configuration` other than the default.π Read
via "National Vulnerability Database".
βΌ CVE-2021-46315 βΌ
π Read
via "National Vulnerability Database".
Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetWizardConfig.php in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin. Malicoius users can use this vulnerability to use "\ " or backticks in the shell metacharacters in the ssid0 or ssid1 parameters to cause arbitrary command execution. Since CVE-2019-17510 vulnerability has not been patched and improved www/hnap1/control/setwizardconfig.php, can also use line breaks and backquotes to bypass.π Read
via "National Vulnerability Database".
βΌ CVE-2022-25313 βΌ
π Read
via "National Vulnerability Database".
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.π Read
via "National Vulnerability Database".
βΌ CVE-2022-22922 βΌ
π Read
via "National Vulnerability Database".
TP-Link TL-WA850RE Wi-Fi Range Extender before v6_200923 was discovered to use highly predictable and easily detectable session keys, allowing attackers to gain administrative privileges.π Read
via "National Vulnerability Database".
βΌ CVE-2022-25315 βΌ
π Read
via "National Vulnerability Database".
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.π Read
via "National Vulnerability Database".
βΌ CVE-2022-25314 βΌ
π Read
via "National Vulnerability Database".
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.π Read
via "National Vulnerability Database".
βΌ CVE-2021-46108 βΌ
π Read
via "National Vulnerability Database".
D-Link DSL-2730E CT-20131125 devices allow XSS via the username parameter to the password page in the maintenance configuration.π Read
via "National Vulnerability Database".
ποΈ Lagging behind? New study highlights weaknesses in open source patch process ποΈ
π Read
via "The Daily Swig".
Patch delays create a βwindow of opportunityβ for observant attackersπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Lagging behind? New study highlights weaknesses in open source patch process
Patch delays create a βwindow of opportunityβ for observant attackers
βΌ CVE-2022-0660 βΌ
π Read
via "National Vulnerability Database".
Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.π Read
via "National Vulnerability Database".
β Iranian State Broadcaster Clobbered by βClumsy, Buggyβ Code β
π Read
via "Threat Post".
Researchers said a Jan. 27 attack that aired footage of opposition leaders calling for assassination of Iranβs Supreme Leader was a clumsy and unsophisticated wiper attack.π Read
via "Threat Post".
Threat Post
Iranian State Broadcaster Clobbered by βClumsy, Buggyβ Code
Researchers said a Jan. 27 attack that aired footage of opposition leaders calling for assassination of Iranβs Supreme Leader was a clumsy and unsophisticated wiper attack.
β Severe WordPress Plug-In UpdraftPlus Bug Threatens Backups β
π Read
via "Threat Post".
An oversight in a WordPress plug-in exposes PII and authentication data to malicious insiders.π Read
via "Threat Post".
Threat Post
Severe WordPress Plug-In UpdraftPlus Bug Threatens Backups
An oversight in a WordPress plug-in exposes PII and authentication data to malicious insiders.
ποΈ Critical vulnerabilities in Zabbix Web Frontend allow authentication bypass, code execution on servers ποΈ
π Read
via "The Daily Swig".
Patch now to protect, say researchersπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Critical vulnerabilities in Zabbix Web Frontend allow authentication bypass, code execution on servers
Patch now to protect, say researchers
π΄ If the Cloud Is More Secure, Then Why Is Everything Still Broken? π΄
π Read
via "Dark Reading".
The sooner we discover sources of risk, the better equipped we will be to create effective mitigations for them.π Read
via "Dark Reading".
Dark Reading
If the Cloud Is More Secure, Then Why Is Everything Still Broken?
The sooner we discover sources of risk, the better equipped we will be to create effective mitigations for them.
π΄ Ransomware Adds New Wrinkle in Russian Cybercrime Market π΄
π Read
via "Dark Reading".
Government crackdowns may destabilize Russian crime rings and strengthen their ties to Chinese allies.π Read
via "Dark Reading".
Dark Reading
Ransomware Adds New Wrinkle in Russian Cybercrime Market
Government crackdowns may destabilize Russian crime rings and strengthen their ties to Chinese allies.
βΌ CVE-2022-0664 βΌ
π Read
via "National Vulnerability Database".
Use of Hard-coded Cryptographic Key in Go github.com/gravitl/netmaker prior to 0.8.5,0.9.4,0.10.0,0.10.1.π Read
via "National Vulnerability Database".
βΌ CVE-2022-25299 βΌ
π Read
via "National Vulnerability Database".
This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target folder.π Read
via "National Vulnerability Database".
βΌ CVE-2022-25298 βΌ
π Read
via "National Vulnerability Database".
This affects the package sprinfall/webcc before 0.3.0. It is possible to traverse directories to fetch arbitrary files from the server.π Read
via "National Vulnerability Database".