βΌ CVE-2021-38995 βΌ
π Read
via "National Vulnerability Database".
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 213073.π Read
via "National Vulnerability Database".
π1
βΌ CVE-2021-38994 βΌ
π Read
via "National Vulnerability Database".
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 213072.π Read
via "National Vulnerability Database".
βΌ CVE-2022-22793 βΌ
π Read
via "National Vulnerability Database".
Cybonet - PineApp Mail Relay Local File Inclusion. Attacker can send a request to : /manage/mailpolicymtm/log/eml_viewer/email.content.body.php?filesystem_path=ENCDODED PATH and by doing that, the attacker can read Local Files inside the server.π Read
via "National Vulnerability Database".
βΌ CVE-2022-22349 βΌ
π Read
via "National Vulnerability Database".
IBM Sterling External Authentication Server 3.4.3.2, 6.0.2.0, and 6.0.3.0 is vulnerable to path traversals, due to not properly validating RESTAPI configuration data. An authorized user could import invalid data which could be used for an attack. IBM X-Force ID: 220144.π Read
via "National Vulnerability Database".
βΌ CVE-2022-22794 βΌ
π Read
via "National Vulnerability Database".
Cybonet - PineApp Mail Relay Unauthenticated Sql Injection. Attacker can send a request to: /manage/emailrichment/userlist.php?CUSTOMER_ID_INNER=1 /admin/emailrichment/userlist.php?CUSTOMER_ID_INNER=1 /manage/emailrichment/usersunlist.php?CUSTOMER_ID_INNER=1 /admin/emailrichment/usersunlist.php?CUSTOMER_ID_INNER=1 and by doing that, the attacker can run Remote Code Execution in one liner.π Read
via "National Vulnerability Database".
βΌ CVE-2021-39038 βΌ
π Read
via "National Vulnerability Database".
IBM WebSphere Application Server 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 213968.π Read
via "National Vulnerability Database".
β Zenly Social-Media App Bugs Allow Account Takeover β
π Read
via "Threat Post".
A pair of bugs in the Snap-owned tracking app reveal phone numbers and allow account hijacking.π Read
via "Threat Post".
Threat Post
Zenly Social-Media App Bugs Allow Account Takeover
A pair of bugs in the Snap-owned tracking app reveal phone numbers and allow account hijacking.
π΄ Why Developers Should Care About Log4j π΄
π Read
via "Dark Reading".
Unless you can gain full visibility into how data flows to and through your dependencies, you canβt be sure if you are affected by this vulnerability.π Read
via "Dark Reading".
Dark Reading
Why Developers Should Care About Log4j
Unless you can gain full visibility into how data flows to and through your dependencies, you canβt be sure if you are affected by this vulnerability.
βΌ CVE-2021-3596 βΌ
π Read
via "National Vulnerability Database".
A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not checking the return value from libxml2's xmlCreatePushParserCtxt() and uses the value directly, which leads to a crash and segmentation fault.π Read
via "National Vulnerability Database".
βΌ CVE-2020-14481 βΌ
π Read
via "National Vulnerability Database".
The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user credentials, including the Windows user or Windows DeskLock passwords. If the compromised user has an administrative account, an attacker could gain full access to the userΓ’β¬β’s operating system and certain components of FactoryTalk View SE.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24709 βΌ
π Read
via "National Vulnerability Database".
@awsui/components-react is the main AWS UI package which contains React components, with TypeScript definitions designed for user interface development. Multiple components in versions before 3.0.367 have been found to not properly neutralize user input and may allow for javascript injection. Users are advised to upgrade to version 3.0.367 or later. There are no known workarounds for this issue.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24232 βΌ
π Read
via "National Vulnerability Database".
A local file inclusion in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0544 βΌ
π Read
via "National Vulnerability Database".
An integer underflow in the DDS loader of Blender leads to an out-of-bounds read, possibly allowing an attacker to read sensitive data using a crafted DDS image file. This flaw affects Blender versions prior to 2.83.19, 2.93.8 and 3.1.π Read
via "National Vulnerability Database".
βΌ CVE-2021-3700 βΌ
π Read
via "National Vulnerability Database".
A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c. This issue occurs when serializing large amounts of buffered write data in the case of a slow or blocked destination.π Read
via "National Vulnerability Database".
βΌ CVE-2021-44662 βΌ
π Read
via "National Vulnerability Database".
A Site Scripting (XSS) vulnerability exists in the Xerte Project Xerte through 3.8.4 via the link parameter in print.php.π Read
via "National Vulnerability Database".
βΌ CVE-2021-44532 βΌ
π Read
via "National Vulnerability Database".
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject to an injection vulnerability when name constraints were used within a certificate chain, allowing the bypass of these name constraints.Versions of Node.js with the fix for this escape SANs containing the problematic characters in order to prevent the injection. This behavior can be reverted through the --security-revert command-line option.π Read
via "National Vulnerability Database".
βΌ CVE-2022-25148 βΌ
π Read
via "National Vulnerability Database".
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.π Read
via "National Vulnerability Database".
βΌ CVE-2022-25305 βΌ
π Read
via "National Vulnerability Database".
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the IP parameter found in the ~/includes/class-wp-statistics-ip.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view a sites statistics, in versions up to and including 13.1.5.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0653 βΌ
π Read
via "National Vulnerability Database".
The Profile Builder Γ’β¬β User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user clicks on a specially crafted link by an attacker. This affects versions up to and including 3.6.1.π Read
via "National Vulnerability Database".
βΌ CVE-2020-10640 βΌ
π Read
via "National Vulnerability Database".
Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execution via a specific communication service.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0651 βΌ
π Read
via "National Vulnerability Database".
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.π Read
via "National Vulnerability Database".