โผ CVE-2021-44532 โผ
๐ Read
via "National Vulnerability Database".
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject to an injection vulnerability when name constraints were used within a certificate chain, allowing the bypass of these name constraints.Versions of Node.js with the fix for this escape SANs containing the problematic characters in order to prevent the injection. This behavior can be reverted through the --security-revert command-line option.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-25148 โผ
๐ Read
via "National Vulnerability Database".
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-25305 โผ
๐ Read
via "National Vulnerability Database".
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the IP parameter found in the ~/includes/class-wp-statistics-ip.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view a sites statistics, in versions up to and including 13.1.5.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-0653 โผ
๐ Read
via "National Vulnerability Database".
The Profile Builder รขโฌโ User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user clicks on a specially crafted link by an attacker. This affects versions up to and including 3.6.1.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-10640 โผ
๐ Read
via "National Vulnerability Database".
Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execution via a specific communication service.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-0651 โผ
๐ Read
via "National Vulnerability Database".
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-44663 โผ
๐ Read
via "National Vulnerability Database".
A Remote Code Execution (RCE) vulnerability exists in the Xerte Project Xerte through 3.8.4 via a crafted php file through elfinder in connetor.php.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-10636 โผ
๐ Read
via "National Vulnerability Database".
Inadequate encryption may allow the passwords for Emerson OpenEnterprise versions through 3.3.4 user accounts to be obtained.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-25306 โผ
๐ Read
via "National Vulnerability Database".
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the browser parameter found in the ~/includes/class-wp-statistics-visitor.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view a sites statistics, in versions up to and including 13.1.5.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-14502 โผ
๐ Read
via "National Vulnerability Database".
The web interface of the 1734-AENTR communication module is vulnerable to stored XSS. A remote, unauthenticated attacker could store a malicious script within the web interface that, when executed, could modify some string values on the homepage of the web interface.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-14504 โผ
๐ Read
via "National Vulnerability Database".
The web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, unauthenticated attacker can send a crafted request that may allow for modification of the configuration settings.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-0546 โผ
๐ Read
via "National Vulnerability Database".
A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-14478 โผ
๐ Read
via "National Vulnerability Database".
A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content. A successful exploit could potentially cause a denial-of-service condition and allow the attacker to arbitrarily read any local file via system-level services.๐ Read
via "National Vulnerability Database".
๐1
โ The Harsh Truths of Cybersecurity in 2022, Part II โ
๐ Read
via "Threat Post".
Sonya Duffin, ransomware and data-protection expert at Veritas Technologies, shares three steps organizations can take today to reduce cyberattack fallout.๐ Read
via "Threat Post".
Threat Post
The Harsh Truths of Cybersecurity in 2022, Part II
Sonya Duffin, ransomware and data-protection expert at Veritas Technologies, shares three steps organizations can take today to reduce cyberattack fallout.
โผ CVE-2021-44664 โผ
๐ Read
via "National Vulnerability Database".
An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a maliciously crafted PHP file though the project interface disguised as a language file to bypasses the upload filters. Attackers can manipulate the files destination by abusing path traversal in the 'mediapath' variable.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-29217 โผ
๐ Read
via "National Vulnerability Database".
A remote URL redirection vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5. HPE has provided a software update to resolve this vulnerability in HPE OneView Global Dashboard.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-23701 โผ
๐ Read
via "National Vulnerability Database".
A potential remote host header injection security vulnerability has been identified in HPE Integrated Lights-Out 4 (iLO 4) firmware version(s): Prior to 2.60. This vulnerability could be remotely exploited to allow an attacker to supply invalid input to the iLO 4 webserver, causing it to respond with a redirect to an attacker-controlled domain. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 4 (iLO 4).๐ Read
via "National Vulnerability Database".
โผ CVE-2021-39363 โผ
๐ Read
via "National Vulnerability Database".
Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow a video replay attack after ARP cache poisoning has been achieved.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-29216 โผ
๐ Read
via "National Vulnerability Database".
A remote cross-site scripting vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5. HPE has provided a software update to resolve this vulnerability in HPE OneView Global Dashboard.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-29220 โผ
๐ Read
via "National Vulnerability Database".
Multiple buffer overflow security vulnerabilities have been identified in HPE iLO Amplifier Pack version(s): Prior to 2.12. These vulnerabilities could be exploited by a highly privileged user to remotely execute code that could lead to a loss of confidentiality, integrity, and availability. HPE has provided a software update to resolve this vulnerability in HPE iLO Amplifier Pack.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-39364 โผ
๐ Read
via "National Vulnerability Database".
Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for camera control) after ARP cache poisoning has been achieved.๐ Read
via "National Vulnerability Database".