βΌ CVE-2022-26201 βΌ
π Read
via "National Vulnerability Database".
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2021-44321 βΌ
π Read
via "National Vulnerability Database".
Mini-Inventory-and-Sales-Management-System is affected by Cross Site Request Forgery (CSRF), where an attacker can update/delete items in the inventory. The attacker must be logged into the application create a malicious file for updating the inventory details and items.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0831 βΌ
π Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3.π Read
via "National Vulnerability Database".
βΌ CVE-2021-43393 βΌ
π Read
via "National Vulnerability Database".
STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to abuse signature verification. This is associated with the ECDSA signature algorithm on the Java Card J-SAFE3 and STSAFE-J platforms exposing a 3.0.4 Java Card API. It is exploitable for STSAFE-J in closed configuration and J-SIGN (when signature verification is activated) but not for J-SAFE3 EPASS BAC and EAC products. It might also impact other products based on the J-SAFE-3 Java Card platform.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0832 βΌ
π Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3.π Read
via "National Vulnerability Database".
ποΈ Japanese beauty retailer Acro blames third-party hack for breach of 100k payment cards ποΈ
π Read
via "The Daily Swig".
Company traces compromise to vulnerability in payment processorβs systemsπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Japanese beauty retailer Acro blames third-party hack for breach of 100k payment cards
Company traces compromise to vulnerability in payment processorβs systems
β S3 Ep72: AirTag stalking, web server coding woes and Instascams [Podcast + Transcript] β
π Read
via "Naked Security".
Latest episode - listen now (or read it, if that's your preference)...π Read
via "Naked Security".
Naked Security
S3 Ep72: AirTag stalking, web server coding woes and Instascams [Podcast + Transcript]
Latest episode β listen now (or read it, if thatβs your preference)β¦
β Free HermeticRansom Ransomware Decryptor Released β
π Read
via "Threat Post".
Cruddy cryptography means victims whose files have been encrypted by the Ukraine-tormenting ransomware can break the chains without paying extortionists.π Read
via "Threat Post".
Threat Post
Free HermeticRansom Ransomware Decryptor Released
Cruddy cryptography means victims whose files have been encrypted by the Ukraine-tormenting ransomware can break the chains without paying extortionists.
βΌ CVE-2020-18327 βΌ
π Read
via "National Vulnerability Database".
Cross Site Scripting (XSS) vulnerability exists in Alfresco Alfresco Community Edition v5.2.0 via the action parameter in the alfresco/s/admin/admin-nodebrowser API. Fixed in v6.2π Read
via "National Vulnerability Database".
βΌ CVE-2022-23729 βΌ
π Read
via "National Vulnerability Database".
When the device is in factory state, it can be access the shell without adb authentication process. The LG ID is LVE-SMP-210010.π Read
via "National Vulnerability Database".
βΌ CVE-2021-46381 βΌ
π Read
via "National Vulnerability Database".
Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow].π Read
via "National Vulnerability Database".
βΌ CVE-2021-46379 βΌ
π Read
via "National Vulnerability Database".
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site.π Read
via "National Vulnerability Database".
π1
βΌ CVE-2021-46382 βΌ
π Read
via "National Vulnerability Database".
Unauthenticated cross-site scripting (XSS) in Netgear WAC120 AC Access Point may lead to mulitple attacks like session hijacking even clipboard hijacking.π Read
via "National Vulnerability Database".
βΌ CVE-2020-18324 βΌ
π Read
via "National Vulnerability Database".
Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.π Read
via "National Vulnerability Database".
βΌ CVE-2022-26336 βΌ
π Read
via "National Vulnerability Database".
A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse TNEF files and the application allows untrusted users to supply them, then a carefully crafted file can cause an Out of Memory exception. This issue affects poi-scratchpad version 5.2.0 and prior versions. Users are recommended to upgrade to poi-scratchpad 5.2.1.π Read
via "National Vulnerability Database".
βΌ CVE-2021-46380 βΌ
π Read
via "National Vulnerability Database".
Chained Cross Site Request Forgery (CSRF) with Reflected Cross Site Scripting (XSS) vulnerability in WAGO 750-8212 PFC200 G2 2ETH RS leads to session hijacking.π Read
via "National Vulnerability Database".
βΌ CVE-2021-3744 βΌ
π Read
via "National Vulnerability Database".
A memory leak flaw was found in the Linux kernel in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ccp/ccp-ops.c, which allows attackers to cause a denial of service (memory consumption). This vulnerability is similar with the older CVE-2019-18808.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0839 βΌ
π Read
via "National Vulnerability Database".
Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0.π Read
via "National Vulnerability Database".
βΌ CVE-2022-23397 βΌ
π Read
via "National Vulnerability Database".
The Cedar Gate EZ-NET portal 6.5.5 6.8.0 Internet portal has a call to display messages to users which does not properly sanitize data sent in through a URL parameter. This leads to a Reflected Cross-Site Scripting vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2020-18325 βΌ
π Read
via "National Vulnerability Database".
Multilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel.π Read
via "National Vulnerability Database".
βΌ CVE-2020-18326 βΌ
π Read
via "National Vulnerability Database".
Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfully create an arbitrary administrator user.π Read
via "National Vulnerability Database".