‼ CVE-2021-23246 ‼
📖 Read
via "National Vulnerability Database".
In ACE2 ColorOS11, the attacker can obtain the foreground package name through permission promotion, resulting in user information disclosure.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-23924 ‼
📖 Read
via "National Vulnerability Database".
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products which may allow Escalation of Privilege, Arbitrary Code Execution, Unauthorized Code Execution, Denial of Service, and Information Disclosure.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-23934 ‼
📖 Read
via "National Vulnerability Database".
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products which may allow Escalation of Privilege, Arbitrary Code Execution, Unauthorized Code Execution, Denial of Service, and Information Disclosure.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-25216 ‼
📖 Read
via "National Vulnerability Database".
An absolute path traversal vulnerability allows a remote attacker to download any file on the Windows file system for which the user account running DVDFab 12 Player (recently renamed PlayerFab) has read-access, by means of an HTTP GET request to http://<IP_ADDRESS>:32080/download/<URL_ENCODED_PATH>.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-24096 ‼
📖 Read
via "National Vulnerability Database".
Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by an Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-23929 ‼
📖 Read
via "National Vulnerability Database".
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products which may allow Escalation of Privilege, Arbitrary Code Execution, Unauthorized Code Execution, Denial of Service, and Information Disclosure.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-25621 ‼
📖 Read
via "National Vulnerability Database".
UUNIVERGE WA 1020 Ver8.2.11 and prior, UNIVERGE WA 1510 Ver8.2.11 and prior, UNIVERGE WA 1511 Ver8.2.11 and prior, UNIVERGE WA 1512 Ver8.2.11 and prior, UNIVERGE WA 2020 Ver8.2.11 and prior, UNIVERGE WA 2021 Ver8.2.11 and prior, UNIVERGE WA 2610-AP Ver8.2.11 and prior, UNIVERGE WA 2611-AP Ver8.2.11 and prior, UNIVERGE WA 2611E-AP Ver8.2.11 and prior, UNIVERGE WA WA2612-AP Ver8.2.11 and prior allows a remote attacker to execute arbitrary OS commands.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-23187 ‼
📖 Read
via "National Vulnerability Database".
Adobe Illustrator version 26.0.3 (and earlier) is affected by a buffer overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file in Illustrator.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-25601 ‼
📖 Read
via "National Vulnerability Database".
Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugin (versions <= 2.4).📖 Read
via "National Vulnerability Database".
‼ CVE-2021-32475 ‼
📖 Read
via "National Vulnerability Database".
ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-23731 ‼
📖 Read
via "National Vulnerability Database".
V8 javascript engine (heap vulnerability) can cause privilege escalation ,which can impact on some webOS TV models.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-26341 ‼
📖 Read
via "National Vulnerability Database".
Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-32476 ‼
📖 Read
via "National Vulnerability Database".
A denial-of-service risk was identified in the draft files area, due to it not respecting user file upload limits. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-24433 ‼
📖 Read
via "National Vulnerability Database".
The package simple-git before 3.3.0 are vulnerable to Command Injection via argument injection. When calling the .fetch(remote, branch, handlerFn) function, both the remote and branch parameters are passed to the git fetch subcommand. By injecting some git options it was possible to get arbitrary command execution.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-23933 ‼
📖 Read
via "National Vulnerability Database".
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products which may allow Escalation of Privilege, Arbitrary Code Execution, Unauthorized Code Execution, Denial of Service, and Information Disclosure.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-25600 ‼
📖 Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3).📖 Read
via "National Vulnerability Database".
‼ CVE-2022-0921 ‼
📖 Read
via "National Vulnerability Database".
Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.12.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-32474 ‼
📖 Read
via "National Vulnerability Database".
An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer host. Note that this required site administrator access or access to the keypair. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-23931 ‼
📖 Read
via "National Vulnerability Database".
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products which may allow Escalation of Privilege, Arbitrary Code Execution, Unauthorized Code Execution, Denial of Service, and Information Disclosure.📖 Read
via "National Vulnerability Database".
🕴 Ukrainian Man Arrested for Alleged Role in Ransomware Attack on Kaseya, Others 🕴
📖 Read
via "Dark Reading".
He's the fifth member of the REvil ransomware gang to get busted in the past year.📖 Read
via "Dark Reading".
Dark Reading
Ukrainian Man Arrested for Alleged Role in Ransomware Attack on Kaseya, Others
He's the fifth member of the REvil ransomware gang to get busted in the past year.
🕴 Is XDR Right for My Organization? 🕴
📖 Read
via "Dark Reading".
Well ... it depends on what you're trying to accomplish, at least for now. The good news is that many modern SIEMs are starting to adopt XDR-like capabilities.📖 Read
via "Dark Reading".
Dark Reading
Is XDR Right for My Organization?
Well ... it depends on what you're trying to accomplish, at least for now. The good news is that many modern SIEMs are starting to adopt XDR-like capabilities.