βΌ CVE-2022-24293 βΌ
π Read
via "National Vulnerability Database".
Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execution.π Read
via "National Vulnerability Database".
π1
βΌ CVE-2021-28276 βΌ
π Read
via "National Vulnerability Database".
A Denial of Service vulnerability exists in jhead 3.04 and 3.05 via a wild address read in the ProcessCanonMakerNoteDir function in makernote.c.π Read
via "National Vulnerability Database".
β Serious Security: DEADBOLT β the ransomware that goes straight for your backups β
π Read
via "Naked Security".
Some tips on how to keep your network safe - even (or perhaps especially!) if you think you're safe already.π Read
via "Naked Security".
Naked Security
Serious Security: DEADBOLT β the ransomware that goes straight for your backups
Some tips on how to keep your network safe β even (or perhaps especially!) if you think youβre safe already.
βΌ CVE-2022-24934 βΌ
π Read
via "National Vulnerability Database".
wpsupdater.exe in Kingsoft WPS Office through 11.2.0.10382 allows remote code execution by modifying HKEY_CURRENT_USER in the registry.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24768 βΌ
π Read
via "National Vulnerability Database".
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All unpatched versions of Argo CD starting with 1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially escalate their privileges to admin-level. Versions starting with 0.8.0 and 0.5.0 contain limited versions of this issue. To perform exploits, an authorized Argo CD user must have push access to an Application's source git or Helm repository or `sync` and `override` access to an Application. Once a user has that access, different exploitation levels are possible depending on their other RBAC privileges. A patch for this vulnerability has been released in Argo CD versions 2.3.2, 2.2.8, and 2.1.14. Some mitigation measures are available but do not serve as a substitute for upgrading. To avoid privilege escalation, limit who has push access to Application source repositories or `sync` + `override` access to Applications; and limit which repositories are available in projects where users have `update` access to Applications. To avoid unauthorized resource inspection/tampering, limit who has `delete`, `get`, or `action` access to Applications.π Read
via "National Vulnerability Database".
βΌ CVE-2020-20095 βΌ
π Read
via "National Vulnerability Database".
iMessage (Messages app) iOS 12.4 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages.π Read
via "National Vulnerability Database".
βΌ CVE-2022-25269 βΌ
π Read
via "National Vulnerability Database".
Passwork On-Premise Edition before 4.6.13 has multiple XSS issues.π Read
via "National Vulnerability Database".
βΌ CVE-2021-44226 βΌ
π Read
via "National Vulnerability Database".
Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any unprivileged user before Synapse is installed. The unprivileged user may have placed Trojan horse DLLs there.π Read
via "National Vulnerability Database".
βΌ CVE-2022-22819 βΌ
π Read
via "National Vulnerability Database".
NXP LPC55S66JBD64, LPC55S66JBD100, LPC55S66JEV98, LPC55S69JBD64, LPC55S69JBD100, and LPC55S69JEV98 microcontrollers (ROM version 1B) have a buffer overflow in parsing SB2 updates before the signature is verified. This can allow an attacker to achieve non-persistent code execution via a crafted unsigned update.π Read
via "National Vulnerability Database".
βΌ CVE-2022-25267 βΌ
π Read
via "National Vulnerability Database".
Passwork On-Premise Edition before 4.6.13 allows migration/uploadExportFile Directory Traversal (to upload files).π Read
via "National Vulnerability Database".
βΌ CVE-2022-25041 βΌ
π Read
via "National Vulnerability Database".
OpenEMR v6.0.0 was discovered to contain an incorrect access control issue.π Read
via "National Vulnerability Database".
βΌ CVE-2020-20094 βΌ
π Read
via "National Vulnerability Database".
Instagram iOS 106.0 and prior and Android 107.0.0.11 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messagesπ Read
via "National Vulnerability Database".
βΌ CVE-2020-20096 βΌ
π Read
via "National Vulnerability Database".
Whatsapp iOS 2.19.80 and prior and Android 2.19.222 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27254 βΌ
π Read
via "National Vulnerability Database".
The remote keyless system on Honda Civic 2018 vehicles sends the same RF signal for each door-open request, which allows for a replay attack, a related issue to CVE-2019-20626.π Read
via "National Vulnerability Database".
βΌ CVE-2022-25268 βΌ
π Read
via "National Vulnerability Database".
Passwork On-Premise Edition before 4.6.13 allows CSRF via the groups, password, and history subsystems.π Read
via "National Vulnerability Database".
βΌ CVE-2022-25266 βΌ
π Read
via "National Vulnerability Database".
Passwork On-Premise Edition before 4.6.13 allows migration/downloadExportFile Directory Traversal (to read files).π Read
via "National Vulnerability Database".
βΌ CVE-2020-20093 βΌ
π Read
via "National Vulnerability Database".
The Facebook Messenger app for iOS 227.0 and prior and Android 228.1.0.10.116 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27192 βΌ
π Read
via "National Vulnerability Database".
The Reporting module in Aseco Lietuva document management system DVS Avilys before 2022-03-10 allows unauthorized file download. An unauthenticated attacker can impersonate an administrator by reading administrative files.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0315 βΌ
π Read
via "National Vulnerability Database".
Insecure Temporary File in GitHub repository horovod/horovod prior to 0.24.0.π Read
via "National Vulnerability Database".
ποΈ Flash loan attack on One Ring protocol nets crypto-thief $1.4 million ποΈ
π Read
via "The Daily Swig".
Price manipulation of LP tokens ejected OShare tokens from protocolπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Flash loan attack on One Ring protocol nets crypto-thief $1.4 million
Price manipulation of LP tokens ejected OShare tokens from protocol
βΌ CVE-2022-0145 βΌ
π Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository forkcms/forkcms prior to 5.11.1.π Read
via "National Vulnerability Database".