📢 Unified endpoint management solutions 2021-22 📢
📖 Read
via "ITPro".
Analysing the UEM landscape📖 Read
via "ITPro".
IT PRO
Unified endpoint management solutions 2021-22
Analysing the UEM landscape
📢 The Total Economic Impact™ of IBM Security MaaS360 with Watson 📢
📖 Read
via "ITPro".
Cost savings and business benefits enabled by MaaS360📖 Read
via "ITPro".
IT PRO
The Total Economic Impactâ„¢ of IBM Security MaaS360 with Watson
Cost savings and business benefits enabled by MaaS360
📢 What is cloud ransomware and how can you avoid attacks? 📢
📖 Read
via "ITPro".
With ransomware increasingly targeting cloud applications and data, as well as cloud-based companies, we explain how you can protect your business📖 Read
via "ITPro".
Cloud Pro
What is cloud ransomware and how can you avoid attacks?
With ransomware increasingly targeting cloud applications and data, as well as cloud-based companies, we explain how you can protect your business
‼ CVE-2022-26252 ‼
📖 Read
via "National Vulnerability Database".
aaPanel v6.8.21 was discovered to be vulnerable to directory traversal. This vulnerability allows attackers to obtain the root user private SSH key(id_rsa).📖 Read
via "National Vulnerability Database".
‼ CVE-2022-26254 ‼
📖 Read
via "National Vulnerability Database".
WoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows unauthenticated attackers to arbitrarily change group ID names.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-44127 ‼
📖 Read
via "National Vulnerability Database".
In DLink DAP-1360 F1 firmware version <=v6.10 in the "webupg" binary, an attacker can use the "file" parameter to execute arbitrary system commands when the parameter is "name=deleteFile" after being authorized.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-26598 ‼
📖 Read
via "National Vulnerability Database".
ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, able to have a security token).📖 Read
via "National Vulnerability Database".
‼ CVE-2022-26273 ‼
📖 Read
via "National Vulnerability Database".
EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnerabilities.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-45491 ‼
📖 Read
via "National Vulnerability Database".
3CX System through 2022-03-17 stores cleartext passwords in a database.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-44208 ‼
📖 Read
via "National Vulnerability Database".
OX App Suite through 7.10.5 allows XSS via an unknown system message in Chat.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-26268 ‼
📖 Read
via "National Vulnerability Database".
Xiaohuanxiong v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /app/controller/Books.php.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-26599 ‼
📖 Read
via "National Vulnerability Database".
ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-24303 ‼
📖 Read
via "National Vulnerability Database".
Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-26600 ‼
📖 Read
via "National Vulnerability Database".
ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==).📖 Read
via "National Vulnerability Database".
‼ CVE-2021-44617 ‼
📖 Read
via "National Vulnerability Database".
A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.php/getOutdated.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-26259 ‼
📖 Read
via "National Vulnerability Database".
A buffer over flow in Xiongmai DVR devices NBD80X16S-KL, NBD80X09S-KL, NBD80X08S-KL, NBD80X09RA-KL, AHB80X04R-MH, AHB80X04R-MH-V2, AHB80X04-R-MH-V3, AHB80N16T-GS, AHB80N32F4-LME, and NBD90S0VT-QW allows attackers to cause a Denial of Service (DoS) via a crafted RSTP request.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-26255 ‼
📖 Read
via "National Vulnerability Database".
Clash for Windows v0.19.8 was discovered to allow arbitrary code execution via a crafted payload injected into the Proxies name column.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-44213 ‼
📖 Read
via "National Vulnerability Database".
OX App Suite through 7.10.5 allows XSS via uuencoding in a multipart/alternative message.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-26258 ‼
📖 Read
via "National Vulnerability Database".
D-Link DIR-820L 1.05B03 was discovered to contain a remote command execution (RCE) vulnerability via the Device Name parameter in /lan.asp.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-45490 ‼
📖 Read
via "National Vulnerability Database".
The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate validation.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-44211 ‼
📖 Read
via "National Vulnerability Database".
OX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signature.📖 Read
via "National Vulnerability Database".