πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-27816 β€Ό

SWHKD 1.1.5 unsafely uses the /tmp/swhks.pid pathname. There can be data loss or a denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27432 β€Ό

A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27815 β€Ό

SWHKD 1.1.5 unsafely uses the /tmp/swhkd.pid pathname. There can be an information leak or denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1172 β€Ό

Null Pointer Dereference Caused Segmentation Fault in GitHub repository gpac/gpac prior to 2.1.0-DEV.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-23868 β€Ό

RuoYi v4.7.2 contains a CSV injection vulnerability through ruoyi-admin when a victim opens .xlsx log file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1177 β€Ό

Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25598 β€Ό

Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache DolphinScheduler users should upgrade to version 2.0.5 or higher.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23869 β€Ό

In RuoYi v4.7.2 through the WebUI, user test1 does not have permission to reset the password of user test3, but the password of user test3 can be reset through the /system/user/resetPwd request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1178 β€Ό

Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1155 β€Ό

Old sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior to 5.3.10.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1154 β€Ό

Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1181 β€Ό

Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24131 β€Ό

DouPHP v1.6 Release 20220121 is affected by Cross Site Scripting (XSS) through /admin/login.php in the background, which will lead to JavaScript code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1180 β€Ό

Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1179 β€Ό

Non-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ How Security Complexity Is Being Weaponized πŸ•΄

As environments grow noisier, it becomes easier for attackers to intentionally create distractions.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ β€˜Dangerous’ EU web authentication plan threatens to undercut browser-led certification system, detractors claim πŸ—“οΈ

Signatories to a letter criticizing EU scheme share their misgivings with The Daily Swig

πŸ“– Read

via "The Daily Swig".
⚠ Zlib data compressor fixes 17-year-old security bug – patch, errrm, now ⚠

This code is venerable! Surely all the bugs must be out by now?

πŸ“– Read

via "Naked Security".
πŸ—“οΈ SQL injection protections in ImpressCMS could be bypassed to achieve RCE πŸ—“οΈ

Features designed to protect against SQL injection could be abused and turned against the host application

πŸ“– Read

via "The Daily Swig".
⚠ World Backup Day: 5 data recovery tips for everyone! ⚠

The only backup you will ever regret is the one you didn't make

πŸ“– Read

via "Naked Security".
πŸ”₯1
πŸ•΄ Cloud Security Architecture Needs to Be Strategic, Realistic, and Based on Risk πŸ•΄

Info-Tech Research Group has released a new research blueprint to help organizations plan the components necessary to build a cloud security architecture.

πŸ“– Read

via "Dark Reading".