πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-42869 β€Ό

A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 via the last_name parameter in the (1) patient/insert, (2) patient_report, (3) /appointment_report, (4) visit_report, and (5) /bill_detail_report pages.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43478 β€Ό

A vulnerability exists in Hoosk 1.8.0 in /install/index.php, due to a failure to check if config.php already exists in the root directory, which could let a malicious user reinstall the website.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42868 β€Ό

A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 in the first_name parameter in (1) patient/insert, (2) patient_report, (3) appointment_report, (4) visit_report, and (5) bill_detail_report pages. .

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42866 β€Ό

A Cross Site Scripting vulnerabilty exists in Pixelimity 1.0 via the Site Description field in pixelimity/admin/setting.php

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22311 β€Ό

IBM Security Verify Access could allow a user, using man in the middle techniques, to obtain sensitive information or possibly change some information due to improper validiation of JWT tokens.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42867 β€Ό

A Cross Site Scripting (XSS) vulnerability exists in DanPros htmly 2.8.1 via the Description field in (1) admin/config, and (2) index.php pages.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36625 β€Ό

An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the country_id parameter in an UPDATE statement.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42946 β€Ό

A Cross Site Scripting (XSS) vulnerability exists in htmly.2.8.1 via the Copyright field in the /admin/config page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37517 β€Ό

An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application allows email addresses as usernames, which can cause a Denial of Service.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Global BEC Crackdown Nets 65 Suspects πŸ•΄

FBI and international law enforcement agencies execute "Operation Eagle Sweep."

πŸ“– Read

via "Dark Reading".
πŸ•΄ Ransomware: Should Companies Ever Pay Up? πŸ•΄

Ransomware is a major threat, and no business is "too small to target." So what should you do after an attack? Is negotiating with criminals ever the answer?

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-43707 β€Ό

Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26546 β€Ό

Hospital Management System v1.0 was discovered to lack an authorization component, allowing attackers to access sensitive information and obtain the admin password.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43479 β€Ό

A Remote Code Execution (RCE) vulnerability exists in The-Secretary 2.5 via install.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43722 β€Ό

D-Link DIR-645 1.03 A1 is vulnerable to Buffer Overflow. The hnap_main function in the cgibin handler uses sprintf to format the soapaction header onto the stack and has no limit on the size.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Vulnerabilities in Rockwell Automation PLCs Could Enable Stuxnet-Like Attacks πŸ•΄

CISA urges organizations using affected technologies to implement recommended mitigation measures.

πŸ“– Read

via "Dark Reading".
β™ŸοΈ Fake Emergency Search Warrants Draw Scrutiny from Capitol Hill β™ŸοΈ

On Tuesday, KrebsOnSecurity warned that hackers increasingly are using compromised government and police department email accounts to obtain sensitive customer data from mobile providers, ISPs and social media companies. Today, one of the U.S. Senate's most tech-savvy lawmakers said he was troubled by the report and is now asking technology companies and federal agencies for information about the frequency of such schemes.

πŸ“– Read

via "Krebs on Security".
⚠ S3 Ep76: Deadbolt, LAPSUS$, Zlib, and a Chrome 0-day [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
⚠ Two different β€œVMware Spring” bugs at large – we cut through the confusion ⚠

Whoever came up with the name "Spring4Shell" didn't help at all... we cut through the Spring Bug confusion

πŸ“– Read

via "Naked Security".
⚠ Apple pushes out two emergency 0-day updates – get ’em now! ⚠

More Apple zero-days - mobile devices, laptops and desktops affected. Update now!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-27963 β€Ό

Xftp 7.0.0088p and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.

πŸ“– Read

via "National Vulnerability Database".